opencode-optimization
Warn
Audited by Socket on Jul 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s purpose is mostly consistent with IDE/MCP setup, but it normalizes unpinned `npx -y ...@latest` execution and credential forwarding to npm-fetched MCP server code. Data flows appear aligned with official services and same-brand packages rather than clear exfiltration, so this is not confirmed malware, but the install trust and credential exposure are medium risk.
Confidence: 85%Severity: 57%
Audit Metadata