opencode

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external and untrusted data, specifically during the PR review workflow where it attaches git diffs or clones remote repositories for analysis. Because the tool being orchestrated (OpenCode) is an autonomous coding agent with capabilities to modify files and execute commands, instructions embedded within the code being reviewed could potentially influence the agent's behavior.
  • Ingestion points: Untrusted data enters the context through file attachments (-f) in the opencode run command and through cloning external repositories via git clone for isolated reviews.
  • Boundary markers: The provided prompt templates do not include explicit delimiters or instructions to ignore embedded commands within the code being reviewed.
  • Capability inventory: The skill utilizes terminal(command=...) for shell execution and process(action=...) for managing interactive TUI sessions, providing a wide range of system interaction capabilities.
  • Sanitization: There is no evidence of sanitization or filtering of the code content before it is processed by the AI coding agent.
  • [EXTERNAL_DOWNLOADS]: The skill recommends the installation of the opencode-ai package using standard package managers like NPM and Homebrew. These are documented as prerequisites for the tool's functionality.
  • [COMMAND_EXECUTION]: The skill extensively uses the terminal and process tools to run the OpenCode CLI, manage background TUI sessions, and handle git operations. This level of access is necessary for the skill's primary purpose of providing an autonomous coding worker environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 06:35 PM