setup-openhands
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill identifies repository CI workflows, build files, and documentation as sources to generate executable shell scripts. While this creates a surface for indirect prompt injection if those files are malicious, it is the intended primary purpose of the skill for project configuration.
- Ingestion points: CI workflows, build files, and repository documentation (SKILL.md).
- Boundary markers: Absent.
- Capability inventory: File-write and subsequent command execution via generated scripts.
- Sanitization: Absent.
- [EXTERNAL_DOWNLOADS]: The skill references official documentation on the vendor's domain (docs.openhands.dev).
Audit Metadata