opencode-handoff

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is coherent and the OpenCode credential exclusion is explicit, but the skill still forwards other host credentials into a container started from a mutable personal GHCR image and a transitive local script. The main risk is supply-chain plus credential forwarding, not confirmed malware.

Confidence: 89%Severity: 80%
Audit Metadata
Analyzed At
Sep 20, 2026, 05:26 PM
Package URL
pkg:socket/skills-sh/luongnv89%2Fskills%2Fopencode-handoff%2F@0d4f26b236d3e5250861d34d92a4f8ae83e2bd24776453630b2eba95193abb01
Security Audit — socket — opencode-handoff