opencode-agents

Warn

Audited by Snyk on Apr 13, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 0.70). Although it doesn’t explicitly instruct creating users, editing systemctl/ssh configs, or requesting sudo, the skill defaults agents to “ALL tools and permissions” and includes examples that grant unrestricted bash/file-edit capabilities (e.g., a “Builder” with no permission block = full access), which encourages agents to execute shell commands and modify files on the host—posing a significant risk of changing machine state.

Issues (1)

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 13, 2026, 11:04 AM
Issues
1
Security Audit — snyk — opencode-agents