dispatch-opencode
Audited by Socket on Sep 16, 2026
5 alerts found:
Securityx2Anomalyx3BENIGN in purpose alignment, but medium-high operational risk. The skill’s background dispatch, daemon processing, and support for autonomous commit/push/PR-comment workflows are coherent with its stated purpose, yet they give an agent meaningful execution and real-world action capability through an external CLI.
The fragment is a task-watcher orchestration script and contains no direct evidence of credential theft, network exfiltration, persistence, cryptomining, destructive behavior, or intentional malware. However, it has meaningful command-injection and path-traversal risks if plan filenames or task IDs can be supplied by an untrusted source. The most serious issues are interpolation of PLAN_FILE and TASK_ID into Python code and unsanitized use of TASK_ID in filesystem paths. These should be fixed by passing values as Python arguments, validating task IDs against a strict allowlist, and enforcing path containment. The assessed risk concerns exploitable input handling, not confirmed malicious intent.
The fragment appears to be a task-plan dispatcher rather than intentionally malicious code. It contains meaningful security weaknesses: unsafe interpolation into generated Python source, unvalidated task IDs used in filesystem paths, unescaped JSON construction, and insufficient validation of TSV-sensitive fields and prompt paths. Exploitation generally requires control of the plan path or plan contents and may depend on dispatch.sh behavior. The file itself shows no direct malware indicators, but it should be hardened before processing untrusted plans.
The fragment is an orchestration script rather than apparent malware. Its main risk is delegated execution: opencode is run with --dangerously-skip-permissions using externally supplied prompt and path parameters, so the overall behavior can be dangerous if those inputs or the PATH-resolved binary are untrusted. The Python path interpolation and lack of cleanup trap are secondary robustness/security issues. No direct credential theft, data exfiltration, persistence, or destructive behavior is visible in this file.
The fragment is an automation wrapper for running OpenCode and collecting results. No clear malicious behavior or embedded malware is present. The principal risks are the intentionally broad --dangerously-skip-permissions setting, exposure of a server password via process arguments, reliance on correctly shell-quoted template values, and unsafe interpolation of TASK_DIR into Python source. These warrant hardening and review of the surrounding task-generation and OpenCode configuration, but the supplied code alone does not demonstrate a supply-chain attack.