Hub rules-openhands

rules-openhands

v3 public Verified

Openhands

Community-governed security ruleset for Openhands

@sigmashakeinc 0 pulls 9 rules published Apr 10, 2026 synced Sep 27, 2026 sigmashakeinc/rules/rulesets/rules-openhands →
Severity
6 error 1 warn 2 info
demo.cast
Community-governed security ruleset for Openhands

Rules index

9 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

openhands

log-openhands-maintenance-mode info log

OpenHands Enterprise Maintenance mode activated — dependency updates and tech-debt reduction in progress. Review all changes in the diff sandbox before merging.

Rule source requires an active Pro or Enterprise subscription.
log-openhands-mcp-access info log

OpenHands accessing an external system via MCP. Audit that the agent is operating within its intended scope and is not leaking project data to unintended third-party integrations.

Rule source requires an active Pro or Enterprise subscription.
no-openhands-dependency-upgrade-unpinned warning log

OpenHands upgrading dependencies without a pinned version. Autonomous upgrades can introduce hallucinated or malicious packages, breaking changes, or supply-chain-compromised releases. Pin the target version explicitly.

Rule source requires an active Pro or Enterprise subscription.
no-openhands-destructive-removal error block

OpenHands attempting recursive force-delete. Autonomous agents using force-recursive deletion can wipe entire project trees with no recovery path. Block agent-driven destructive removal; require explicit human approval for any deletion of directories.

Rule source requires an active Pro or Enterprise subscription.
no-openhands-hardcoded-secret-write error log

OpenHands generating code with a hardcoded secret. AI-generated code frequently embeds literal credentials. Use environment variables or a secrets manager; never hardcode credentials in generated source files.

Rule source requires an active Pro or Enterprise subscription.
no-openhands-production-unconstrained error block

OpenHands accessing production path without constraint. Autonomous agents must not operate on production artifacts. Scope agent runs to a dedicated non-production workspace or sandbox branch.

Rule source requires an active Pro or Enterprise subscription.
no-openhands-prompt-injection-task error block

Prompt injection detected in OpenHands task input. Task strings containing role-override or instruction-ignore patterns (CWE-1428) attempt to redirect agent behavior at runtime. Reject tasks with injection markers and re-issue with a sanitized plain-language description.

Rule source requires an active Pro or Enterprise subscription.
no-openhands-sandbox-bypass error ask

OpenHands applying multi-file changes with the diff-review sandbox disabled. Disabling the sandbox removes the human-in-the-loop diff review step — changes land directly without inspection. Re-enable sandbox for any multi-file refactor.

Rule source requires an active Pro or Enterprise subscription.
no-openhands-system-path-write error block

OpenHands attempting to write a system path. Agent-driven writes to /usr/, /bin/, /sbin/, /lib/, or /etc/ risk corrupting system binaries or overwriting security-critical configs. OpenHands agents must be restricted to the project workspace.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v3
Published
Apr 10, 2026
Source commits
0
Synced
Sep 27, 2026
Hash
21105089f9bc378a5eb7ca6a32cffc4fcf162233663877b0d4b6bf246dbf117a
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-openhands/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-openhands. The published version only bumps when a maintainer resyncs.

No commit history available.