opencode-github

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill facilitates the learning of standard development tools (git, gh) without introducing malicious code or patterns.- [CREDENTIALS_UNSAFE]: The skill identifies the risks of manual token handling and recommends using 'gh auth setup-git'. This ensures tokens are stored in the system keyring and are not accessible to the AI agent, following security best practices.- [EXTERNAL_DOWNLOADS]: Downloads training materials from the author's public GitHub repository (github.com/mathruffian-dot/opencode-lazy-packs.git). This is expected behavior for a tutorial and targets the vendor's own infrastructure.- [SAFE]: The skill includes instructions for protecting user privacy by using GitHub's no-reply email addresses for Git identity configuration.- [SAFE]: Regarding potential indirect prompt injection:
  • Ingestion points: 'git clone' command in SKILL.md.
  • Boundary markers: None.
  • Capability inventory: Shell access to Git and GitHub CLI.
  • Sanitization: None.
  • Assessment: The activity is the primary purpose of the skill and targets vendor-owned resources.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 02:22 AM
Security Audit — agent-trust-hub — opencode-github