opencode-expert
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [Indirect Prompt Injection] (LOW): The documentation defines a toolset that combines external data ingestion with high-privilege capabilities. Ingestion points:
webfetchandreadtools (SKILL.md). Boundary markers: None specified in the guide. Capability inventory:bash(shell execution),write/edit/patch(filesystem modification), andmcp(server integration) as listed in SKILL.md. Sanitization: No sanitization or validation protocols are mentioned. - [Metadata Poisoning] (SAFE): Metadata fields (name, description) accurately reflect the content and purpose of the skill.
- [No Code] (SAFE): The skill consists exclusively of markdown documentation and does not include any scripts or executable files.
Audit Metadata