opencode-agents

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but it acts as a delegation wrapper to an external agent/CLI stack and even suggests installing that stack if missing. The main risks are transitive trust, local-context forwarding to remote agents, and indirect prompt-injection exposure from web-research subagents; there is no clear evidence of credential theft or overtly malicious behavior.

Confidence: 81%Severity: 58%
Audit Metadata
Analyzed At
Apr 12, 2026, 05:57 AM
Package URL
pkg:socket/skills-sh/axot%2Fagent-skills%2Fopencode-agents%2F@31e33ba2f547fa40bf103b035286d47941ade02d