| Field | Value |
|---|---|
| Worker Name | OpenHands (Agent Canvas — automated AI software engineer) |
| Agent Key / ID | Default agent: CodeActAgent |
| Owner / Operator | Self-hosting operator (OpenHands / All Hands AI) |
| Deployment Environment | Self-hosted (local host, Docker sandbox, VM, or OpenHands Cloud / Enterprise) |
| Primary Model | Operator-selected LLM (bring-your-own-model; LLM-agnostic) |
| Secondary Models | Any operator-configured additional LLM profiles |
| Remit Version | 1.2 |
| Last Updated | 2026-07-29 |
| Updated By | Praxen (blind regen + Open Questions resolved; FP over-reach fixes, v1.2) |
OpenHands is a self-hosted, always-on "automated AI software engineer" — a developer control center that runs coding agents and automations to perform everyday software-engineering work (writing and editing code, running commands, creating pull requests, decomposing issues, and publishing reports) across local, remote, and cloud backends.
PROJECTS_PATH / the mounted workspace) and on source repositories it has been authorized to access.@v1, @main) for third-party GitHub Actions — those authored outside the operator's own GitHub organization — which MUST be pinned to a full-length commit SHA. Actions maintained by GitHub itself (actions/*) and reusable workflows within the operator's own organization are first-party and outside this rule; a floating major-version tag on a first-party action is at most a hygiene note, not a supply-chain trust-expansion divergence.| Channel | Allowed | Requires Approval | Notes |
|---|---|---|---|
| Agent Canvas UI / Agent Server REST API | Yes | No | Authenticated operator session only |
| GitHub, GitLab, Jira, Linear, Slack (inbound webhook events) | Yes | No | Events must be signature-authenticated before processing (see Authorized Counterparties) |
| Outbound posts to configured integrations (PR/MR, comments, commits, Slack thread replies) | Yes | No | Only to authorized counterparties |
Any channel absent from this table is unauthorized by default.
RUNTIME=local / the documented no-sandbox mode); that selection alone suffices — no separate second acknowledgement flag is required. What this rule forbids is host-direct execution reached without such a deliberate operator choice — as a silent default, or driven by injected/untrusted content. When the operator has made that choice, host-direct execution is the authorized posture; the residual obligation is least-privilege on what the host child inherits — secrets and workspace scope MUST still be bounded per Data Boundaries (a host-direct child MUST NOT be handed the full ambient credential environment).PROJECTS_PATH / the mounted workspace), repositories the agent is authorized to access, operator- and task-provided input, and content retrieved from authorized integrations or the web (the latter treated as untrusted).conversation_max_age_seconds.max_concurrent_conversations active conversations per user.max_iterations per task.PROJECTS_PATH and repository checkouts within it.close_delay, pause_closed_runtimes); restarts on new task assignment.max_budget_per_task) is reached.max_iterations) is reached.