ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      bjesuiter

      Safety Report

      Opencode Acp Control

      @bjesuiter

      Control OpenCode directly via the Agent Client Protocol (ACP). Start sessions, send prompts, resume conversations, and manage OpenCode updates.

      3,597Downloads
      17Installs
      8Stars
      3Versions
      CLI & Shell Tools1,805

      Security Analysis

      medium confidence
      Suspicious0.04 risk

      The skill's instructions match its stated purpose (controlling OpenCode via ACP) but the manifest omits that it requires the 'opencode' CLI and runtime process/bash capabilities — an incoherence worth flagging before install.

      Feb 11, 20261 files2 concerns
      Purpose & Capabilityconcern

      The SKILL.md expects the agent to run the 'opencode' CLI (e.g., `opencode acp`, `opencode session list`) and to use process/bash helpers (process.write, process.poll, process.kill). However the skill metadata declares no required binaries or credentials. The omission of the 'opencode' CLI (and the implicit requirement for the agent's process/bash capabilities) is an inconsistency: a user installing this should expect the skill to require the opencode binary and the ability to spawn background processes.

      Instruction Scopenote

      Runtime instructions tell the agent to start an OpenCode process in a specified workdir, send JSON-RPC messages, poll for responses, and restart/kill processes. This stays within the stated purpose (managing OpenCode sessions) but it does involve running shell commands and operating in user-specified project directories, which means the skill — via OpenCode — can interact with project files (the initialize message declares fs read/write capabilities). The instructions do not explicitly ask the agent to read unrelated system files or environment variables.

      Install Mechanismok

      This is an instruction-only skill with no install spec or downloaded code, which is lower risk. Nothing will be written to disk by the skill package itself. The primary risk comes from the runtime commands the instructions ask the agent to run.

      Credentialsok

      The manifest does not request environment variables or credentials, and the instructions do not reference secrets or unrelated credentials. That is proportionate. Note: the skill implicitly needs access to the user's filesystem via the OpenCode instance (cwd/workdir), but that is consistent with a code-workflow tool.

      Persistence & Privilegeok

      The skill does not set always:true and is user-invocable. disable-model-invocation is false (default autonomous invocation allowed), which is normal for skills; no excessive persistence or cross-skill configuration changes are requested.

      Guidance

      This skill appears to do what it says (control OpenCode via ACP) but the manifest omitted a key runtime requirement: the 'opencode' CLI and the agent's ability to spawn background processes. Before installing, verify you trust the opencode binary you will run and the skill's author/repo (the SKILL.md links to a GitHub repo). Be aware this skill will run shell commands in your project directories and interact with files through OpenCode — avoid using it in environments with sensitive secrets or untrusted code. Ask the skill author to update the manifest to declare the required 'opencode' binary and any other runtime capabilities, and consider running it first in an isolated/test workspace.

      Latest Release

      v1.0.2

      - Updated skill metadata to version 1.0.2. - Added a dedicated metadata section with links to protocol docs, GitHub repo, and issue tracker. - Minor formatting changes and clarifications in documentation. - No changes to core skill functionality or usage instructions.

      More by @bjesuiter

      Prd

      7 stars

      Mole Mac Cleanup

      1 stars

      Nb

      0 stars

      exe-dev

      0 stars

      Bridle

      0 stars

      self-improving-agent

      @pskoett · 1,456 stars

      Published by @bjesuiter on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]