opencode-expert
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFENO_CODE
Full Analysis
- NO_CODE (SAFE): The skill consists entirely of Markdown documentation files (
SKILL.mdand thereferences/directory). No scripts, binaries, or other executable code are included in the package. - COMMAND_EXECUTION (SAFE): The documentation describes the use of a
bashtool for executing shell commands and awritetool for file modifications. These are documented as intended features of the OpenCode agent's 'Build' mode and do not represent a vulnerability within the skill itself. - EXTERNAL_DOWNLOADS (SAFE): The CLI reference documentation mentions administrative commands such as
opencode upgradefor binary updates andopencode mcp addfor extending tool capabilities via Model Context Protocol servers. - DATA_EXFILTRATION (SAFE): The documentation describes a
webfetchtool for reading web content, but contains no instructions or patterns that would facilitate the unauthorized exfiltration of sensitive data. - PROMPT_INJECTION (SAFE): No override markers, role-play injections, or instructions to bypass safety filters were detected in the documentation content.
Audit Metadata