plugin-installer
Fail
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The plugin reference in
references/plugins/llm-api-key-proxy.mdinstructs the agent to guide the user in downloading and executing pre-compiled binaries (proxy_app.exeor./proxy_app) from a GitHub Releases page (github.com/Mirrowel/LLM-API-Key-Proxy/releases). Executing unverified binaries from third-party repositories is a critical security risk. - [COMMAND_EXECUTION]: The skill instructions in
SKILL.mdandreferences/plugins/llm-api-key-proxy.mdinclude shell commands for modifying file permissions (chmod +x) and performing recursive deletions of cache directories (rm -rf ~/.cache/opencode/node_modules), which are high-risk operations if misdirected. - [PROMPT_INJECTION]: The
references/plugins/pickle-thinker.mddocumentation describes a plugin that explicitly uses prompt injection techniques by forcing theUltrathinkmagic keyword as the first token in messages and synthetic tool outputs to override and manipulate the behavior of specific AI models (GLM-4.6 / Big Pickle). - [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of numerous third-party npm packages (e.g.,
@tarquinen/opencode-dcp,opencode-gemini-auth,@howaboua/pickle-thinker) from various unverified community maintainers, increasing the risk of supply chain attacks. - [INDIRECT_PROMPT_INJECTION]: The skill creates an attack surface for indirect prompt injection by instructing the agent to discover and gather information from external, untrusted sources (npm, GitHub, web search) to document new plugins.
- Ingestion points: Instructions in
SKILL.mdunderGather Plugin Informationto read external READMEs and package files. - Boundary markers: None provided to separate untrusted plugin data from agent instructions.
- Capability inventory: Ability to execute shell scripts (
list_plugins.py), write new configuration files, and modifyopencode.jsonwhich impacts agent behavior. - Sanitization: No sanitization or validation steps are described for the data gathered from external sources.
- Ingestion points: Instructions in
Recommendations
- AI detected serious security threats
Audit Metadata