openhands-api

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The provided scripts (scripts/openhands_api.py, scripts/openhands_api.ts) include methods such as agent_execute_bash that facilitate the execution of shell commands on a remote agent server. This capability is a core feature of the OpenHands platform, allowing users to control sandboxed agents through the API.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a delegation pattern through the app_conversation_start method, which initiates new agent conversations using a provided initial_message. This constitutes a vulnerability surface where untrusted external data, if interpolated without sanitization, could be used to inject malicious instructions into a delegated agent's context.
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations to https://app.all-hands.dev (the vendor's official cloud platform) and potentially user-defined agent_server_url endpoints. These connections are necessary for communicating with the OpenHands API and managing remote agents.
  • [DYNAMIC_EXECUTION]: The scripts/openhands_api.py script utilizes the zipfile module to extract conversation trajectory archives downloaded from the API. While this is the intended method for offline analysis of agent activities, extracting content from remote sources without explicit path validation carries an inherent risk of path traversal (ZipSlip).
  • [CREDENTIALS_UNSAFE]: Instructions in SKILL.md describe how to retrieve session keys from a local file at ~/.openhands/agent-canvas/api-key.txt. This is a vendor-specific path for their Agent Canvas tool, and the documentation includes explicit warnings against logging or exposing these secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 03:37 PM
Security Audit — agent-trust-hub — openhands-api