Cotal connector for OpenCode: a native in-process plugin that joins a session to the mesh.
No attack was identified in the inspected package sources. The flagged process and network behavior runs a local OpenCode server and checks its readiness over loopback.
The AI recommended clean. Static policy retained a warning. The static scanner classified the package as malicious with confidence of at least 85%. A critical static finding has confidence of at least 90%. These conditions do not mean that the AI confirmed malicious behavior.
Source matches reverse-shell style process and socket wiring.
dist/serve.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/serve.jsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.jsView on unpkgThis report applies to @cotal-ai/connector-opencode@0.73.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source matches reverse-shell style process and socket wiring.
dist/serve.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/serve.jsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.jsView on unpkg