opencode

Warn

Audited by Socket on Mar 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The fragment is a comprehensive configuration/documentation for the OpenCode agent framework. It is coherent with its stated purpose and reflects legitimate architecture for extensible agents, skills, tools, and provider integration. However, notable security considerations exist: automatic updates, external provider endpoints, MCP remote tooling, and environment-based credential interpolation create external data flows and potential credential exposure. The presence of local plugin paths and remote dependencies increases attack surface and requires rigorous controls (version pinning, signed updates, least-privilege permissions, secret management, and integrity verification). Overall, the risk is moderate with actionable hardening steps recommended before deployment.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 3, 2026, 08:37 AM
Package URL
pkg:socket/skills-sh/kortix-ai%2Fkortix-registry%2Fopencode%2F@2250a47bce44a9f73e9d32b9a125558e6224b2a9