opencode-model-variant-management

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's instructions and contract are consistent with its stated purpose of managing configuration and authentication settings for AI model providers.
  • [DATA_EXPOSURE]: The skill mentions handling environment variables and authentication configurations as inputs. This is required for the intended purpose of configuring model providers. There are no hardcoded credentials or evidence of data exfiltration to unauthorized domains.
  • [PROMPT_INJECTION]: The skill does not contain instructions attempting to bypass safety filters, override system prompts, or exfiltrate its own instructions.
  • [COMMAND_EXECUTION]: The skill does not execute arbitrary shell commands or subprocesses. Its operations are limited to reviewing and updating configuration files within the repository context.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external provider documentation to update internal configurations. While it has the permission to modify files without explicit user approval (requires-user-approval false), no malicious injection triggers were identified. This ingestion surface is a standard part of the skill's development workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 07:07 AM
Security Audit — agent-trust-hub — opencode-model-variant-management