agent-sdk-builder

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied input via the INITIAL_PROMPT parameter which is directly interpolated into the instructions. Ingestion points: The {INITIAL_PROMPT} placeholder in SKILL.md. Boundary markers: None. Capability inventory: git clone, file writes, code generation. Sanitization: None.
  • [EXTERNAL_DOWNLOADS]: Fetches examples and documentation from official OpenHands GitHub repositories.
  • [COMMAND_EXECUTION]: Executes git clone and file system operations to manage the SDK workspace.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 03:37 PM
Security Audit — agent-trust-hub — agent-sdk-builder