openhands-api
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The provided scripts (
scripts/openhands_api.py,scripts/openhands_api.ts) include methods such asagent_execute_bashthat facilitate the execution of shell commands on a remote agent server. This capability is a core feature of the OpenHands platform, allowing users to control sandboxed agents through the API. - [INDIRECT_PROMPT_INJECTION]: The skill implements a delegation pattern through the
app_conversation_startmethod, which initiates new agent conversations using a providedinitial_message. This constitutes a vulnerability surface where untrusted external data, if interpolated without sanitization, could be used to inject malicious instructions into a delegated agent's context. - [EXTERNAL_DOWNLOADS]: The skill performs network operations to
https://app.all-hands.dev(the vendor's official cloud platform) and potentially user-definedagent_server_urlendpoints. These connections are necessary for communicating with the OpenHands API and managing remote agents. - [DYNAMIC_EXECUTION]: The
scripts/openhands_api.pyscript utilizes thezipfilemodule to extract conversation trajectory archives downloaded from the API. While this is the intended method for offline analysis of agent activities, extracting content from remote sources without explicit path validation carries an inherent risk of path traversal (ZipSlip). - [CREDENTIALS_UNSAFE]: Instructions in
SKILL.mddescribe how to retrieve session keys from a local file at~/.openhands/agent-canvas/api-key.txt. This is a vendor-specific path for their Agent Canvas tool, and the documentation includes explicit warnings against logging or exposing these secrets.
Audit Metadata