8RR8← All audits

Audit Report

OpenInterpreter/open-interpreter

e00f08e2ed54 · ran in 27.3s · bundle 01a29b22

Deterministic · 8 ambiguous skipped
Complete audit →

Overall score

1.7 /4

Partial

Risk class

HIGH

1

Code passed

9 / 31

Attestation Yes

0

Outstanding ext.

1

Overall completion status
Code findings on the left; user-attested external evidence on the right.
31

CODE-CHECKED CLAUSES

  • Strong7
  • Adequate2
  • Partial7
  • Inadequate4
  • Absent11
0

ATTESTATION QUESTIONS

  • Yes0
  • No0
  • Not Applicable0
  • Outstanding0

Harm

Don't hurt people

1.8/4

Partial

Truth

Don't deceive people

1.5/4

Inadequate

Responsibility

Don't abuse power

1.0/4

Inadequate

Order

Don't destabilize society

2.3/4

Partial

1 outstanding external confirmations — required for a complete Annex IV dossier. Complete now →

Safety

Don't harm people
1.6/4Partial5 clauses
PARTIAL
Risk management system established, implemented, documented EU AI Act, Art 9
skip
2/3 rules

2/4

Why we flagged it

Composite raw score 0.45 (2/3 rules matched). Supporting docs may exist outside the repo.

Confidence
100%
Evidence · 2 hits— click to view code
SECURITY.md
presence_of_threat_model
View on GitHub →
.github/workflows/python-package.yml
ci_eval_gates
View on GitHub →

Suggested fix · we looked for these and found none

  • presence_of_risk_register
PARTIAL
Appropriate level of accuracy declared and tested EU AI Act, Art 15(1)
skip
2/3 rules

2/4

Why we flagged it

Composite raw score 0.45 (2/3 rules matched).

Confidence
100%
Evidence · 3 hits— click to view code
tests/
eval_suite_present
View on GitHub →
README.md
metrics_documented
View on GitHub →
.github/workflows/python-package.yml
ci_eval_gates
View on GitHub →

Suggested fix · we looked for these and found none

  • metrics_documented
INADEQUATE
Resilience to errors, faults, inconsistencies EU AI Act, Art 15(4)
0/3 rules

1/4

Why we flagged it

Composite raw score 0.16 (0/3 rules matched).

Confidence
81%
Evidence · 2 hits— click to view code
pyproject.toml
manifest_framework_dep
View on GitHub →

Anthropic SDK

pyproject.toml
manifest_framework_dep
View on GitHub →

HuggingFace Transformers

Suggested fix · we looked for these and found none

  • error_handling_at_tool_boundaries
  • retry_logic
  • fallback_behaviour
INADEQUATE
Risks and benefits to people identified NIST AI RMF, Art MAP 3.4
1/2 rules

1/4

Why we flagged it

Composite raw score 0.20 (1/2 rules matched). Supporting docs may exist outside the repo.

Confidence
80%
Evidence · 1 hit— click to view code
SECURITY.md
presence_of_threat_model
View on GitHub →

Suggested fix · we looked for these and found none

  • presence_of_risk_register
PARTIAL
AI system performance evaluated and documented NIST AI RMF, Art MEASURE 2.3
skip
2/3 rules

2/4

Why we flagged it

Composite raw score 0.45 (2/3 rules matched).

Confidence
100%
Evidence · 3 hits— click to view code
tests/
eval_suite_present
View on GitHub →
README.md
metrics_documented
View on GitHub →
.github/workflows/python-package.yml
ci_eval_gates
View on GitHub →

Suggested fix · we looked for these and found none

  • metrics_documented

Privacy

Respect boundaries
2.0/4Partial5 clauses
STRONG
Untargeted facial image scraping for face databases EU AI Act, Art 5(1)(e)
0/1 rules

4/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%
Evidence · 1 hit— click to view code
pyproject.toml
manifest_biometric_dep
View on GitHub →

Suggested fix · we looked for these and found none

  • detect_face_image_scraping
STRONG
Emotion recognition in workplace and education EU AI Act, Art 5(1)(f)
0/1 rules

4/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • detect_emotion_recognition_in_workplace_education
EXTERNAL
Real-time remote biometric identification in public spaces EU AI Act, Art 5(1)(h)
EXT

Why we flagged it

Deployment context (public space, real-time, law enforcement use, judicial authorisation) is operational, not knowable from code. Always external.

Confidence
100%
ABSENT
Data and data governance practices documented EU AI Act, Art 10
0/3 rules

0/4

Why we flagged it

Composite raw score 0.10 (0/3 rules matched). Supporting docs may exist outside the repo.

Confidence
75%
Evidence · 2 hits— click to view code
installers/oi-mac-installer.sh:70
http_external_io
View on GitHub →
python -c "import urllib.request; exec(urllib.request.urlopen('$INSTALL_URL').read())" # elif command -v perl &> /dev/null; then #
installers/oi-mac-installer.sh:70
http_external_io
View on GitHub →
rllib.request; exec(urllib.request.urlopen('$INSTALL_URL').read())" # elif command -v perl &> /dev/null; then # echo "Using Perl

Suggested fix · we looked for these and found none

  • presence_of_data_card
  • data_loading_code_quality
  • bias_evaluation_present
ABSENT
Privacy risk of the AI system evaluated NIST AI RMF, Art MEASURE 2.8
0/2 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/2 rules matched).

Confidence
60%

Suggested fix · we looked for these and found none

  • pii_redaction_present
  • privacy_documentation

Transparency

Don't deceive people
1.3/4Inadequate6 clauses
STRONG
Subliminal techniques distorting behaviour EU AI Act, Art 5(1)(a)
0/1 rules

4/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • detect_manipulative_prompt_patterns
ADEQUATE
Transparent operation and instructions for use EU AI Act, Art 13
3/3 rules

3/4

Why we flagged it

Composite raw score 0.75 (3/3 rules matched). Supporting docs may exist outside the repo.

Confidence
90%
Evidence · 3 hits— click to view code
README.md
readme_quality
View on GitHub →

2 required sections present

README.md
output_interpretation_guidance
View on GitHub →
README.md
limitations_section_present
View on GitHub →
INADEQUATE
Users informed they are interacting with an AI EU AI Act, Art 50(1)
1/2 rules

1/4

Why we flagged it

Composite raw score 0.20 (1/2 rules matched).

Confidence
80%
Evidence · 1 hit— click to view code
README.md
ai_disclosure_in_user_facing_strings
View on GitHub →

Suggested fix · we looked for these and found none

  • ai_disclosure_in_user_facing_strings
ABSENT
AI-generated content marked as such, machine-readable EU AI Act, Art 50(2)
0/2 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/2 rules matched).

Confidence
60%

Suggested fix · we looked for these and found none

  • c2pa_or_watermark_library_imported
  • provenance_metadata_written_to_outputs
ABSENT
Emotion recognition / biometric categorisation disclosure EU AI Act, Art 50(3)
0/1 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%
Evidence · 1 hit— click to view code
README.md
emotion_or_biometric_disclosure_string
View on GitHub →

Suggested fix · we looked for these and found none

  • emotion_or_biometric_disclosure_string
ABSENT
Deepfake content labelled as artificially generated EU AI Act, Art 50(4)
0/1 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • deepfake_label_on_outputs

Auditability

Actions must be traceable
1.6/4Partial5 clauses
INADEQUATE
Technical documentation drawn up before placing on market EU AI Act, Art 11
1/3 rules

1/4

Why we flagged it

Composite raw score 0.15 (1/3 rules matched). Supporting docs may exist outside the repo.

Confidence
80%
Evidence · 1 hit— click to view code
README.md
readme_quality
View on GitHub →

2 required sections present

Suggested fix · we looked for these and found none

  • presence_of_model_card
  • architecture_docs
PARTIAL
Automatic recording of events over the lifetime EU AI Act, Art 12(1)
skip
1/3 rules

2/4

Why we flagged it

Composite raw score 0.42 (1/3 rules matched).

Confidence
100%
Evidence · 5 hits— click to view code
interpreter/core/computer/terminal/languages/javascript.py:54
log_at_tool_boundary
View on GitHub →
ssed_lines.append(f'console.log("##active_line{i}##");') processed_lines.append(line) # Join lines to form the processe
interpreter/core/computer/terminal/languages/javascript.py:65
log_at_tool_boundary
View on GitHub →
}} catch (e) {{ console.log(e); }} console.log("##end_of_execution##"); """ return code
interpreter/core/computer/terminal/languages/javascript.py:67
log_at_tool_boundary
View on GitHub →
console.log(e); }} console.log("##end_of_execution##"); """ return code
interpreter/core/computer/terminal/languages/javascript.py:54
log_at_tool_boundary
View on GitHub →
ssed_lines.append(f'console.log("##active_line{i}##");') processed_lines.append(line) # Join lines to form the processe
interpreter/core/computer/terminal/languages/javascript.py:65
log_at_tool_boundary
View on GitHub →
}} catch (e) {{ console.log(e); }} console.log("##end_of_execution##"); """ return code

Suggested fix · we looked for these and found none

  • structured_logging_imported
  • logging_persistent_sink
PARTIAL
Logging ensures traceability appropriate to risk EU AI Act, Art 12(2)
skip
2/3 rules

2/4

Why we flagged it

Composite raw score 0.51 (2/3 rules matched). Supporting docs may exist outside the repo.

Confidence
100%
Evidence · 7 hits— click to view code
interpreter/core/computer/terminal/languages/javascript.py:54
log_at_tool_boundary
View on GitHub →
ssed_lines.append(f'console.log("##active_line{i}##");') processed_lines.append(line) # Join lines to form the processe
interpreter/core/computer/terminal/languages/javascript.py:65
log_at_tool_boundary
View on GitHub →
}} catch (e) {{ console.log(e); }} console.log("##end_of_execution##"); """ return code
interpreter/core/computer/terminal/languages/javascript.py:67
log_at_tool_boundary
View on GitHub →
console.log(e); }} console.log("##end_of_execution##"); """ return code
interpreter/core/computer/terminal/languages/jupyter_language.py:7
import_logging
View on GitHub →
his """ import ast import logging import os import queue import re import sys import threading import time import traceback os.environ["LI
interpreter/core/llm/llm.py:15
import_logging
View on GitHub →
999999 import json import logging import subprocess import time import uuid import requests import tokentrim as tt from .run_text_llm imp

…and 2 more.

Suggested fix · we looked for these and found none

  • logs_include_request_id
ADEQUATE
Context of use established and understood NIST AI RMF, Art MAP 1.1
skip
2/2 rules

3/4

Why we flagged it

Composite raw score 0.70 (2/2 rules matched). Supporting docs may exist outside the repo.

Confidence
90%
Evidence · 2 hits— click to view code
README.md
readme_quality
View on GitHub →

2 required sections present

README.md
output_interpretation_guidance
View on GitHub →
ABSENT
Post-deployment monitoring, appeal and override, change management NIST AI RMF, Art MANAGE 4.1
0/4 rules

0/4

Why we flagged it

Composite raw score 0.06 (0/4 rules matched).

Confidence
76%

Suggested fix · we looked for these and found none

  • feedback_capture_present
  • override_path_present
  • structured_logging_imported
  • versioning_visible

Accountability

Don't abuse power
1.3/4Inadequate3 clauses
PARTIAL
Deployer log-retention capability supported EU AI Act, Art 26(6)
skip
1/1 rules

2/4

Why we flagged it

Composite raw score 0.50 (1/1 rules matched). Supporting docs may exist outside the repo.

Confidence
100%
Evidence · 2 hits— click to view code
interpreter/core/computer/terminal/languages/javascript.py:54
log_at_tool_boundary
View on GitHub →
ssed_lines.append(f'console.log("##active_line{i}##");') processed_lines.append(line) # Join lines to form the processe
interpreter/core/computer/terminal/languages/javascript.py:65
log_at_tool_boundary
View on GitHub →
}} catch (e) {{ console.log(e); }} console.log("##end_of_execution##"); """ return code
ABSENT
Risk management process documented and accountable NIST AI RMF, Art GOVERN 1.4
0/2 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/2 rules matched). Supporting docs may exist outside the repo.

Confidence
60%

Suggested fix · we looked for these and found none

  • presence_of_risk_register
  • risk_owner_assignment
PARTIAL
Ongoing monitoring and periodic review of risk management NIST AI RMF, Art GOVERN 1.5
skip
1/2 rules

2/4

Why we flagged it

Composite raw score 0.50 (1/2 rules matched). Supporting docs may exist outside the repo.

Confidence
100%
Evidence · 1 hit— click to view code
.github/workflows/python-package.yml
ci_eval_gates
View on GitHub →

Suggested fix · we looked for these and found none

  • drift_monitoring_present

Human Oversight

Humans stay in control
0.0/4Absent1 clause
ABSENT
Effective human oversight designed and built-in EU AI Act, Art 14(1)
0/3 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/3 rules matched).

Confidence
65%

Suggested fix · we looked for these and found none

  • human_in_loop_hooks_present
  • oversight_ui_present
  • tool_calls_have_dry_run

Fairness

Treat people fairly
3.2/4Adequate5 clauses
STRONG
Exploiting vulnerabilities (age, disability, socio-economic) EU AI Act, Art 5(1)(b)
0/1 rules

4/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • detect_protected_attribute_targeting
STRONG
Social scoring leading to detrimental treatment EU AI Act, Art 5(1)(c)
0/1 rules

4/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched). Supporting docs may exist outside the repo.

Confidence
55%

Suggested fix · we looked for these and found none

  • detect_scoring_with_persistent_user_state
STRONG
Predictive policing solely from profiling EU AI Act, Art 5(1)(d)
0/1 rules

4/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • detect_crime_risk_scoring_from_profile
STRONG
Biometric categorisation by protected attributes EU AI Act, Art 5(1)(g)
0/1 rules

4/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • detect_biometric_categorisation_by_protected_attrs
ABSENT
Fairness and bias evaluated NIST AI RMF, Art MEASURE 2.11
0/1 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • bias_evaluation_present

Security & Governance

Don't destabilize society
0.0/4Absent2 clauses
ABSENT
Cybersecurity measures appropriate to circumstances EU AI Act, Art 15(5)
0/4 rules

0/4

Why we flagged it

Composite raw score 0.08 (0/4 rules matched).

Confidence
78%
Evidence · 1 hit— click to view code
interpreter/core/respond.py:117
rate_limit_usage
View on GitHub →
litellm.exceptions.RateLimitError) and ("exceeded" in str(e).lower() or "insufficient_quota" i

Suggested fix · we looked for these and found none

  • prompt_injection_defences
  • rate_limiting
  • secrets_not_in_prompts
  • adversarial_eval_present
ABSENT
Security and resilience evaluated NIST AI RMF, Art MEASURE 2.7
0/3 rules

0/4

Why we flagged it

Composite raw score 0.08 (0/3 rules matched).

Confidence
73%
Evidence · 1 hit— click to view code
interpreter/core/respond.py:117
rate_limit_usage
View on GitHub →
litellm.exceptions.RateLimitError) and ("exceeded" in str(e).lower() or "insufficient_quota" i

Suggested fix · we looked for these and found none

  • prompt_injection_defences
  • adversarial_eval_present
  • rate_limiting