setup-openhands

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill instructs the agent to create and configure executable shell scripts (.openhands/setup.sh and .openhands/pre-commit.sh) that are designed to run automatically at the start of sessions or before commits.- [INDIRECT_PROMPT_INJECTION]: The skill identifies and processes external data from the repository to generate executable commands, creating an attack surface where malicious repository content could influence the generated scripts.
  • Ingestion points: CI workflows, build files, and project documentation are read to determine configuration steps (Step 2 and Step 3 in SKILL.md).
  • Boundary markers: There are no instructions provided to the agent to differentiate between legitimate repository configuration and potentially malicious instructions embedded in those files.
  • Capability inventory: The agent possesses file-writing capabilities to create executable scripts and workflows (.openhands/*.sh, AGENTS.md, and .github/workflows/pr-review.yml).
  • Sanitization: The instructions do not specify any validation or sanitization of the commands extracted from the repository files before they are written to the executable scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 12:07 PM
Security Audit — agent-trust-hub — setup-openhands