Audit Report
OpenInterpreter/open-interpreter
e00f08e2ed54 · ran in 27.3s · bundle 01a29b22
Overall score
1.7 /4
Partial
Risk class
HIGH
1
Code passed
9 / 31
Attestation Yes
0
Outstanding ext.
1
CODE-CHECKED CLAUSES
- Strong7
- Adequate2
- Partial7
- Inadequate4
- Absent11
ATTESTATION QUESTIONS
- Yes0
- No0
- Not Applicable0
- Outstanding0
Harm
Don't hurt people
1.8/4
Partial
Truth
Don't deceive people
1.5/4
Inadequate
Responsibility
Don't abuse power
1.0/4
Inadequate
Order
Don't destabilize society
2.3/4
Partial
⚠ 1 outstanding external confirmations — required for a complete Annex IV dossier. Complete now →
Safety
Don't harm people1.6/4Partial5 clauses▸
Safety
Don't harm peoplePARTIALRisk management system established, implemented, documented EU AI Act, Art 9 skip2/3 rules2/4
▸
2/4
Why we flagged it
Composite raw score 0.45 (2/3 rules matched). Supporting docs may exist outside the repo.
▸Evidence · 2 hits— click to view code
Suggested fix · we looked for these and found none
- presence_of_risk_register
PARTIALAppropriate level of accuracy declared and tested EU AI Act, Art 15(1) skip2/3 rules2/4
▸
2/4
Why we flagged it
Composite raw score 0.45 (2/3 rules matched).
▸Evidence · 3 hits— click to view code
Suggested fix · we looked for these and found none
- metrics_documented
INADEQUATEResilience to errors, faults, inconsistencies EU AI Act, Art 15(4)0/3 rules1/4
▸
1/4
Why we flagged it
Composite raw score 0.16 (0/3 rules matched).
▸Evidence · 2 hits— click to view code
Anthropic SDK
HuggingFace Transformers
Suggested fix · we looked for these and found none
- error_handling_at_tool_boundaries
- retry_logic
- fallback_behaviour
INADEQUATERisks and benefits to people identified NIST AI RMF, Art MAP 3.41/2 rules1/4
▸
1/4
Why we flagged it
Composite raw score 0.20 (1/2 rules matched). Supporting docs may exist outside the repo.
▸Evidence · 1 hit— click to view code
Suggested fix · we looked for these and found none
- presence_of_risk_register
PARTIALAI system performance evaluated and documented NIST AI RMF, Art MEASURE 2.3 skip2/3 rules2/4
▸
2/4
Why we flagged it
Composite raw score 0.45 (2/3 rules matched).
▸Evidence · 3 hits— click to view code
Suggested fix · we looked for these and found none
- metrics_documented
Privacy
Respect boundaries2.0/4Partial5 clauses▸
Privacy
Respect boundariesSTRONGUntargeted facial image scraping for face databases EU AI Act, Art 5(1)(e)0/1 rules4/4
▸
4/4
Why we flagged it
Composite raw score 0.00 (0/1 rules matched).
▸Evidence · 1 hit— click to view code
Suggested fix · we looked for these and found none
- detect_face_image_scraping
STRONGEmotion recognition in workplace and education EU AI Act, Art 5(1)(f)0/1 rules4/4
▸
4/4
Why we flagged it
Composite raw score 0.00 (0/1 rules matched).
Suggested fix · we looked for these and found none
- detect_emotion_recognition_in_workplace_education
EXTERNALReal-time remote biometric identification in public spaces EU AI Act, Art 5(1)(h)EXT▸
Why we flagged it
Deployment context (public space, real-time, law enforcement use, judicial authorisation) is operational, not knowable from code. Always external.
ABSENTData and data governance practices documented EU AI Act, Art 100/3 rules0/4
▸
0/4
Why we flagged it
Composite raw score 0.10 (0/3 rules matched). Supporting docs may exist outside the repo.
▸Evidence · 2 hits— click to view code
python -c "import urllib.request; exec(urllib.request.urlopen('$INSTALL_URL').read())" # elif command -v perl &> /dev/null; then #rllib.request; exec(urllib.request.urlopen('$INSTALL_URL').read())" # elif command -v perl &> /dev/null; then # echo "Using PerlSuggested fix · we looked for these and found none
- presence_of_data_card
- data_loading_code_quality
- bias_evaluation_present
ABSENTPrivacy risk of the AI system evaluated NIST AI RMF, Art MEASURE 2.80/2 rules0/4
▸
0/4
Why we flagged it
Composite raw score 0.00 (0/2 rules matched).
Suggested fix · we looked for these and found none
- pii_redaction_present
- privacy_documentation
Transparency
Don't deceive people1.3/4Inadequate6 clauses▸
Transparency
Don't deceive peopleSTRONGSubliminal techniques distorting behaviour EU AI Act, Art 5(1)(a)0/1 rules4/4
▸
4/4
Why we flagged it
Composite raw score 0.00 (0/1 rules matched).
Suggested fix · we looked for these and found none
- detect_manipulative_prompt_patterns
ADEQUATETransparent operation and instructions for use EU AI Act, Art 133/3 rules3/4
▸
3/4
Why we flagged it
Composite raw score 0.75 (3/3 rules matched). Supporting docs may exist outside the repo.
▸Evidence · 3 hits— click to view code
2 required sections present
INADEQUATEUsers informed they are interacting with an AI EU AI Act, Art 50(1)1/2 rules1/4
▸
1/4
Why we flagged it
Composite raw score 0.20 (1/2 rules matched).
▸Evidence · 1 hit— click to view code
Suggested fix · we looked for these and found none
- ai_disclosure_in_user_facing_strings
ABSENTAI-generated content marked as such, machine-readable EU AI Act, Art 50(2)0/2 rules0/4
▸
0/4
Why we flagged it
Composite raw score 0.00 (0/2 rules matched).
Suggested fix · we looked for these and found none
- c2pa_or_watermark_library_imported
- provenance_metadata_written_to_outputs
ABSENTEmotion recognition / biometric categorisation disclosure EU AI Act, Art 50(3)0/1 rules0/4
▸
0/4
Why we flagged it
Composite raw score 0.00 (0/1 rules matched).
▸Evidence · 1 hit— click to view code
Suggested fix · we looked for these and found none
- emotion_or_biometric_disclosure_string
ABSENTDeepfake content labelled as artificially generated EU AI Act, Art 50(4)0/1 rules0/4
▸
0/4
Why we flagged it
Composite raw score 0.00 (0/1 rules matched).
Suggested fix · we looked for these and found none
- deepfake_label_on_outputs
Auditability
Actions must be traceable1.6/4Partial5 clauses▸
Auditability
Actions must be traceableINADEQUATETechnical documentation drawn up before placing on market EU AI Act, Art 111/3 rules1/4
▸
1/4
Why we flagged it
Composite raw score 0.15 (1/3 rules matched). Supporting docs may exist outside the repo.
▸Evidence · 1 hit— click to view code
2 required sections present
Suggested fix · we looked for these and found none
- presence_of_model_card
- architecture_docs
PARTIALAutomatic recording of events over the lifetime EU AI Act, Art 12(1) skip1/3 rules2/4
▸
2/4
Why we flagged it
Composite raw score 0.42 (1/3 rules matched).
▸Evidence · 5 hits— click to view code
ssed_lines.append(f'console.log("##active_line{i}##");') processed_lines.append(line) # Join lines to form the processe}} catch (e) {{ console.log(e); }} console.log("##end_of_execution##"); """ return codeconsole.log(e); }} console.log("##end_of_execution##"); """ return codessed_lines.append(f'console.log("##active_line{i}##");') processed_lines.append(line) # Join lines to form the processe}} catch (e) {{ console.log(e); }} console.log("##end_of_execution##"); """ return codeSuggested fix · we looked for these and found none
- structured_logging_imported
- logging_persistent_sink
PARTIALLogging ensures traceability appropriate to risk EU AI Act, Art 12(2) skip2/3 rules2/4
▸
2/4
Why we flagged it
Composite raw score 0.51 (2/3 rules matched). Supporting docs may exist outside the repo.
▸Evidence · 7 hits— click to view code
ssed_lines.append(f'console.log("##active_line{i}##");') processed_lines.append(line) # Join lines to form the processe}} catch (e) {{ console.log(e); }} console.log("##end_of_execution##"); """ return codeconsole.log(e); }} console.log("##end_of_execution##"); """ return codehis """ import ast import logging import os import queue import re import sys import threading import time import traceback os.environ["LI
999999 import json import logging import subprocess import time import uuid import requests import tokentrim as tt from .run_text_llm imp
…and 2 more.
Suggested fix · we looked for these and found none
- logs_include_request_id
ADEQUATEContext of use established and understood NIST AI RMF, Art MAP 1.1 skip2/2 rules3/4
▸
3/4
Why we flagged it
Composite raw score 0.70 (2/2 rules matched). Supporting docs may exist outside the repo.
▸Evidence · 2 hits— click to view code
2 required sections present
ABSENTPost-deployment monitoring, appeal and override, change management NIST AI RMF, Art MANAGE 4.10/4 rules0/4
▸
0/4
Why we flagged it
Composite raw score 0.06 (0/4 rules matched).
Suggested fix · we looked for these and found none
- feedback_capture_present
- override_path_present
- structured_logging_imported
- versioning_visible
Accountability
Don't abuse power1.3/4Inadequate3 clauses▸
Accountability
Don't abuse powerPARTIALDeployer log-retention capability supported EU AI Act, Art 26(6) skip1/1 rules2/4
▸
2/4
Why we flagged it
Composite raw score 0.50 (1/1 rules matched). Supporting docs may exist outside the repo.
▸Evidence · 2 hits— click to view code
ssed_lines.append(f'console.log("##active_line{i}##");') processed_lines.append(line) # Join lines to form the processe}} catch (e) {{ console.log(e); }} console.log("##end_of_execution##"); """ return codeABSENTRisk management process documented and accountable NIST AI RMF, Art GOVERN 1.40/2 rules0/4
▸
0/4
Why we flagged it
Composite raw score 0.00 (0/2 rules matched). Supporting docs may exist outside the repo.
Suggested fix · we looked for these and found none
- presence_of_risk_register
- risk_owner_assignment
PARTIALOngoing monitoring and periodic review of risk management NIST AI RMF, Art GOVERN 1.5 skip1/2 rules2/4
▸
2/4
Why we flagged it
Composite raw score 0.50 (1/2 rules matched). Supporting docs may exist outside the repo.
▸Evidence · 1 hit— click to view code
Suggested fix · we looked for these and found none
- drift_monitoring_present
Human Oversight
Humans stay in control0.0/4Absent1 clause▸
Human Oversight
Humans stay in controlABSENTEffective human oversight designed and built-in EU AI Act, Art 14(1)0/3 rules0/4
▸
0/4
Why we flagged it
Composite raw score 0.00 (0/3 rules matched).
Suggested fix · we looked for these and found none
- human_in_loop_hooks_present
- oversight_ui_present
- tool_calls_have_dry_run
Fairness
Treat people fairly3.2/4Adequate5 clauses▸
Fairness
Treat people fairlySTRONGExploiting vulnerabilities (age, disability, socio-economic) EU AI Act, Art 5(1)(b)0/1 rules4/4
▸
4/4
Why we flagged it
Composite raw score 0.00 (0/1 rules matched).
Suggested fix · we looked for these and found none
- detect_protected_attribute_targeting
STRONGSocial scoring leading to detrimental treatment EU AI Act, Art 5(1)(c)0/1 rules4/4
▸
4/4
Why we flagged it
Composite raw score 0.00 (0/1 rules matched). Supporting docs may exist outside the repo.
Suggested fix · we looked for these and found none
- detect_scoring_with_persistent_user_state
STRONGPredictive policing solely from profiling EU AI Act, Art 5(1)(d)0/1 rules4/4
▸
4/4
Why we flagged it
Composite raw score 0.00 (0/1 rules matched).
Suggested fix · we looked for these and found none
- detect_crime_risk_scoring_from_profile
STRONGBiometric categorisation by protected attributes EU AI Act, Art 5(1)(g)0/1 rules4/4
▸
4/4
Why we flagged it
Composite raw score 0.00 (0/1 rules matched).
Suggested fix · we looked for these and found none
- detect_biometric_categorisation_by_protected_attrs
ABSENTFairness and bias evaluated NIST AI RMF, Art MEASURE 2.110/1 rules0/4
▸
0/4
Why we flagged it
Composite raw score 0.00 (0/1 rules matched).
Suggested fix · we looked for these and found none
- bias_evaluation_present
Security & Governance
Don't destabilize society0.0/4Absent2 clauses▸
Security & Governance
Don't destabilize societyABSENTCybersecurity measures appropriate to circumstances EU AI Act, Art 15(5)0/4 rules0/4
▸
0/4
Why we flagged it
Composite raw score 0.08 (0/4 rules matched).
▸Evidence · 1 hit— click to view code
litellm.exceptions.RateLimitError) and ("exceeded" in str(e).lower() or "insufficient_quota" iSuggested fix · we looked for these and found none
- prompt_injection_defences
- rate_limiting
- secrets_not_in_prompts
- adversarial_eval_present
ABSENTSecurity and resilience evaluated NIST AI RMF, Art MEASURE 2.70/3 rules0/4
▸
0/4
Why we flagged it
Composite raw score 0.08 (0/3 rules matched).
▸Evidence · 1 hit— click to view code
litellm.exceptions.RateLimitError) and ("exceeded" in str(e).lower() or "insufficient_quota" iSuggested fix · we looked for these and found none
- prompt_injection_defences
- adversarial_eval_present
- rate_limiting