Pi-native UES coding-agent runtime with adaptive stability, Turbo Fast Path, durable verification, managed services, and weak-model orchestration
LPM treats this as warn-only first-party agent extension lifecycle risk. The package has an installer that sets up its own OpenCode skills, agents, and plugin in the user configuration. No confirmed attack was identified.
Package source references dynamic require/import behavior.
evals/long/graders/long-horizon.mjsView on unpkg · L13Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
evals/polyglot/fixtures/polyglot-bench/python/tenant_auth.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
evals/polyglot/fixtures/polyglot-bench/python/tenant_auth.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/content-artifacts.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/process-runner.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/browser-runtime.mjsView on unpkgThis report applies to opencode-agent-skill@15.5.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
evals/long/graders/long-horizon.mjsView on unpkg · L13Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
evals/polyglot/fixtures/polyglot-bench/python/tenant_auth.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
evals/polyglot/fixtures/polyglot-bench/python/tenant_auth.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/content-artifacts.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/process-runner.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/browser-runtime.mjsView on unpkg