AGENT LAB: SKILLS

opencode-expert

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • NO_CODE (SAFE): The skill consists entirely of Markdown documentation files (SKILL.md and the references/ directory). No scripts, binaries, or other executable code are included in the package.
  • COMMAND_EXECUTION (SAFE): The documentation describes the use of a bash tool for executing shell commands and a write tool for file modifications. These are documented as intended features of the OpenCode agent's 'Build' mode and do not represent a vulnerability within the skill itself.
  • EXTERNAL_DOWNLOADS (SAFE): The CLI reference documentation mentions administrative commands such as opencode upgrade for binary updates and opencode mcp add for extending tool capabilities via Model Context Protocol servers.
  • DATA_EXFILTRATION (SAFE): The documentation describes a webfetch tool for reading web content, but contains no instructions or patterns that would facilitate the unauthorized exfiltration of sensitive data.
  • PROMPT_INJECTION (SAFE): No override markers, role-play injections, or instructions to bypass safety filters were detected in the documentation content.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 05:13 PM