oh-my-opencode-usage

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a comprehensive user guide for the oh-my-opencode tool, including instructions for various agents (Sisyphus, Hephaestus, etc.) and workflow management patterns.
  • [EXTERNAL_DOWNLOADS]: The skill contains references to documentation and source code at 'opencode.ai' and the 'github.com/code-yeongyu/oh-my-opencode' repository, which are the official sites for the tool described. These references are documented neutrally as they are relevant to the skill's primary purpose.
  • [COMMAND_EXECUTION]: While the skill documents commands for file modification (/write, /edit) and project analysis (/init), these are presented as standard tool functionalities for user-guided development and do not execute automatically or maliciously.
  • [DATA_EXFILTRATION]: The skill mentions session data storage in local and project-specific directories (~/.config/opencode/sessions/ and .opencode/sessions/) and features like /share for conversation sharing, which are standard session management capabilities of the documented tool.
  • [PROMPT_INJECTION]: The skill operates as a documentation layer; while it describes a tool that processes project code (Category 8 surface), it does not include any instructions designed to bypass agent safety filters or override system constraints.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 11:45 AM
Security Audit — agent-trust-hub — oh-my-opencode-usage