oh-my-opencode

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its stated purpose as a multi-agent OpenCode orchestrator, but its footprint is high-risk: unpinned package execution, autonomous continuation loops, and external-content research combined with agent action capabilities. There is no clear evidence of credential harvesting or malicious exfiltration, so this is not confirmed malware, but it is a medium/high-risk orchestration skill that should be used only with strong user oversight.

Confidence: 80%Severity: 69%
Audit Metadata
Analyzed At
May 4, 2026, 01:51 PM
Package URL
pkg:socket/skills-sh/MetaMask%2Fskills%2Foh-my-opencode%2F@753c6b3b9db2407442cb31e2094cd77bc2fb2291
Security Audit — socket — oh-my-opencode