Public AI agent scan brief
OpenHands/OpenHands AI agent security scan
Partial no-execution triage for the public OpenHands repo. This is a heuristic scan of 90 selected public text files, not a commissioned audit, vulnerability disclosure, or security certification. These are not confirmed vulnerabilities.
Top findings
Coding agents need clear write, shell, and browser controls
The scan snapshot saw 77,768 stars and review signals around write actions, remote service exposure, and credential paths with some redaction evidence. A paid review would confirm tool safety annotations, workspace boundaries, auth middleware, and tenant assumptions.
Evidence slice
Files that triggered review signals
Write-action signals appeared around `.agents/skills/cross-repo-testing/SKILL.md`, `enterprise/tests/unit/test_saas_server.py`, frontend API tests, and `frontend/__tests__/utils/browser-tab.test.ts`.
Remote and auth-related signals appeared near `enterprise/tests/unit/server/test_constants.py`, `enterprise/tests/unit/test_auth_middleware.py`, `frontend/__tests__/api/v1-conversation-service.test.ts`, `frontend/__tests__/api/v1-git-service.test.ts`, and `frontend/__tests__/routes/vscode-tab.test.tsx`.
Paid handoff
Convert this scan into a fixed-scope review
- Confirm the current coding-agent surface, write actions, shell access, and hosted mode.
- Review auth middleware, browser tab, git, filesystem, and API proxy boundaries.
- Validate redaction, approval gates, default-deny behavior, and regression tests.
- Pay USD $1,000 only after written scope acceptance.