opencode-agent-creator
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill designs agents to process untrusted external data such as codebase files, logs, and web content. It implements mitigation strategies by using a 'cold-context' contract, where subagents are isolated from the primary conversation context, and structural XML markers to define task boundaries, which reduces the risk of malicious data influencing agent behavior.
- [COMMAND_EXECUTION]: Provides templates for agents capable of executing shell commands. The instructions explicitly recommend a least-privilege model, advising users to deny shell access by default or use restrictive whitelists for specific tools like git.
- [DYNAMIC_EXECUTION]: Documented patterns allow for the creation of custom TypeScript tools and the generation of agent configuration files. This functionality is a core feature for extending agent capabilities within the OpenCode ecosystem and is presented as a developer extension mechanism.
- [EXTERNAL_DOWNLOADS]: Includes research agent examples that fetch data from external services such as Jina Reader and Tavily to supplement the agent's knowledge. These are standard integrations for research-oriented agents and are documented for legitimate use.
Audit Metadata