Open-source PraisonAI enforces fail-closed prompt-injection scanning and logs tool calls; compliance, insurance and outcome-linked payment remain unpublished
A rare enforced runtime control and a real tool-call audit log sit alongside the same absence of certification, cover and settlement terms found industry-wide.
PraisonAI, an open-source multi-agent framework, publishes an enforced runtime control uncommon among the agents AI Dispatch has reviewed this year: its documentation states the system "scans prompts and tool inputs (including dict keys) for prompt injection before processing — cycle-safe and fail-closed on oversized inputs." An AI Dispatch review scored that control at 2 out of 3 on the outlet's runtime-governance dimension, the highest mark issued this week, though the review noted the enforcement is scoped to injection defense rather than a ceiling on the agent's overall spend or authority.
The framework also logs tool calls to a "thread-safe JSONL audit log," scored 1 out of 3 on the audit-trail dimension — a real record, the review found, but one that publishes no claim of tamper-evidence, hash-chaining or customer reviewability. Separately, platform member and workspace mutation endpoints "enforce admin / owner roles."
PraisonAI runs self-hosted — "your machine, cloud, or edge" — with more than 140 built-in tools and more than 100 language models spanning OpenAI, Anthropic, Google, Ollama and Groq, switchable "seamlessly." It supports the Model Context Protocol and the Agent2Agent protocol, deploying via "Docker, Cloud, MCP Server, A2A Protocol," and integrates with Slack, Discord, Telegram, WhatsApp, GitHub, Google Calendar, Sheets, Drive, Gmail, Notion and Jira.
Outside runtime controls, the review found nothing to score: no certification, framework mapping or audit report on the compliance dimension; no cover, carrier or indemnity term on insurance; and, because the project is self-hosted open source with no vendor-run payment mechanism, no outcome-linked settlement to evaluate. Security vulnerabilities are reported through GitHub Security Advisories, "the preferred reporting method for fastest response."
The result is a mixed profile rather than a uniform one: PraisonAI's engineering includes controls most vendors AI Dispatch has reviewed do not publish, while carrying the same absence of compliance certification, insurance and outcome-linked payment as agents with no runtime governance at all.
Entries in this piece 1
Published index entries backed by the same source documents this piece cites.
Sources 9
“Scans prompts and tool inputs (including dict keys) for prompt injection before processing — cycle-safe and fail-closed on oversized inputs”
docs.praison.ai · checked Aug 20, 2026“Thread-safe JSONL audit log for tool calls.”
docs.praison.ai · checked Aug 20, 2026“Platform member/workspace mutation endpoints now enforce admin / owner roles”
docs.praison.ai · checked Aug 20, 2026“Runs Anywhere Your machine, cloud, or edge. Self-hosted with full control over your data.”
docs.praison.ai · checked Aug 2, 2026“140+ Built-in Tools Web search, file operations, databases, APIs — all ready to use out of the box.”
docs.praison.ai · checked Aug 2, 2026“100+ LLM Models OpenAI, Anthropic, Google, Ollama, Groq — seamlessly switch between any provider.”
docs.praison.ai · checked Aug 2, 2026“Deploy Docker, Cloud, MCP Server, A2A Protocol, and production patterns.”
docs.praison.ai · checked Aug 2, 2026“Platform Integrations Slack Deploy AI bots to Slack workspaces Discord Create Discord bots with agent intelligence Telegram Build Telegram bots in minutes WhatsApp Connect via WhatsApp Business GitHub Automate repos, issues, and PRs Google Calendar, Sheets, Drive, Gmail Notion Read and write Notion pages Jira Manage Jira issues and projects”
docs.praison.ai · checked Aug 2, 2026“GitHub Security Advisories is the preferred reporting method for fastest response.”
docs.praison.ai · checked Aug 20, 2026