Roleflow: sistema OpenCode portable con roles por responsabilidad + routing barato + ahorro de tokens. Público, instalable desde cualquier PC o server con una línea en opencode.json.
LPM flags this version as an AI-agent control-surface risk. Installation automatically writes agent instructions and skills into a foreign, global OpenCode control surface. Existing definitions can be overwritten.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpackage.json automatically runs postinstall.mjs during installation.
package.jsonView on unpkg · L21Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgpostinstall.mjs targets the user's global .config/opencode agents and skills directories without a consent gate.
postinstall.mjsView on unpkg · L9Recursive copying permits overwriting existing generic agent and skill definitions.
postinstall.mjsView on unpkg · L14This report applies to roleflow@1.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L21Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L21package.json automatically runs postinstall.mjs during installation.
package.jsonView on unpkg · L21postinstall.mjs targets the user's global .config/opencode agents and skills directories without a consent gate.
postinstall.mjsView on unpkg · L9Recursive copying permits overwriting existing generic agent and skill definitions.
postinstall.mjsView on unpkg · L14