setup-openhands
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill instructs the agent to create and configure executable shell scripts (
.openhands/setup.shand.openhands/pre-commit.sh) that are designed to run automatically at the start of sessions or before commits.- [INDIRECT_PROMPT_INJECTION]: The skill identifies and processes external data from the repository to generate executable commands, creating an attack surface where malicious repository content could influence the generated scripts. - Ingestion points: CI workflows, build files, and project documentation are read to determine configuration steps (Step 2 and Step 3 in SKILL.md).
- Boundary markers: There are no instructions provided to the agent to differentiate between legitimate repository configuration and potentially malicious instructions embedded in those files.
- Capability inventory: The agent possesses file-writing capabilities to create executable scripts and workflows (
.openhands/*.sh,AGENTS.md, and.github/workflows/pr-review.yml). - Sanitization: The instructions do not specify any validation or sanitization of the commands extracted from the repository files before they are written to the executable scripts.
Audit Metadata