opencode-acp-control

Warn

Audited by Socket on Sep 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly aligned with its stated purpose of controlling OpenCode, but it grants broad local process control and includes risky update guidance centered on an external auto-updating CLI and a mismatched curl|bash install URL. I do not see confirmed credential theft or overt exfiltration, but the install/update trust model and autonomous process-management scope make it higher risk than a normal documentation-only skill.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Sep 2, 2026, 04:36 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fopencode-acp-control%2F@67c739bed3e42da4ef886ba53e920f31db810d090e2933fdf3134138f4f82132
Security Audit — socket — opencode-acp-control