Evidence-first engineering runtime with adaptive context, selective routing, weak-model recovery, bounded ACI and benchmark-gated verification for OpenCode
LPM treats this as warn-only first-party agent extension lifecycle risk. A global installation runs a package installer that modifies OpenCode configuration. No confirmed credential theft, network exfiltration, or remote code execution was identified.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
evals/long/graders/long-horizon.mjsView on unpkg · L13Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install.mjsView on unpkg · L39Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
evals/polyglot/fixtures/polyglot-bench/python/tenant_auth.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
evals/polyglot/fixtures/polyglot-bench/python/tenant_auth.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/control-center.mjs#virtual:normalized:round1View on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
global-config/plugins/ues-router/index.jsView on unpkgThis report applies to opencode-agent-skill@10.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L27Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L27Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
evals/polyglot/fixtures/polyglot-bench/python/tenant_auth.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
evals/polyglot/fixtures/polyglot-bench/python/tenant_auth.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/control-center.mjs#virtual:normalized:round1View on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
global-config/plugins/ues-router/index.jsView on unpkgPackage source references dynamic require/import behavior.
evals/long/graders/long-horizon.mjsView on unpkg · L13Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install.mjsView on unpkg · L39