Pi-native UES coding-agent runtime with adaptive efficiency intelligence, durable verification, cache-stable context, managed services, and weak-model orchestration
LPM treats this as warn-only first-party agent extension lifecycle risk. No confirmed attack surface was established. The package does install its own OpenCode router plugin and related resources into the user configuration when its install command is invoked.
Package source references dynamic require/import behavior.
evals/long/graders/long-horizon.mjsView on unpkg · L13Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
evals/polyglot/fixtures/polyglot-bench/python/tenant_auth.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
evals/polyglot/fixtures/polyglot-bench/python/tenant_auth.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/content-artifacts.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/process-runner.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/browser-runtime.mjsView on unpkgThis report applies to opencode-agent-skill@15.7.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
evals/long/graders/long-horizon.mjsView on unpkg · L13Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
evals/polyglot/fixtures/polyglot-bench/python/tenant_auth.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
evals/polyglot/fixtures/polyglot-bench/python/tenant_auth.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/content-artifacts.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/process-runner.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/browser-runtime.mjsView on unpkg