opencode-command-authoring

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is modest, but the skill depends on undocumented, unverifiable local wrapper CLIs and mismatches official OpenCode command locations and invocation patterns. There is no evidence of explicit credential theft or exfiltration, but the execution trust and provenance gaps are disproportionate to a simple command-authoring skill.

Confidence: 91%Severity: 82%
Audit Metadata
Analyzed At
Sep 18, 2026, 10:49 AM
Package URL
pkg:socket/skills-sh/open-hax%2Fopencode-skills%2Fopencode-command-authoring%2F@042becc984bd80c5d31ff161d23f2012e7fa26ee53613b32003b582da837eb5c
Security Audit — socket — opencode-command-authoring