opencode-command-authoring

Warn

Audited by Socket on Jun 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The stated purpose is coherent, but the skill relies on undocumented repo-local executables (`bin/create-command`, `bin/opencode-command`) rather than the official OpenCode workflow documented upstream. No clear credential theft or malicious exfiltration is shown, but install/execution trust is weak because the agent is asked to execute opaque local tooling whose provenance cannot be verified from the skill.

Confidence: 83%Severity: 58%
Audit Metadata
Analyzed At
Jun 22, 2026, 10:00 PM
Package URL
pkg:socket/skills-sh/open-hax%2Feta-mu-pi%2Fopencode-command-authoring%2F@c917df660f5877ab673a380d2378f8ea37d0514b4d423efa2bed9d9b3c1035fc
Security Audit — socket — opencode-command-authoring