open-managed-agents avatar

open-managed-agents

Open Managed Agents — an open-source alternative to Claude Managed Agents and OpenAI Agents API. Deploy with Node.js or Docker, run on Cloudflare, or use hosted OpenMA. Choose your models, harnesses and sandboxes.

Ecosystem pluginAI ModelsNetwork
Verification
L5 · Ecosystem plugin
Risk
Out of scope
Health
Active
Trust
Bronze

Install verification: Ecosystem plugin: installs via dsh plugin add but declares no dsh.bundle and mounts no plugin capability — the L1-L5 install ladder does not rate it; the security scan still runs.Install verification details →

What it doesAI

Open-source, self-hosted Claude Managed Agents API and runtime, drop-in compatible with Claude Tag, deployable on Cloudflare or Node.js.

  • Drop-in compatible with Claude Managed Agents API
  • Runs on Cloudflare Workers/Durable Objects or Node.js
  • Apache 2.0 licensed open source
aiAI

Capability tags are AI-inferred or rule-extracted from the README (see badge) — vocabulary-limited, not install-verified. AI = inferred; README = literal keyword from the readme.

Installation

dsh plugin --profile web add github:openma-ai/open-managed-agents#@openma/cli@0.5.0

security scan passed · source release @openma/cli@0.5.0

Install method: GitHub · runtime test inconclusive (L5 unknown)

Verification & Compatibility

Grouped by plugin version: each card lists the dsh versions actually tested against that artifact version and their install verdicts (L5 wins). Untested combinations are omitted — absence means untested, never assumed compatible. L1–L3 are a plugin-level static archive (independent of the dsh version — the same verdict on every dsh row): they sit in each row's level grid next to L4/L5, marked "static", while their evidence is stored once per plugin inside that row's "checks & evidence" instead of being duplicated per version.

External credentials (plugin-level): none detected

Install compatibility matrix (rows = plugin versions〔latest 5〕, columns = dsh versions〔latest 5〕)
At-a-glance → evidence in the cards below
plugin \ dshdsh 0.1.7-rc.2
current
dsh 0.1.7-rc.1dsh 0.1.7-alpha.2dsh 0.1.6-alpha.2dsh 0.1.6-alpha.1
e602b3·····
e32fe3·○···
0cbc7f·····
@openma/cli@0.5.0○·○○○
Install compatibility (by plugin version, dsh versions within)
Legend:✓ L5 runtime verified○ ecosystem plugin◼ ecosystem app✗ failed
e602b3github2026-08-28

https://github.com/openma-ai/open-managed-agents

Ecosystem plugin: installs via dsh plugin add but declares no dsh.bundle and mounts no plugin capability — its level reads L5 · Ecosystem plugin.

e32fe3github2026-09-23

https://github.com/openma-ai/open-managed-agents

○dsh 0.1.7-rc.12026-09-23ecosystem plugin
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: 0.1.7-rc.1
  • • Plugin artifact: github · https://github.com/openma-ai/open-managed-agents (version unstated)
Levels (L1–L3 plugin-level static archive · L4/L5 newest real verdicts for this combination)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Unknown
L5 runtime
Not tested
Install test ran: the package installs but declares no dsh.bundle and mounts no capability — an ecosystem plugin, not a usable dsh plugin (shown as L5 · ecosystem plugin)
ecosystem plugin

ID: open-managed-agents@e32fe3@dsh0.1.7-rc.1 · profile: l4-sandbox

Issued: 2026-09-23 · expires: 2026-09-30

View checks & evidence
L1 · Found✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed
Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-09-25
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-09-25
L4 · Install tested? Unknown
Sandbox install verdict? Unknown
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-23
spec github:openma-ai/open-managed-agents · channel GitHub source · outcome unknown
L5 · Run tested– Not tested

This level was not executed in this scan.

L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.

○dsh 0.1.3-alpha.12026-09-06ecosystem plugin
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: 0.1.3-alpha.1
  • • Plugin artifact: github · https://github.com/openma-ai/open-managed-agents (version unstated)
Levels (L1–L3 plugin-level static archive · L4/L5 newest real verdicts for this combination)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Unknown
L5 runtime
Not tested
Install test ran: the package installs but declares no dsh.bundle and mounts no capability — an ecosystem plugin, not a usable dsh plugin (shown as L5 · ecosystem plugin)
ecosystem plugin

ID: open-managed-agents@e32fe3@dsh0.1.3-alpha.1 · profile: l4-sandbox

Issued: 2026-09-06 · expires: 2026-09-13

View checks & evidence
L1 · Found✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed
Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-09-25
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-09-25
L4 · Install tested? Unknown
Sandbox install verdict? Unknown
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-06
spec github:openma-ai/open-managed-agents · channel GitHub source · outcome unknown
L5 · Run tested– Not tested

This level was not executed in this scan.

L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.

○dsh 0.1.2-alpha.12026-09-02ecosystem plugin
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: 0.1.2-alpha.1
  • • Plugin artifact: artifact unstated (historical)
Levels (L1–L3 plugin-level static archive · L4/L5 newest real verdicts for this combination)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Passed
L5 runtime
Unknown
Install test ran: the package installs but declares no dsh.bundle and mounts no capability — an ecosystem plugin, not a usable dsh plugin (shown as L5 · ecosystem plugin)
ecosystem plugin

ID: open-managed-agents@e32fe3@dsh0.1.2-alpha.1 · profile: l5-web-smoke

Issued: 2026-09-02 · expires: 2026-12-01

View checks & evidence
L1 · Found✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed
Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-09-25
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-09-25
L4 · Install tested✓ Passed
Install succeeded✓ Passed
L5 · Run tested? Unknown

ecosystem plugin: no dsh.bundle declaration

Sandbox install passed✓ Passed
check took: 138ms
Web boot ready✓ Passed
Source: DSH runtime · Method: web boot · Captured 2026-09-02
ready line dsh web: http://127.0.0.1:54395/?token=…
HTTP endpoint served✓ Passed
Source: DSH runtime · Method: HTTP request · Captured 2026-09-02
path / · HTTP 200 · took 138ms
Plugin active in inventory? Unknown
Source: DSH runtime · Method: plugin inventory query · Captured 2026-09-02
verdict not-found · entries 148
phases: active 121 · null 27
ecosystem plugin: installed, but declares no dsh.bundle — not mounted as a plugin (shown as L5 · ecosystem plugin)

L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.

0cbc7fgithub2026-09-04

github:openma-ai/open-managed-agents

○dsh 0.1.2-rc.12026-09-04ecosystem plugin
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: 0.1.2-rc.1
  • • Plugin artifact: github · github:openma-ai/open-managed-agents#0cbc7f
Levels (L1–L3 plugin-level static archive · L4/L5 newest real verdicts for this combination)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Passed
L5 runtime
Unknown
Install test ran: the package installs but declares no dsh.bundle and mounts no capability — an ecosystem plugin, not a usable dsh plugin (shown as L5 · ecosystem plugin)
ecosystem plugin

ID: open-managed-agents@0cbc7f@dsh0.1.2-rc.1 · profile: l5-web-smoke

Issued: 2026-09-04 · expires: 2026-12-03

View checks & evidence
L1 · Found✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed
Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-09-25
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-09-25
L4 · Install tested✓ Passed
Install succeeded✓ Passed
L5 · Run tested? Unknown

ecosystem plugin: no dsh.bundle declaration

Sandbox install passed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-04
spec github:openma-ai/open-managed-agents · install mode reused L4 scratch
check took: 50ms
Web boot ready✓ Passed
Source: DSH runtime · Method: web boot · Captured 2026-09-04
ready line dsh web: http://127.0.0.1:49673/?token=…
HTTP endpoint served✓ Passed
Source: DSH runtime · Method: HTTP request · Captured 2026-09-04
path / · HTTP 200 · took 50ms
Plugin active in inventory? Unknown
Source: DSH runtime · Method: plugin inventory query · Captured 2026-09-04
verdict not-found · entries 149
phases: active 121 · null 28
ecosystem plugin: installed, but declares no dsh.bundle — not mounted as a plugin (shown as L5 · ecosystem plugin)

L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.

@openma/cli@0.5.0github2026-09-25

https://github.com/openma-ai/open-managed-agents

○dsh 0.1.7-rc.2current2026-09-25ecosystem plugin
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: 0.1.7-rc.2
  • • Plugin artifact: github · https://github.com/openma-ai/open-managed-agents#@openma/cli@0.5.0
Levels (L1–L3 plugin-level static archive · L4/L5 newest real verdicts for this combination)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Passed
L5 runtime
Unknown
Install test ran: the package installs but declares no dsh.bundle and mounts no capability — an ecosystem plugin, not a usable dsh plugin (shown as L5 · ecosystem plugin)
ecosystem plugin

ID: open-managed-agents@@openma_cli@0.5.0@dsh0.1.7-rc.2 · profile: l4-sandbox

Issued: 2026-09-25 · expires: 2026-10-02

View checks & evidence
L1 · Found✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed
Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-09-25
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-09-25
L4 · Install tested✓ Passed
Install executed in confined sandbox✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-25
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · channel GitHub source · outcome ran · exit 0
check took: 18.6s
Install succeeded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-25
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · channel GitHub source · outcome ran · exit 0
check took: 18.6s
Installed artifact confirmed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-25
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · channel GitHub source · outcome ran · exit 0
check took: 18.6s
L5 · Run tested? Unknown

not present in web-profile loader inventory

Sandbox install passed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-25
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · install mode reused L4 scratch
check took: 13ms
Web boot ready✓ Passed
Source: DSH runtime · Method: web boot · Captured 2026-09-25
ready line dsh web: http://127.0.0.1:61524/?token=…
HTTP endpoint served✓ Passed
Source: DSH runtime · Method: HTTP request · Captured 2026-09-25
path / · HTTP 200 · took 13ms
Plugin active in inventory? Unknown
Source: DSH runtime · Method: plugin inventory query · Captured 2026-09-25
verdict not-found · entries 149
phases: active 121 · null 28
not present in web-profile loader inventory

L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.

○dsh 0.1.7-alpha.22026-09-23ecosystem plugin
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: 0.1.7-alpha.2
  • • Plugin artifact: github · https://github.com/openma-ai/open-managed-agents#@openma/cli@0.5.0
Levels (L1–L3 plugin-level static archive · L4/L5 newest real verdicts for this combination)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Passed
L5 runtime
Unknown
Install test ran: the package installs but declares no dsh.bundle and mounts no capability — an ecosystem plugin, not a usable dsh plugin (shown as L5 · ecosystem plugin)
ecosystem plugin

ID: open-managed-agents@@openma_cli@0.5.0@dsh0.1.7-alpha.2 · profile: l4-sandbox

Issued: 2026-09-23 · expires: 2026-09-30

View checks & evidence
L1 · Found✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed
Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-09-25
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-09-25
L4 · Install tested✓ Passed
Install executed in confined sandbox✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-23
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · channel GitHub source · outcome ran · exit 0
check took: 27.5s
Install succeeded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-23
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · channel GitHub source · outcome ran · exit 0
check took: 27.5s
Installed artifact confirmed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-23
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · channel GitHub source · outcome ran · exit 0
check took: 27.5s
L5 · Run tested? Unknown

not present in web-profile loader inventory

Sandbox install passed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-23
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · install mode reused L4 scratch
check took: 22ms
Web boot ready✓ Passed
Source: DSH runtime · Method: web boot · Captured 2026-09-23
ready line dsh web: http://127.0.0.1:60948/?token=…
HTTP endpoint served✓ Passed
Source: DSH runtime · Method: HTTP request · Captured 2026-09-23
path / · HTTP 200 · took 22ms
Plugin active in inventory? Unknown
Source: DSH runtime · Method: plugin inventory query · Captured 2026-09-23
verdict not-found · entries 149
phases: active 121 · null 28
not present in web-profile loader inventory

L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.

○dsh 0.1.6-alpha.22026-09-20ecosystem plugin
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: 0.1.6-alpha.2
  • • Plugin artifact: github · https://github.com/openma-ai/open-managed-agents#@openma/cli@0.5.0
Levels (L1–L3 plugin-level static archive · L4/L5 newest real verdicts for this combination)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Passed
L5 runtime
Unknown
Install test ran: the package installs but declares no dsh.bundle and mounts no capability — an ecosystem plugin, not a usable dsh plugin (shown as L5 · ecosystem plugin)
ecosystem plugin

ID: open-managed-agents@@openma_cli@0.5.0@dsh0.1.6-alpha.2 · profile: l3-fullscan

Issued: 2026-09-20 · expires: 2026-09-27

View checks & evidence
L1 · Found✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed
Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-09-25
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-09-25
L4 · Install tested✓ Passed
Install executed in confined sandbox✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-19
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · channel GitHub source · outcome ran · exit 0
check took: 23.5s
Install succeeded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-19
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · channel GitHub source · outcome ran · exit 0
check took: 23.5s
Installed artifact confirmed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-19
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · channel GitHub source · outcome ran · exit 0
check took: 23.5s
L5 · Run tested? Unknown

not present in web-profile loader inventory

Sandbox install passed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-19
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · install mode reused L4 scratch
check took: 79ms
Web boot ready✓ Passed
Source: DSH runtime · Method: web boot · Captured 2026-09-19
ready line dsh web: http://127.0.0.1:56127/?token=…
HTTP endpoint served✓ Passed
Source: DSH runtime · Method: HTTP request · Captured 2026-09-19
path / · HTTP 200 · took 79ms
Plugin active in inventory? Unknown
Source: DSH runtime · Method: plugin inventory query · Captured 2026-09-19
verdict not-found · entries 149
phases: active 121 · null 28
not present in web-profile loader inventory

L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.

○dsh 0.1.6-alpha.12026-09-16ecosystem plugin
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: 0.1.6-alpha.1
  • • Plugin artifact: github · https://github.com/openma-ai/open-managed-agents#@openma/cli@0.5.0
Levels (L1–L3 plugin-level static archive · L4/L5 newest real verdicts for this combination)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Passed
L5 runtime
Unknown
Install test ran: the package installs but declares no dsh.bundle and mounts no capability — an ecosystem plugin, not a usable dsh plugin (shown as L5 · ecosystem plugin)
ecosystem plugin

ID: open-managed-agents@@openma_cli@0.5.0@dsh0.1.6-alpha.1 · profile: l4-sandbox

Issued: 2026-09-16 · expires: 2026-09-23

View checks & evidence
L1 · Found✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed
Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-09-25
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-09-25
L4 · Install tested✓ Passed
Install executed in confined sandbox✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-16
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · channel GitHub source · outcome ran · exit 0
check took: 31.7s
Install succeeded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-16
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · channel GitHub source · outcome ran · exit 0
check took: 31.7s
Installed artifact confirmed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-16
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · channel GitHub source · outcome ran · exit 0
check took: 31.7s
L5 · Run tested? Unknown

not present in web-profile loader inventory

Sandbox install passed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-16
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · install mode reused L4 scratch
check took: 206ms
Web boot ready✓ Passed
Source: DSH runtime · Method: web boot · Captured 2026-09-16
ready line dsh web: http://127.0.0.1:49709/?token=…
HTTP endpoint served✓ Passed
Source: DSH runtime · Method: HTTP request · Captured 2026-09-16
path / · HTTP 200 · took 206ms
Plugin active in inventory? Unknown
Source: DSH runtime · Method: plugin inventory query · Captured 2026-09-16
verdict not-found · entries 149
phases: active 121 · null 28
not present in web-profile loader inventory

L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.

○dsh 0.1.5-rc.22026-09-11ecosystem plugin
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: 0.1.5-rc.2
  • • Plugin artifact: github · https://github.com/openma-ai/open-managed-agents#@openma/cli@0.5.0
Levels (L1–L3 plugin-level static archive · L4/L5 newest real verdicts for this combination)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Passed
L5 runtime
Unknown
Install test ran: the package installs but declares no dsh.bundle and mounts no capability — an ecosystem plugin, not a usable dsh plugin (shown as L5 · ecosystem plugin)
ecosystem plugin

ID: open-managed-agents@@openma_cli@0.5.0@dsh0.1.5-rc.2 · profile: l4-sandbox

Issued: 2026-09-11 · expires: 2026-09-18

View checks & evidence
L1 · Found✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed
Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-09-25
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-09-25
L4 · Install tested✓ Passed
Install executed in confined sandbox✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-11
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · channel GitHub source · outcome ran · exit 0
check took: 33.7s
Install succeeded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-11
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · channel GitHub source · outcome ran · exit 0
check took: 33.7s
Installed artifact confirmed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-11
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · channel GitHub source · outcome ran · exit 0
check took: 33.7s
L5 · Run tested? Unknown

not present in web-profile loader inventory

Sandbox install passed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-11
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · install mode reused L4 scratch
check took: 27ms
Web boot ready✓ Passed
Source: DSH runtime · Method: web boot · Captured 2026-09-11
ready line dsh web: http://127.0.0.1:55452/?token=…
HTTP endpoint served✓ Passed
Source: DSH runtime · Method: HTTP request · Captured 2026-09-11
path / · HTTP 200 · took 27ms
Plugin active in inventory? Unknown
Source: DSH runtime · Method: plugin inventory query · Captured 2026-09-11
verdict not-found · entries 149
phases: active 121 · null 28
not present in web-profile loader inventory

L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.

○dsh 0.1.3-alpha.22026-09-08ecosystem plugin
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: 0.1.3-alpha.2
  • • Plugin artifact: github · https://github.com/openma-ai/open-managed-agents#@openma/cli@0.5.0
Levels (L1–L3 plugin-level static archive · L4/L5 newest real verdicts for this combination)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Passed
L5 runtime
Unknown
Install test ran: the package installs but declares no dsh.bundle and mounts no capability — an ecosystem plugin, not a usable dsh plugin (shown as L5 · ecosystem plugin)
ecosystem plugin

ID: open-managed-agents@@openma_cli@0.5.0@dsh0.1.3-alpha.2 · profile: l4-sandbox

Issued: 2026-09-08 · expires: 2026-09-15

View checks & evidence
L1 · Found✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed
Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-09-25
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-09-25
L4 · Install tested✓ Passed
Install executed in confined sandbox✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-08
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · channel GitHub source · outcome ran · exit 0
check took: 56.4s
Install succeeded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-08
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · channel GitHub source · outcome ran · exit 0
check took: 56.4s
Installed artifact confirmed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-08
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · channel GitHub source · outcome ran · exit 0
check took: 56.4s
L5 · Run tested? Unknown

not present in web-profile loader inventory

Sandbox install passed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-08
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · install mode reused L4 scratch
check took: 51ms
Web boot ready✓ Passed
Source: DSH runtime · Method: web boot · Captured 2026-09-08
ready line dsh web: http://127.0.0.1:53269/?token=…
HTTP endpoint served✓ Passed
Source: DSH runtime · Method: HTTP request · Captured 2026-09-08
path / · HTTP 200 · took 51ms
Plugin active in inventory? Unknown
Source: DSH runtime · Method: plugin inventory query · Captured 2026-09-08
verdict not-found · entries 149
phases: active 121 · null 28
not present in web-profile loader inventory

L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.

○dsh 0.1.3-alpha.12026-09-07ecosystem plugin
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: 0.1.3-alpha.1
  • • Plugin artifact: github · https://github.com/openma-ai/open-managed-agents#@openma/cli@0.5.0
Levels (L1–L3 plugin-level static archive · L4/L5 newest real verdicts for this combination)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Passed
L5 runtime
Unknown
Install test ran: the package installs but declares no dsh.bundle and mounts no capability — an ecosystem plugin, not a usable dsh plugin (shown as L5 · ecosystem plugin)
ecosystem plugin

ID: open-managed-agents@@openma_cli@0.5.0@dsh0.1.3-alpha.1 · profile: l4-sandbox

Issued: 2026-09-07 · expires: 2026-09-14

View checks & evidence
L1 · Found✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed
Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-09-25
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-09-25
L4 · Install tested✓ Passed
Install executed in confined sandbox✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-07
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · channel GitHub source · outcome ran · exit 0
check took: 28.4s
Install succeeded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-07
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · channel GitHub source · outcome ran · exit 0
check took: 28.4s
Installed artifact confirmed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-07
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · channel GitHub source · outcome ran · exit 0
check took: 28.4s
L5 · Run tested? Unknown

not present in web-profile loader inventory

Sandbox install passed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-07
spec github:openma-ai/open-managed-agents#@openma/cli@0.5.0 · install mode reused L4 scratch
check took: 77ms
Web boot ready✓ Passed
Source: DSH runtime · Method: web boot · Captured 2026-09-07
ready line dsh web: http://127.0.0.1:49716/?token=…
HTTP endpoint served✓ Passed
Source: DSH runtime · Method: HTTP request · Captured 2026-09-07
path / · HTTP 200 · took 77ms
Plugin active in inventory? Unknown
Source: DSH runtime · Method: plugin inventory query · Captured 2026-09-07
verdict not-found · entries 150
phases: active 122 · null 28
not present in web-profile loader inventory

L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.

Author badges

Embed the official badges in your README to showcase security & install-test status:

dsh.so risk
`[![dsh.so risk](https://www.dsh.so/badge/open-managed-agents.svg)](https://www.dsh.so/artifact/open-managed-agents/)`

Security Report

Automated static scan, not manual review.

DSH.SO AUDITPASSED0f4240
Automated review · daily
PASSED

No critical or warning findings in the automated scan. The result is valid only for the version shown under “scanned version”.

0 critical·0 warning·0 info·15 files scanned
plugin versionv0.1.0
scanned version@openma/cli@0.5.0git2026-09-26
current version@openma/cli@0.5.0same version
rulesetdsh-static:73b7d4a831 rules

The scan result is valid for the scanned commit. New commits within 7 days are tolerated (the rating still counts); after 7 days without a rescan the badge shows outdated.

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk details

• Static heuristic scan: pending

• Dependency vulnerabilities: —

• Hardcoded secrets: —

• Supply chain risks: —

⚠ Static scan not run yet — results will appear here.

Activity

Last commit 2026-09-28 · activity: Active

• Repo created: 2026-04-10

• Stars: ★ 308 · Forks: 42

• Health: Active — committed within last 30 days

Source

GitHub: github.com/openma-ai/open-managed-agents

Was this page helpful?