openhands
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the
@openhands/agent-canvaspackage from the public NPM registry. - [COMMAND_EXECUTION]: The instructions involve executing the
agent-canvasCLI tool to manage agent frontends and backends. - [REMOTE_CODE_EXECUTION]: The skill describes how to run the OpenHands agent, which is designed to execute code in a local or sandboxed environment.
- [DATA_EXFILTRATION]: The skill includes a security notice warning the user that the agent has full filesystem access when run locally without a sandbox, encouraging the use of hardened configurations.
Audit Metadata