opencode CLI native untuk Termux/Android tanpa proot — membundel loader musl + binary opencode resmi (upstream opencode-ai)
LPM flags this version as an AI-agent control-surface risk. Installing the package on Android automatically changes the user's global OpenCode agent and command directories. It can overwrite same-named agent profiles with a shell- and write-enabled orchestrator.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
bin/opencode-termux.tsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
bin/opencode-termux.tsView on unpkg · L61Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/opencode-termux.tsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/opencode-termux.tsView on unpkgManifest-reachable source overwrites another installed package with package-defined remote behavior.
bin/opencode-termux.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/opencode-termux.jsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
install.mjsView on unpkg · L26Source file is highly similar to a previously finalized malicious package; route for source-aware review.
install.mjsView on unpkgPackage ships native binary artifacts.
prebuilt/ld-musl-aarch64-termux.soView on unpkgThis report applies to @nemoobc/opencode-termux@1.20.4.
See version security history for other recorded verdicts.
Evidence last updated: .
Source fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/opencode-termux.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L10Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L10Package source references child process execution.
bin/opencode-termux.tsView on unpkg · L1Manifest-reachable source overwrites another installed package with package-defined remote behavior.
bin/opencode-termux.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/opencode-termux.jsView on unpkgPackage ships native binary artifacts.
prebuilt/ld-musl-aarch64-termux.soView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/opencode-termux.tsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
bin/opencode-termux.tsView on unpkg · L61Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/opencode-termux.tsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/opencode-termux.jsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
install.mjsView on unpkg · L26Source file is highly similar to a previously finalized malicious package; route for source-aware review.
install.mjsView on unpkg