agent-sdk-builder
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied input via the INITIAL_PROMPT parameter which is directly interpolated into the instructions. Ingestion points: The {INITIAL_PROMPT} placeholder in SKILL.md. Boundary markers: None. Capability inventory: git clone, file writes, code generation. Sanitization: None.
- [EXTERNAL_DOWNLOADS]: Fetches examples and documentation from official OpenHands GitHub repositories.
- [COMMAND_EXECUTION]: Executes git clone and file system operations to manage the SDK workspace.
Audit Metadata