opencode-delegate

Warn

Audited by Socket on Aug 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly aligned with its stated purpose, but it delegates coding to an external authenticated CLI with auto-approved write actions and optional curl|bash installation. Data flows appear consistent with OpenCode’s official ecosystem rather than a credential-harvesting proxy, so this is not clearly malicious; the main concerns are supply-chain trust, credential forwarding to the CLI, and unattended repository modification.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Aug 17, 2026, 07:09 PM
Package URL
pkg:socket/skills-sh/amelnagdy%2Fdelegate-skills%2Fopencode-delegate%2F@bb4c60bc956fa481196a4c1ca0bcb0ea383f0d3e22acc1915f862fe9ba349475
Security Audit — socket — opencode-delegate