opencode-expert
Pass
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: LOW
Full Analysis
- [SAFE] (SAFE): No malicious patterns, prompt injections, or obfuscated content were detected. The skill provides standard documentation for the OpenCode ecosystem.\n- [COMMAND_EXECUTION] (INFO): The documentation mentions a 'bash' tool and various CLI commands (e.g.,
opencode run). These are standard capabilities for a developer-oriented AI agent and do not indicate a security vulnerability in the context of documentation.\n- [EXTERNAL_DOWNLOADS] (INFO): References theopencode upgradecommand and the ability to add MCP servers. These are legitimate software maintenance and extensibility features.\n- [DATA_EXFILTRATION] (INFO): Documents a 'webfetch' tool and a/sharecommand. These represent network-enabled features of the underlying tool rather than malicious exfiltration attempts within the skill itself.
Audit Metadata