configuring-opencode
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents the platform's ability to ingest configuration and instructions from external sources, which constitutes a potential surface for indirect prompt injection if the remote sources are compromised.
- Ingestion points: Configuration files (
opencode.json), remote skill URLs (https://example.com/.well-known/skills/), and remote instruction URLs (https://example.com/shared-rules.md) defined in SKILL.md. - Boundary markers: The documentation does not explicitly detail delimiters or sanitization for these external inputs.
- Capability inventory: The skill describes capabilities including file system access, network requests via MCP, and plugin execution.
- Sanitization: Not explicitly addressed in the provided configuration documentation.
- [EXTERNAL_DOWNLOADS]: The documentation explains how to configure the platform to fetch and load code or data from remote network locations.
- Evidence: Mentions configuring skills from remote URLs and loading instructions from external Markdown files.
- Evidence: Describes the configuration of MCP (Model Context Protocol) servers that can be remote HTTP/SSE endpoints or local tools installed via NPM.
- [DYNAMIC_EXECUTION]: The skill describes the platform's native support for loading and executing TypeScript or JavaScript plugins and custom CLI tools.
- Evidence: SKILL.md documents plugin discovery in local directories and loading via npm packages or file URLs.
- Evidence: Documents the use of
{file:path}and{env:VARIABLE}substitutions within configuration files to dynamically inject content or secrets into the runtime environment.
Audit Metadata