Opencode Cli

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill is an instruction-only integration for the OpenCode CLI and its requirements and instructions are coherent with its stated purpose; no unexplained credential or install demands were found.

This is an instruction-only OpenCode CLI integration and appears coherent, but take these precautions before using it: (1) Only run in repositories/environments you trust — the skill may trigger MCP servers that have access to project files and databases. (2) If you follow the MCP guidance, verify any npm packages before installing globally (npm install -g) or prefer vetted/global installs over npx to reduce remote-code risk. (3) Provide SUPABASE/CONTEXT7 credentials only when needed and avoid committing them to version control; the skill marks them optional. (4) Background tasks require active polling/monitoring via the agent’s process tool — expect ongoing process activity and logs. (5) One minor inconsistency to double-check: the Context7 guide points to an Upstash link for obtaining an API key — confirm the correct credential provider for your Context7 setup. If you want extra assurance, ask the author for the canonical MCP package names and their official upstream URLs before installing any MCP servers.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

No visible risk-analysis findings were reported for this release.