Back to skill

Security audit

Aha Opencode Omo

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed orchestration guide for OpenCode with OMO and does not include hidden code, persistence, or data exfiltration behavior.

Install this only if you want an agent-facing workflow that may use OpenCode/OMO subagents and related orchestration features. Review the confirmation and delegation behavior so you understand when work may be split across agents, and keep stricter local project or permission rules in place for sensitive repositories.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The file imposes a blanket `verbosity:low` constraint on all orchestration transparency statements, including risk, confirmation, and validation disclosures, without user opt-in. In a security- or safety-relevant orchestration framework, forced brevity can suppress material caveats, reduce informed consent for higher-risk actions, and make it easier for dangerous capability routing changes to be under-explained.

Static analysis

No suspicious patterns detected.