opencode-plugins
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a legitimate development tool for building OpenCode plugins and follows standard project structures.
- [PROMPT_INJECTION]: The skill ingests external source code and documentation, which constitutes an indirect prompt injection surface. This is a low-risk concern inherent to skills that process user-provided or external code.
- Ingestion points: SKILL.md (Input includes 'Plugin source' and 'OpenCode plugin documentation').
- Boundary markers: None identified in the skill instructions.
- Capability inventory: SKILL.md (Modifies implementation and tests under 'packages/plugin').
- Sanitization: The skill does not describe specific sanitization or validation steps for the input data.
Audit Metadata