opencode-connect-model

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a user manual and setup guide for the OpenCode platform. It does not contain malicious code, hidden instructions, or obfuscated content.
  • [CREDENTIALS_UNSAFE]: The instructions specifically address API key management but do so by providing security best practices. It explicitly warns users to keep keys private, avoid committing credentials to Git, and identifies the local storage path (auth.json) to prevent accidental exposure. No hardcoded credentials were found.
  • [EXTERNAL_DOWNLOADS]: The skill directs users to official resources on the opencode.ai domain and well-known services like Homebrew for installation. These references are appropriate for the skill's stated purpose of environment configuration.
  • [COMMAND_EXECUTION]: The manual includes standard CLI commands for the opencode tool (e.g., opencode auth login, opencode run). These commands are used for legitimate configuration and testing purposes as part of the setup tutorial.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 02:34 AM
Security Audit — agent-trust-hub — opencode-connect-model