Discord Rich Presence for [OpenCode](https://opencode.ai). works on both opencode 1.x.x and 2.x.x.
LPM flags this version as an AI-agent control-surface risk. An npm postinstall hook modifies OpenCode's plugin control configuration without an explicit user command. It can target the user's home OpenCode configuration.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe manifest automatically runs the configuration script after npm installation.
package.jsonView on unpkg · L53Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.mjsView on unpkg · L1The script locates an OpenCode configuration file in the user's home configuration directory.
scripts/postinstall.mjsView on unpkg · L24The script writes its own plugin entry into the selected OpenCode configuration file.
scripts/postinstall.mjsView on unpkg · L110This report applies to opencode-rpc@2.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L53The manifest automatically runs the configuration script after npm installation.
package.jsonView on unpkg · L53Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L53The script locates an OpenCode configuration file in the user's home configuration directory.
scripts/postinstall.mjsView on unpkg · L24Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.mjsView on unpkg · L1The script writes its own plugin entry into the selected OpenCode configuration file.
scripts/postinstall.mjsView on unpkg · L110