opencode-sdk

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to ingest and act upon 'server changes' to regenerate SDK artifacts. This creates an attack surface where malicious instructions embedded in the server code or API definitions could influence the agent's behavior during the SDK update process.
  • Ingestion points: The agent reads server contract changes, specifically monitoring packages/opencode/src/server/server.ts.
  • Boundary markers: There are no instructions providing delimiters or warnings to the agent to disregard natural language instructions that might be found within the server code changes.
  • Capability inventory: The skill provides the agent with the authority to modify and update files under the packages/sdk/* directories and generate documentation.
  • Sanitization: The skill lacks any steps for validating or sanitizing the input code changes before they are used to generate new SDK components.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 10:49 AM
Security Audit — agent-trust-hub — opencode-sdk