Back to skill

Security audit

Oh-my-openagent

Security checks for vulnerabilities and agentic risk

Overview

This skill appears purpose-aligned, but it asks users to install and run a mutable third-party plugin while documenting broad background automation and credential-file handling without enough safety scoping.

Install only if you trust the `oh-my-opencode` package source and are comfortable giving it broad local agent authority. Pin a reviewed version instead of using `latest`, avoid opening or pasting `auth.json`, disable unnecessary background agents/hooks, and use a sandbox or least-privilege environment for autonomous loops and MCPs.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:33
Finding

Unpinned Third-Party Package Download and Execution

Content
View full analysis
Remediation
View remediation
install ``` 2. Replace the mutable plugin declaration with the same exact version: ```json { "plugin": ["oh-my-opencode@"] } ``` 3. Publish the expected package digest, lockfile entry, or registry integrity value and require verification before execution. 4. Review release provenance and use signed releases or trusted publishing attestations where available. 5. Avoid automatic updates to `latest`; require an explicit review and approval process for each upgrade. 6. Run installation and plugin execution with least privilege, without administrative permissions, and within an appropriate sandbox where feasible. 7. Document how users can inspect the resolved package version and source before allowing it to execute. ]]>

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/providers.md:69
Finding

Credential Store Inspection May Expose Provider Authentication Tokens

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
- User wants to add, disable, or configure hooks
- User asks about task delegation, categories, or background tasks
- User needs help with provider authentication or model routing
- User wants to create or manage custom skills
- User asks about slash commands like /ralph-loop, /start-work, /refactor

## Installation

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documents an external reference-search agent that always runs in the background, but it does not warn that prompts, code snippets, dependency names, or other project context may be transmitted to third-party services. In a multi-agent orchestration skill, this omission is risky because users may trigger the feature implicitly and unknowingly disclose sensitive repository or business information to external providers.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation advertises autonomous looping commands that can continue operating until a task is complete, but it provides no warning about unattended execution, repeated tool actions, cost growth, or unintended code and environment changes. In an agent-orchestration skill, that omission materially increases the chance that users trigger long-running autonomous behavior without understanding the operational and safety implications.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation says keyword detector hooks fire when specific keywords appear in conversation, with examples like detecting coding tasks or deployment requests. This is ambiguous because it does not define the exact keywords, scope, or exclusion conditions, which could cause unintended activations from ordinary discussion.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The custom hook example uses a very broad keyword pattern ("deploy") that can match ordinary conversation and automatically trigger behavior. In an agent orchestration system with hooks that inject context or modify behavior, this encourages unsafe configurations where normal chat text can activate operational workflows without sufficient contextual validation or user confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instructions tell users to place API keys directly into ~/.local/share/opencode/auth.json without any secret-handling guidance. That normalizes editing a credential file by hand and may lead users to expose keys in editors, backups, screenshots, version control, or to set unsafe file permissions, making credential theft more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explicitly tells users to inspect ~/.local/share/opencode/auth.json to check auth status, but it does not warn that this file contains live authentication tokens and API credentials. In a tool/setup guide, encouraging casual inspection of a secret store increases the chance of credential exposure through screen sharing, shell history, logs, copied snippets, or accidental disclosure to other agents/tools.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The dev-browser trigger phrases are broad natural-language patterns like 'go to [url]', 'click on', 'fill out the form', and 'scrape', which can match many ordinary user requests. In an orchestration system that auto-loads skills based on such phrases, this can cause unintended browser-capable tooling to activate, increasing the chance of over-privileged actions, untrusted navigation, or prompt/command injection through web content.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The git-master trigger phrases include generic terms such as 'commit', 'rebase', 'squash', and history questions, which are ambiguous in normal conversation and may auto-load a powerful git skill without clear intent. In an agent context this can expand capabilities unexpectedly and lead to unintended repository mutation, history rewriting, or exposure of sensitive code history when a safer non-tool response would have sufficed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The example skill frontmatter starts an MCP server via npx without pinning an exact package version, which allows whatever version resolves at load time to be fetched and executed. In a skill system where MCPs start automatically when the skill is loaded, this creates a supply-chain and remote code execution risk if a package is updated maliciously, hijacked, or unexpectedly changed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This example again shows an embedded MCP launched with npx and no pinned version while also injecting environment variables into the spawned process. Because the MCP is started automatically on skill load, an attacker controlling the published package or a compromised dependency path could obtain code execution and potentially exfiltrate secrets such as API_KEY from the MCP environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill states that the Explore agent always runs in the background for internal codebase search, but it does not warn users that their files and project contents may be automatically inspected. While this is primarily local exposure rather than third-party exfiltration, silent background inspection can still violate user expectations and increase the chance that sensitive content is surfaced to other agents or logs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The commands that initialize documentation and create handoff summaries describe generating structured knowledge and capturing modified files, decisions, and remaining tasks, but they do not warn that project data may be written, summarized, or persisted. In a multi-agent context, that can expose sensitive codebase details, secrets present in files, or internal decision context to places users may not expect.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.