Back to skill

Security audit

OpenCode ACP Control v2

Security checks across malware telemetry and agentic risk

Overview

The skill largely matches its OpenCode-control purpose, but it includes broad cleanup and raw execution workflows that could affect other OpenClaw sessions or run outside the intended scope.

Before installing, make sure you trust OpenCode with the selected project directory. Review or disable the wildcard lock-cleanup commands, avoid enabling GitHub/Supabase MCP unless needed, and inspect generated exec/process.write steps before running them.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.