MEDIUM SEVERITYCONFIRMED

truncate_string violates length contract when max_length < 3

Package
llm
Version
0.29
Verified
2026-03-28

Description

The `truncate_string` function in the `llm` package adds a `...` suffix (3 characters) without checking whether the requested `max_length` is at least 3. When `max_length=0`, the function returns `'hello wo...'` (11 chars) — violating the length contract entirely.

Reproduction

truncate_string('hello world', max_length=0)
# Returns: 'hello wo...' — 11 chars, not 0
← All bugsScan your code →