plugin-installer

Fail

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The plugin reference in references/plugins/llm-api-key-proxy.md instructs the agent to guide the user in downloading and executing pre-compiled binaries (proxy_app.exe or ./proxy_app) from a GitHub Releases page (github.com/Mirrowel/LLM-API-Key-Proxy/releases). Executing unverified binaries from third-party repositories is a critical security risk.
  • [COMMAND_EXECUTION]: The skill instructions in SKILL.md and references/plugins/llm-api-key-proxy.md include shell commands for modifying file permissions (chmod +x) and performing recursive deletions of cache directories (rm -rf ~/.cache/opencode/node_modules), which are high-risk operations if misdirected.
  • [PROMPT_INJECTION]: The references/plugins/pickle-thinker.md documentation describes a plugin that explicitly uses prompt injection techniques by forcing the Ultrathink magic keyword as the first token in messages and synthetic tool outputs to override and manipulate the behavior of specific AI models (GLM-4.6 / Big Pickle).
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of numerous third-party npm packages (e.g., @tarquinen/opencode-dcp, opencode-gemini-auth, @howaboua/pickle-thinker) from various unverified community maintainers, increasing the risk of supply chain attacks.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates an attack surface for indirect prompt injection by instructing the agent to discover and gather information from external, untrusted sources (npm, GitHub, web search) to document new plugins.
    • Ingestion points: Instructions in SKILL.md under Gather Plugin Information to read external READMEs and package files.
    • Boundary markers: None provided to separate untrusted plugin data from agent instructions.
    • Capability inventory: Ability to execute shell scripts (list_plugins.py), write new configuration files, and modify opencode.json which impacts agent behavior.
    • Sanitization: No sanitization or validation steps are described for the data gathered from external sources.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 14, 2026, 05:49 PM