LOW SEVERITYCONFIRMED
null JSON input silently invokes tool with all default argument values
Package
openai-agents
Version
0.13.2
Verified
2026-03-28
Description
In `agents/tool.py`, the tool invocation path uses `if json_data` to decide whether to call `params_pydantic_model(**json_data)`. `json.loads('null')` returns `None`, which is falsy. The tool is silently called with no arguments, using all Pydantic default values, even though the LLM explicitly sent `null`. The LLM intent is discarded without any error.
Reproduction
from agents.tool import _parse_function_tool_json_input
json_data = _parse_function_tool_json_input(tool_name='t', input_json='null')
# json_data = None
# Downstream: `schema.params_pydantic_model(**json_data) if json_data else schema.params_pydantic_model()`
# Falls through to no-arg call — LLM's null input silently ignored