oh-my-opencode-slim
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill interacts with local configuration files such as
~/.config/opencode/opencode.jsonandoh-my-opencode-slim.jsonc, which may contain sensitive settings like API provider keys. This access is local and necessary for the skill's primary function of configuration management. - [INDIRECT_PROMPT_INJECTION]: The skill has the capability to modify prompt override files (e.g.,
orchestrator_append.md), creating a surface for instructions that could influence future agent behavior. - Ingestion points: The skill reads existing
.json,.jsonc, and.mdfiles from the user's configuration directory. - Boundary markers: No specific delimiters or sanitization of input data are mentioned, but the skill relies on the user to provide valid content.
- Capability inventory: The skill is authorized to read, create, and modify local configuration files and prompt payload files.
- Sanitization: The instructions explicitly mandate asking for user confirmation before applying any changes and preserving existing settings and formatting.
Audit Metadata