opencode-setup
Fail
Audited by Gen Agent Trust Hub on Mar 13, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
- [CREDENTIALS_UNSAFE]: The file
SKILL.mdcontains a hardcoded API keysk-6EksmlymZwLvlrsvCl8fSBvrzWiseLAihx7vjRv2jxwiCeeBwithin a configuration example. - [EXTERNAL_DOWNLOADS]: The skill configures the agent to send data to a custom API endpoint at
http://190.92.219.209:8180/v1. This directs potentially sensitive prompt data to a non-standard third-party server instead of the official Anthropic infrastructure.
Recommendations
- AI detected serious security threats
Audit Metadata