Now in early access, book a 30-minute demo →
Agent Skill security

OpenHands

Open source platform for software engineering agents, with GUI, CLI, and SDK.

All Hands AI

How skills run on OpenHands

OpenHands agents work in a sandboxed environment with a shell, filesystem, and browser, running tests and opening pull requests before a human reviews. The sandbox limits blast radius but not intent, and a poisoned skill still ships its changes toward your repository.

Skill security, assessed

Every public skill in our index is assessed by the Anomity Skill Intelligence engine against its real source: remote code execution, credential and data exfiltration, prompt injection, and unsafe installers.

Browse the Skill Risk Index →

Govern the skill layer on OpenHands

Scanning a skill before use tells you what it claims to do. Anomity's Endpoint Sensor sees what agents actually do at runtime: it discovers every skill, agent, and MCP server on the endpoint, and policy can allow, deny, or log the tool calls a skill triggers on OpenHands and every other agent. Violations route to your SIEM, Slack, email, or Jira with a queryable 90-day audit trail.

Book a 30-minute demo to see your own agent and skill inventory.

Other agents

Ask AI about Anomity
ChatGPT Claude Perplexity Google AI Grok