im fix all your security issues for your project noticed you had lots of issues #6860

Open
opened 2026-02-16 18:05:27 -05:00 by yindo · 3 comments
Owner

Originally created by @KernFerm on GitHub (Jan 19, 2026).

Originally created by @KernFerm on GitHub (Jan 19, 2026).
Author
Owner

@github-actions[bot] commented on GitHub (Jan 19, 2026):

This issue might be a duplicate of existing security issues. Please check:

  • #6355: RCE and file read vulnerability (critical security vulnerabilities)
  • #6361: No trusted workspace functionality leads to arbitrary commands execution on startup
  • #7163: Security Issue - Autoloading Repository Plugins
  • #7173: Security Issue - Lifecycle Script Execution via .opencode/package.json
  • #6527: Plan mode restrictions bypassed when spawning sub-agents
  • #7474: Subagent permissions not enforced - configured restrictions ignored
  • #7982: Security issue with the share function
  • #8852: Opencode running in plan mode called a subagent to bypass edit permission

Feel free to ignore if you're addressing a specific security concern not covered by these issues.

@github-actions[bot] commented on GitHub (Jan 19, 2026): This issue might be a duplicate of existing security issues. Please check: - #6355: RCE and file read vulnerability (critical security vulnerabilities) - #6361: No trusted workspace functionality leads to arbitrary commands execution on startup - #7163: Security Issue - Autoloading Repository Plugins - #7173: Security Issue - Lifecycle Script Execution via .opencode/package.json - #6527: Plan mode restrictions bypassed when spawning sub-agents - #7474: Subagent permissions not enforced - configured restrictions ignored - #7982: Security issue with the share function - #8852: Opencode running in plan mode called a subagent to bypass edit permission Feel free to ignore if you're addressing a specific security concern not covered by these issues.
Author
Owner

@rekram1-node commented on GitHub (Jan 19, 2026):

?

@rekram1-node commented on GitHub (Jan 19, 2026): ?
Author
Owner

@KernFerm commented on GitHub (Jan 19, 2026):

I looked at all your code files and you have lots of security issues Plaintext credential storage, No built-in secrets manager, Risk of secret leakage from workspace, Arbitrary command execution via repo configuration, Broad local file access by default, Injected system prompt behavior. 50 plus

I am handling all of it and making it more secure

Security should be at your top of list for applications like this

I am a principal engineer

@KernFerm commented on GitHub (Jan 19, 2026): I looked at all your code files and you have lots of security issues Plaintext credential storage, No built-in secrets manager, Risk of secret leakage from workspace, Arbitrary command execution via repo configuration, Broad local file access by default, Injected system prompt behavior. 50 plus I am handling all of it and making it more secure Security should be at your top of list for applications like this I am a principal engineer
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: anomalyco/opencode#6860