opencode-ts
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
SecuritySecurityreferences/server-and-routes.md
MEDIUMSecurityMEDIUM
references/server-and-routes.md
No direct malicious payload is evident in the provided fragment. The code implements a legitimate extensible plugin and configuration system, but it creates a substantial supply-chain and code-execution risk: configuration-controlled npm or file plugins are installed and executed with broad application and shell access, and unpinned plugins may use latest versions. Review plugin sources, lockfiles, package-manager lifecycle behavior, configuration ownership, and whether untrusted users can modify configuration. Unknown-error responses may also disclose stack traces. Findings are limited to the shown fragment and do not establish malicious intent in the larger file.
Confidence: 94%Severity: 70%
Audit Metadata