opencode-qa

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
references/server-api.md

This is operational API documentation, not executable source code, and it contains no evidence of malware or intentional malicious behavior. It documents a highly privileged local automation server. Security concerns are deployment-related: authentication is disabled when the password variable is absent, credentials may be placed in URLs, and caller-controlled workspace routing plus shell and PTY endpoints require strict access control and directory validation.

Confidence: 99%Severity: 58%
Audit Metadata
Analyzed At
Sep 15, 2026, 01:36 PM
Package URL
pkg:socket/skills-sh/code-yeongyu%2Foh-my-openagent%2Fopencode-qa%2F@7291821b51e5a049a0c918946655c672eed1df2691c05d680076ae8218008499
Security Audit — socket — opencode-qa