opencode-delegation
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documentation instructs the user to install the
opencode-aipackage globally using npm (npm install -g opencode-ai@latest). - [COMMAND_EXECUTION]: The skill executes several shell commands to interact with the OpenCode tool, including
opencode run,opencode auth list, andopencode --version. It also runs a local Python script usinguv run python scripts/delegation_executor.py. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied prompts and passes them to the
opencodecommand-line interface, creating a potential vector for indirect injection. - Ingestion points: The
PROMPTargument in the Makefile example and positional arguments in theopencode runcommand (SKILL.md). - Boundary markers: No delimiters or 'ignore' instructions are visible in the command construction examples to separate user input from the execution context.
- Capability inventory: The skill has the ability to execute the
opencodebinary, which can interact with various AI models and perform delegated tasks (SKILL.md). - Sanitization: There is no evidence of prompt sanitization, escaping, or validation before the user input is passed to the external tool.
Audit Metadata