opencode-runner
Warn
Audited by Socket on May 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core purpose is coherent for an OpenCode runner, but the footprint is materially risky because it forwards workspace content and provider credentials through an external CLI, and headless mode auto-approves permissions. The install paths are partly legitimate, yet the documented tap drift weakens trust. High security risk, but not confirmed malware.
Confidence: 89%Severity: 76%
Audit Metadata