Cotal connector for OpenCode: a native in-process plugin that joins a session to the mesh.
No confirmed attack surface was identified. The package is a user-invoked OpenCode connector and local launcher.
The AI recommended clean, but the final policy action is warn. This report does not record a matching static-policy override reason.
Source matches reverse-shell style process and socket wiring.
dist/serve.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/serve.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/serve.jsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/index.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin.bundle.jsView on unpkgThis report applies to @cotal-ai/connector-opencode@0.54.0.
See version security history for other recorded verdicts.
Evidence last updated: .
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/serve.jsView on unpkg · L1Source matches reverse-shell style process and socket wiring.
dist/serve.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/serve.jsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/index.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/plugin.bundle.jsView on unpkg