openhands-api

Pass

Audited by Gen Agent Trust Hub on May 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [SAFE]: No security issues were detected. The skill's functionality aligns with its purpose as an API client for OpenHands Cloud services.
  • [EXTERNAL_DOWNLOADS]: The skill communicates with the official OpenHands domain https://app.all-hands.dev to manage conversations and download trajectories.
  • [COMMAND_EXECUTION]: Provides methods in scripts/openhands_api.py and scripts/openhands_api.ts to execute bash commands within remote sandbox environments via authenticated API calls.
  • [CREDENTIALS_UNSAFE]: Instructions and scripts recommend using environment variables such as OPENHANDS_CLOUD_API_KEY and OPENHANDS_API_KEY for secure authentication.
Audit Metadata
Risk Level
SAFE
Analyzed
May 16, 2026, 01:58 PM
Security Audit — agent-trust-hub — openhands-api