opencode-permission

Warn

Audited by Snyk on May 6, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 0.80). The skill edits the agent's permission configuration (~/.config/opencode/opencode.jsonc) to auto-approve or deny arbitrary shell commands, thereby changing the machine's security posture and enabling the agent to bypass confirmations for potentially dangerous actions (even though it doesn't require sudo), so it meaningfully risks compromising the machine state.

Issues (1)

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 6, 2026, 01:01 AM
Issues
1
Security Audit — snyk — opencode-permission