setup-openhands

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill identifies repository CI workflows, build files, and documentation as sources to generate executable shell scripts. While this creates a surface for indirect prompt injection if those files are malicious, it is the intended primary purpose of the skill for project configuration.
  • Ingestion points: CI workflows, build files, and repository documentation (SKILL.md).
  • Boundary markers: Absent.
  • Capability inventory: File-write and subsequent command execution via generated scripts.
  • Sanitization: Absent.
  • [EXTERNAL_DOWNLOADS]: The skill references official documentation on the vendor's domain (docs.openhands.dev).
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 11:12 AM
Security Audit — agent-trust-hub — setup-openhands