Back to skill

Security audit

Development Coding Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward OpenCode workflow guide for development tasks, with normal code-change risks but no hidden or unrelated behavior in the artifact.

Install only if you trust the OpenCode CLI source and are comfortable letting it modify the selected Git repository. Prefer a pinned or locally managed OpenCode version, run it in a development checkout, monitor background tasks, and review diffs before committing or applying database migrations.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:73
Finding

Unpinned Global Installation of a Third-Party CLI Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 73-77
Vulnerability Type: Unpinned and globally installed third-party dependency
Risk Level: Medium

markdown
## Requirements

- OpenCode CLI installed (`npm install -g opencode`)
- Git repository for target project
- PTY support enabled (automatic with `pty:true`)

Technical Analysis

The documented installation command uses npm install -g opencode without specifying an exact package version or integrity constraint. Consequently, users following these instructions receive whichever release the package registry currently resolves as the latest version rather than a previously reviewed and reproducible version.

npm packages may execute lifecycle scripts during installation. Because the dependency is installed globally, those scripts execute with the privileges of the user running npm and the installed executable becomes available system-wide for that user. If the package, publisher account, or distribution channel is compromised, a malicious release could execute code during installation or when the CLI is later invoked against a project.

The audit found no evidence that the currently referenced package is malicious. The vulnerability is the unsafe, mutable dependency-installation practice and its associated supply-chain exposure.

Attack Path

  1. An attacker compromises the package publisher, npm account, package distribution channel, or a future package release.
  2. The attacker publishes a malicious version under the referenced opencode package name.
  3. A user follows the Skill documentation and executes npm install -g opencode.
  4. npm resolves and downloads the attacker-controlled latest release because no exact version or integrity value is specified.
  5. Malicious package lifecycle scripts can execute during installation, or malicious behavior can execute when opencode run is invoked.
  6. The malicious process can access resour ...[truncated 812 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin OpenCode to an exact, reviewed version rather than resolving the mutable latest release.
  2. Verify and document the package's official name, publisher identity, registry, and release provenance.
  3. Prefer a project-local development dependency governed by a committed lockfile instead of a global installation.
  4. Enforce package integrity verification and use trusted registry configuration.
  5. Review package contents and lifecycle scripts before approving version upgrades.
  6. Run the CLI with least privilege and restrict its access to credentials, sensitive environment variables, unrelated directories, and unnecessary network resources.
  7. Execute it in an isolated development environment or sandbox where feasible.
  8. Require users to inspect generated changes and repository diffs before committing or deploying them.
Vulnerability Patterns
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.


name: dev-coding-agent description: 'Enhanced coding agent for development workflows. Optimized for building features, fixing bugs, and code refactoring with OpenCode integration.' metadata: { "openclaw": { "emoji": "👨‍💻", "requires": { "anyBins": ["opencode"] } }, "author": "Roger", "version": "1.0.0" }

Development Coding Agent

Specialized coding agent skill optimized for software development tasks using OpenCode.

Quick Start

Basic Usage

bash
# Simple task in your project
bash pty:true workdir:~/your-project command:"opencode run 'Add feature or fix bug'"

# Background ta

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The database migration example encourages running a code-modifying, potentially schema-altering action without any warning to review the generated changes, back up data, or test in a safe environment first. In an agent skill intended to drive automated development workflows, this omission increases the chance of unintended destructive changes to project state or user data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.