opencode-command-authoring

Warn

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes vendor-specific executables (bin/create-command and bin/opencode-command) to manage and execute workspace commands stored in .opencode/command/. \n- [COMMAND_EXECUTION]: The instruction opencode-command --run enables dynamic execution of scripts, allowing the agent to run code it has authored within the environment. \n- [PROMPT_INJECTION]: The governance configuration in CONTRACT.edn sets requires-user-approval to false, allowing the agent to perform command execution actions without human intervention or review, which bypasses the typical security constraint of user confirmation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 22, 2026, 09:59 PM
Security Audit — agent-trust-hub — opencode-command-authoring