opencode-ts

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
references/server-and-routes.md

No direct malicious payload is evident in the provided fragment. The code implements a legitimate extensible plugin and configuration system, but it creates a substantial supply-chain and code-execution risk: configuration-controlled npm or file plugins are installed and executed with broad application and shell access, and unpinned plugins may use latest versions. Review plugin sources, lockfiles, package-manager lifecycle behavior, configuration ownership, and whether untrusted users can modify configuration. Unknown-error responses may also disclose stack traces. Findings are limited to the shown fragment and do not establish malicious intent in the larger file.

Confidence: 94%Severity: 70%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:50 AM
Package URL
pkg:socket/skills-sh/pproenca%2Fdot-skills%2Fopencode-ts%2F@3aafe2e7c5972613e33b4d5cfb763a528372d72360226a31cb7fa40b2a713e32
Security Audit — socket — opencode-ts