configuring-opencode

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill acts as a documentation assistant for the OpenCode platform, providing users with templates and guidance for configuration files like opencode.json and tui.json.- [DATA_EXFILTRATION]: The skill documents the platform's support for secure secret management via environment variables ({env:VAR}) and file substitution ({file:PATH}). These features are presented as standard configuration mechanisms for handling API keys and sensitive tokens rather than unauthorized exfiltration.- [EXTERNAL_DOWNLOADS]: The skill references several external resources, including NPM packages for providers and MCP servers (e.g., @brave/brave-search-mcp-server), and provides examples for remote skill and instruction loading via URLs. These are documented features of the platform and are described neutrally.- [PROMPT_INJECTION]: The skill describes an interface that ingests user requirements to generate configurations for a powerful tool (capable of shell execution and network operations). It details a comprehensive permission system (allow/ask/deny) to control agent autonomy, which serves as a primary defense against indirect injection attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 11:03 AM
Security Audit — agent-trust-hub — configuring-opencode