opencode-delegation

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation instructs the user to install the opencode-ai package globally using npm (npm install -g opencode-ai@latest).
  • [COMMAND_EXECUTION]: The skill executes several shell commands to interact with the OpenCode tool, including opencode run, opencode auth list, and opencode --version. It also runs a local Python script using uv run python scripts/delegation_executor.py.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied prompts and passes them to the opencode command-line interface, creating a potential vector for indirect injection.
  • Ingestion points: The PROMPT argument in the Makefile example and positional arguments in the opencode run command (SKILL.md).
  • Boundary markers: No delimiters or 'ignore' instructions are visible in the command construction examples to separate user input from the execution context.
  • Capability inventory: The skill has the ability to execute the opencode binary, which can interact with various AI models and perform delegated tasks (SKILL.md).
  • Sanitization: There is no evidence of prompt sanitization, escaping, or validation before the user input is passed to the external tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:05 AM
Security Audit — agent-trust-hub — opencode-delegation