Cotal connector for OpenCode: a native in-process plugin that joins a session to the mesh.
LPM treats this as warn-only first-party agent extension lifecycle risk. At runtime, the connector launches a local OpenCode service with a bundled plugin and an allow-permission configuration. No install-time attack or external endpoint was confirmed.
Source matches reverse-shell style process and socket wiring.
dist/serve.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/serve.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/serve.jsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/index.jsView on unpkg · L7This report applies to @cotal-ai/connector-opencode@0.42.0.
See version security history for other recorded verdicts.
Evidence last updated: .
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/serve.jsView on unpkg · L1Source matches reverse-shell style process and socket wiring.
dist/serve.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/serve.jsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/index.jsView on unpkg · L7