skills/gain-tech/opencode-setup/dcp/Gen Agent Trust Hub

dcp

Warn

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references an external Node.js package for its core context pruning functionality.
  • Evidence: The configuration section in SKILL.md specifies the use of "@tarquinen/opencode-dcp@latest".
  • Concern: The package @tarquinen/opencode-dcp originates from an unverified source rather than an established service or vendor associated with this skill.
  • Concern: The use of the @latest version tag is a security risk as it allows the skill to automatically pull the most recent version of the package. This is a common vector for supply chain attacks where a compromised dependency could introduce malicious code without the user's knowledge or consent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 7, 2026, 03:46 PM
Security Audit — agent-trust-hub — dcp