Pi-native UES coding-agent runtime with V16 deterministic correctness gates, durable evidence integrity, external-data provenance, Windows-safe cleanup, and measured cost-aware routing
LPM treats this as warn-only first-party agent extension lifecycle risk. The package provides a CLI setup command that installs its OpenCode router plugin and adds package workflow instructions to the configured global agent file. This is a first-party agent extension setup capability; no active attack was identified.
Package source references dynamic require/import behavior.
evals/long/graders/long-horizon.mjsView on unpkg · L13Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
evals/polyglot/fixtures/polyglot-bench/python/tenant_auth.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
evals/polyglot/fixtures/polyglot-bench/python/tenant_auth.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/content-artifacts.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/process-runner.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/browser-runtime.mjsView on unpkgThis report applies to opencode-agent-skill@16.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
evals/long/graders/long-horizon.mjsView on unpkg · L13Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
evals/polyglot/fixtures/polyglot-bench/python/tenant_auth.pyView on unpkgPackage ships non-JavaScript build or shell helper files.
evals/polyglot/fixtures/polyglot-bench/python/tenant_auth.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/content-artifacts.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/process-runner.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/browser-runtime.mjsView on unpkg