opencode-cli

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Anomaly
AnomalyLOW
references/mcp-config-guide.md

This is non-executable configuration documentation with no direct evidence of malware or intentional sabotage. It does recommend installing and automatically running unpinned third-party npm MCP servers and placing credentials in configuration files, creating meaningful supply-chain, credential-exposure, and database-impact risks. Package identity, publisher provenance, versions, integrity hashes, and MCP permissions should be verified before use.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 19, 2026, 11:32 PM
Package URL
pkg:socket/skills-sh/xianmingyao%2Fopenclaw-cayson%2Fopencode-cli%2F@ebd23a06ef9edaf87d67f2b07e701b28a03cea27f575efc34da78a5095eb7011
Security Audit — socket — opencode-cli