opencode-session-db
Warn
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill accesses sensitive local application data at
~/.local/share/opencode/opencode.db, which contains private message history, project worktrees, and tool outputs from past user sessions. - [COMMAND_EXECUTION]: The bundled script
scripts/query.shcontains a SQL injection vulnerability. User-controlled arguments are directly interpolated into SQL strings (e.g.,WHERE m.session_id = '${ARG}'andLIKE '%${ARG}%') without sanitization or parameterization. An attacker could provide malicious input to manipulate the database queries and extract data outside the intended scope, although the impact is limited to read operations by the-readonlyflag. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: Historical chat messages and tool outputs are retrieved from the
messageandparttables inSKILL.mdandscripts/query.sh. - Boundary markers: No boundary markers or 'ignore' instructions are used to separate historical data from current instructions, potentially leading the agent to follow instructions embedded in old sessions.
- Capability inventory: The skill allows execution of the
sqlite3CLI and access to local file paths. - Sanitization: The skill does not perform any validation or sanitization of the JSON data (text and tool outputs) retrieved from the database before processing it.
Audit Metadata