Urgent.News

What's breaking now, across thousands of outlets.

AI

I Linted 14 Public AI SDK Repos. 12 Ship a Call With No Token Ceiling.

I argued last week that an AI SDK call with no bounds is three CWEs in one missing config object . Fair question back: does anyone actually ship that? So I linted for it. 20,004 source files across 14 public repositories, 474 of which import the Vercel AI SDK, 116 of which contain a real generation call . That 116 is the denominator; everything below is a fraction of it. Bound Files missing it…

I recently analyzed 14 public AI SDK repositories, finding that 12 of them contain calls to AI models without any token limits. I inspected 20,004 source files across these repositories and discovered that 116 of them contain calls to generate text or complete prompts. Of these 116 files, 12 of the 14 repositories have at least one call with no restrictions on the output size.

The repositories that had calls without token limits included five from the SDK vendor. One repository, cloudflare_agents, contributed half of the problematic files. These repositories were minimal examples, often missing important parameters in their code that would normally prevent unbounded calls. The problem is that the unbounded call is correct upstream but wrong downstream, which is why it goes unnoticed.

An example of an unbounded call is `const result = streamText({ model, messages });`. However, a more subtle case was found in 302ai_302-AI-Studio, where the `options` were built indirectly, leading to the absence of the necessary token limit parameter.

I recommend checking your own code for unbounded calls, as it is essential to have limits in place to prevent excessive usage. The eslint-plugin-vercel-ai-security rule can help enforce these limits by checking for `maxOutputTokens`, `requestTimeout`, and `abortSignal` options in your code.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in AI

What Independent Benchmarks Say About Opus 5.5

Two independent benchmark results for Opus 5.5 came out this week, and they don't really agree. One has it in first place.

  • Opus 5.5 ranks first in Artificial Analysis' Intelligence Index with 58 points.
  • Opus 5.5 leads SciCode with an 11-point margin over OpenAI's GPT-6 Astra.
  • Endor Labs places Opus 5.5 third in secure code performance with 68.7% FuncPass.

More from Wednesday 7 October →