configuring-opencode

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents the platform's ability to ingest configuration and instructions from external sources, which constitutes a potential surface for indirect prompt injection if the remote sources are compromised.
  • Ingestion points: Configuration files (opencode.json), remote skill URLs (https://example.com/.well-known/skills/), and remote instruction URLs (https://example.com/shared-rules.md) defined in SKILL.md.
  • Boundary markers: The documentation does not explicitly detail delimiters or sanitization for these external inputs.
  • Capability inventory: The skill describes capabilities including file system access, network requests via MCP, and plugin execution.
  • Sanitization: Not explicitly addressed in the provided configuration documentation.
  • [EXTERNAL_DOWNLOADS]: The documentation explains how to configure the platform to fetch and load code or data from remote network locations.
  • Evidence: Mentions configuring skills from remote URLs and loading instructions from external Markdown files.
  • Evidence: Describes the configuration of MCP (Model Context Protocol) servers that can be remote HTTP/SSE endpoints or local tools installed via NPM.
  • [DYNAMIC_EXECUTION]: The skill describes the platform's native support for loading and executing TypeScript or JavaScript plugins and custom CLI tools.
  • Evidence: SKILL.md documents plugin discovery in local directories and loading via npm packages or file URLs.
  • Evidence: Documents the use of {file:path} and {env:VARIABLE} substitutions within configuration files to dynamically inject content or secrets into the runtime environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:49 PM
Security Audit — agent-trust-hub — configuring-opencode