opencode-command-authoring
Warn
Audited by Socket on Sep 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is modest, but the skill depends on undocumented, unverifiable local wrapper CLIs and mismatches official OpenCode command locations and invocation patterns. There is no evidence of explicit credential theft or exfiltration, but the execution trust and provenance gaps are disproportionate to a simple command-authoring skill.
Confidence: 91%Severity: 82%
Audit Metadata