opencode-acp-control
Warn
Audited by Socket on Sep 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is mostly aligned with its stated purpose of controlling OpenCode, but it grants broad local process control and includes risky update guidance centered on an external auto-updating CLI and a mismatched curl|bash install URL. I do not see confirmed credential theft or overt exfiltration, but the install/update trust model and autonomous process-management scope make it higher risk than a normal documentation-only skill.
Confidence: 84%Severity: 58%
Audit Metadata