Cotal connector for OpenCode: a native in-process plugin that joins a session to the mesh.
No attack was identified. The launcher starts an OpenCode service for the connector on loopback and authenticates its local readiness request.
The AI recommended clean. Static policy retained a warning. The static scanner classified the package as malicious with confidence of at least 85%. A critical static finding has confidence of at least 90%. These conditions do not mean that the AI confirmed malicious behavior.
Source matches reverse-shell style process and socket wiring.
dist/serve.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/serve.jsView on unpkg · L1package.json defines test, typecheck, build, and bundle scripts but no preinstall, install, or postinstall hook.
package.jsonView on unpkg · L38This report applies to @cotal-ai/connector-opencode@0.72.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source matches reverse-shell style process and socket wiring.
dist/serve.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/serve.jsView on unpkg · L1package.json defines test, typecheck, build, and bundle scripts but no preinstall, install, or postinstall hook.
package.jsonView on unpkg · L38