Review recommended
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
warnThis skill provides a bridge to the OpenCode CLI for delegating coding tasks. A security analysis identified a potential command injection vulnerability in the relay script when executed on Windows systems. The skill also facilitates remote code implementation through the OpenCode tool and presents an indirect prompt injection surface.
Socket
passNo alerts
Snyk
passRisk: LOW · No issues