opencode-session-db

Warn

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill accesses sensitive local application data at ~/.local/share/opencode/opencode.db, which contains private message history, project worktrees, and tool outputs from past user sessions.
  • [COMMAND_EXECUTION]: The bundled script scripts/query.sh contains a SQL injection vulnerability. User-controlled arguments are directly interpolated into SQL strings (e.g., WHERE m.session_id = '${ARG}' and LIKE '%${ARG}%') without sanitization or parameterization. An attacker could provide malicious input to manipulate the database queries and extract data outside the intended scope, although the impact is limited to read operations by the -readonly flag.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: Historical chat messages and tool outputs are retrieved from the message and part tables in SKILL.md and scripts/query.sh.
  • Boundary markers: No boundary markers or 'ignore' instructions are used to separate historical data from current instructions, potentially leading the agent to follow instructions embedded in old sessions.
  • Capability inventory: The skill allows execution of the sqlite3 CLI and access to local file paths.
  • Sanitization: The skill does not perform any validation or sanitization of the JSON data (text and tool outputs) retrieved from the database before processing it.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 28, 2026, 11:50 AM
Security Audit — agent-trust-hub — opencode-session-db