opencode CLI native untuk Termux/Android tanpa proot — membundel loader musl + binary opencode resmi (upstream opencode-ai)
LPM treats this as warn-only first-party agent extension lifecycle risk. Npm postinstall modifies the user's OpenCode agent and command control surface, then adds a default configuration if absent. The installed agent profiles can write files, run shell commands, and launch subagents.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
bin/opencode-termux.tsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
bin/opencode-termux.tsView on unpkg · L61Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/opencode-termux.tsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/opencode-termux.tsView on unpkgManifest-reachable source overwrites another installed package with package-defined remote behavior.
bin/opencode-termux.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/opencode-termux.jsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
install.mjsView on unpkg · L26Source file is highly similar to a previously finalized malicious package; route for source-aware review.
install.mjsView on unpkgPackage ships native binary artifacts.
prebuilt/ld-musl-aarch64-termux.soView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/opencode-termux.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L10Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L10Package source references child process execution.
bin/opencode-termux.tsView on unpkg · L1Manifest-reachable source overwrites another installed package with package-defined remote behavior.
bin/opencode-termux.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/opencode-termux.jsView on unpkgPackage ships native binary artifacts.
prebuilt/ld-musl-aarch64-termux.soView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/opencode-termux.tsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
bin/opencode-termux.tsView on unpkg · L61Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/opencode-termux.tsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/opencode-termux.jsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
install.mjsView on unpkg · L26Source file is highly similar to a previously finalized malicious package; route for source-aware review.
install.mjsView on unpkg