opencode-session-db
Warn
Audited by Socket on Sep 28, 2026
1 alert found:
AnomalyAnomalyscripts/query.sh
LOWAnomalyLOW
scripts/query.sh
The code appears to be a legitimate read-only SQLite inspection and export script, with no evident malware or supply-chain backdoor behavior. Its primary security weakness is SQL injection caused by direct interpolation of command-line arguments into SQL. Parameterized queries or strict validation of session IDs, search terms, and numeric limits should be used. The script also intentionally exposes sensitive local conversation and tool data to its caller.
Confidence: 98%Severity: 58%
Audit Metadata