Security audit
OpenCode ACP Control v2
Security checks across malware telemetry and agentic risk
Overview
The skill largely matches its OpenCode-control purpose, but it includes broad cleanup and raw execution workflows that could affect other OpenClaw sessions or run outside the intended scope.
Before installing, make sure you trust OpenCode with the selected project directory. Review or disable the wildcard lock-cleanup commands, avoid enabling GitHub/Supabase MCP unless needed, and inspect generated exec/process.write steps before running them.
VirusTotal
66/66 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
