dcp
Warn
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references an external Node.js package for its core context pruning functionality.
- Evidence: The configuration section in
SKILL.mdspecifies the use of"@tarquinen/opencode-dcp@latest". - Concern: The package
@tarquinen/opencode-dcporiginates from an unverified source rather than an established service or vendor associated with this skill. - Concern: The use of the
@latestversion tag is a security risk as it allows the skill to automatically pull the most recent version of the package. This is a common vector for supply chain attacks where a compromised dependency could introduce malicious code without the user's knowledge or consent.
Audit Metadata