opencode
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external and untrusted data, specifically during the PR review workflow where it attaches git diffs or clones remote repositories for analysis. Because the tool being orchestrated (OpenCode) is an autonomous coding agent with capabilities to modify files and execute commands, instructions embedded within the code being reviewed could potentially influence the agent's behavior.
- Ingestion points: Untrusted data enters the context through file attachments (
-f) in theopencode runcommand and through cloning external repositories viagit clonefor isolated reviews. - Boundary markers: The provided prompt templates do not include explicit delimiters or instructions to ignore embedded commands within the code being reviewed.
- Capability inventory: The skill utilizes
terminal(command=...)for shell execution andprocess(action=...)for managing interactive TUI sessions, providing a wide range of system interaction capabilities. - Sanitization: There is no evidence of sanitization or filtering of the code content before it is processed by the AI coding agent.
- [EXTERNAL_DOWNLOADS]: The skill recommends the installation of the
opencode-aipackage using standard package managers like NPM and Homebrew. These are documented as prerequisites for the tool's functionality. - [COMMAND_EXECUTION]: The skill extensively uses the
terminalandprocesstools to run the OpenCode CLI, manage background TUI sessions, and handle git operations. This level of access is necessary for the skill's primary purpose of providing an autonomous coding worker environment.
Audit Metadata