OpenCode Go subscription usage bars for the opencode v2 TUI - 5h/weekly/monthly windows, /limit popup
LPM treats this as warn-only first-party agent extension lifecycle risk. Install automatically registers this package as an OpenCode TUI plugin by writing the user's OpenCode cli.json plugins list and copying plugin files into the OpenCode config directory. The usage client later reads the local OpenCode Go key and calls the official usage API.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgnpm postinstall unconditionally runs scripts/install.mjs.
package.jsonView on unpkg · L21Package source references dynamic require/import behavior.
dist/usage.tsView on unpkg · L29Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install.mjsView on unpkg · L1This report applies to @leo.gimp/opencode-usage-bar@2.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L21Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L21npm postinstall unconditionally runs scripts/install.mjs.
package.jsonView on unpkg · L21Package source references dynamic require/import behavior.
dist/usage.tsView on unpkg · L29Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install.mjsView on unpkg · L1