opencode-command-authoring
Warn
Audited by Socket on Jun 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The stated purpose is coherent, but the skill relies on undocumented repo-local executables (`bin/create-command`, `bin/opencode-command`) rather than the official OpenCode workflow documented upstream. No clear credential theft or malicious exfiltration is shown, but install/execution trust is weak because the agent is asked to execute opaque local tooling whose provenance cannot be verified from the skill.
Confidence: 83%Severity: 58%
Audit Metadata