opencode-qa
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalyreferences/server-api.md
LOWAnomalyLOW
references/server-api.md
This is operational API documentation, not executable source code, and it contains no evidence of malware or intentional malicious behavior. It documents a highly privileged local automation server. Security concerns are deployment-related: authentication is disabled when the password variable is absent, credentials may be placed in URLs, and caller-controlled workspace routing plus shell and PTY endpoints require strict access control and directory validation.
Confidence: 99%Severity: 58%
Audit Metadata