SkillTotal

Is opencode-mcp safe?

No malicious indicators - review capabilities before installing
Notable — review in context (capabilities are not malware):
  • Dangerous MCP tool capability
  • Node.js network egress
  • Delegated authentication (OAuth 2.0 / OIDC)

What to do: Nothing here argues against installing it. Grant the capabilities it lists only if you expect the tool to need them.

opencode-mcp is an npm package analyzed by SkillTotal's deterministic static scanner. The scan found no malicious indicators. It can: delegated authentication, mcp tools detected and network egress — capabilities are what the code can do, not a verdict on intent. Risk score 0/100 (low).

opencode-mcp 3.0.0

npm_package · npm:opencode-mcp
LOW
0
/ 100 risk score
Snapshot · scanned Oct 7, 2026 · opencode-mcp@3.0.0 · engine 0.56.2 / ruleset 62

Automated static-analysis result. It can contain false positives and false negatives, and is not a claim about the intent of opencode-mcp's authors. Report a false positive.

Capabilities — what this component can do (not a risk score):
delegated authenticationmcp tools detectednetwork egress

Behavioral traits

How this component maps to the CSA agentic threat model. Descriptive — it never affects the risk score.

Tool surface
Tool Usage
Execution authority
Tool Access Control / Direct Tool Access
Network egress
Interaction & Communication / Direct Communication
Delegated authentication
Tool Execution Context / User Delegated Credentials

Findings (4)

HIGHDangerous MCP tool capabilityST-MCP-DANGEROUS-TOOL

An MCP tool exposes a powerful capability (files, shell, network, browser, or credentials).

server.tool("opencode_file_read", "Read the content of a file", {
server.tool("opencode_shell_execute", "Run a shell command through the opencode session", {
server.tool("opencode_tui_execute_command", "Execute a slash command through the TUI (e.g. '/init', '/undo')", {

Why it matters: Wired into an agent, these grant it real access to your machine — confirm each is required.

Fix: Confirm each powerful tool is required and constrained; broad MCP tools (shell/filesystem/network) grant an agent significant host access.

MEDIUMNode.js network egressST-NET-NODE

The component makes outbound network requests.

const res = await withAbort(fetch(url, { method: "GET", headers, signal: context.signal }), context.signal);
const response = await fetch(`${baseUrl.replace(/\/$/, "")}/global/health`, {

Why it matters: Usually legitimate, but confirm the destinations are expected and no sensitive data leaves.

Fix: Confirm the destination hosts are expected and that no sensitive data is sent off-host.

LOWDelegated authentication (OAuth 2.0 / OIDC)ST-AUTH-DELEGATED

An OAuth 2.0 / OpenID Connect delegated-authentication flow was detected (authorization-code / refresh-token / token-exchange grant, an OIDC authorize/discovery endpoint or id_token, or a delegation library). Tools authenticate with the end user's delegated, scoped credentials rather than a long-lived embedded service credential.

return toolJson(await client.post(`/provider/${encodeURIComponent(providerId)}/oauth/authorize`, { method: method ?? 0, ...(inputs ? { inputs } : {}) }));

Fix: Delegated auth is a lower-blast-radius execution context than an embedded static credential. Confirm the requested scopes are minimal and that tokens are never logged or forwarded off-host.

LOWMCP tool surface detectedST-MCP-DETECTED

An MCP tool surface (manifest or tool definitions) was found.

const server = new McpServer({ name: "opencode-mcp", version: "3.0.0",
legacy: "serve", transport: new TaskTransport(new StdioServerTransport(), jobs),
return this.registerTool(name, { description, inputSchema: input, outputSchema: output, annotations }, async (args, ctx) => withRequestOptions({ signal: ctx.mcpReq.signal }, async () => {
server.tool("opencode_config_get", "Get the current opencode configuration", {
server.tool("opencode_config_update", "Update the opencode configuration. Pass a partial config object with fields to update.", {
server.tool("opencode_config_providers", "List all configured providers and their default models", {
server.tool("opencode_events_poll", "Poll project events from OpenCode, or explicitly select global scope. Collects up to maxEvents within the duration. Connection failures are reported with any partial events; stopping observation does not …
server.tool("opencode_find_text", "Search for text patterns in project files (regex supported). Returns file paths, line numbers, and matching lines.", {
server.tool("opencode_find_file", "Find files and directories by name (fuzzy match)", {
server.tool("opencode_find_symbol", "Find workspace symbols by name (functions, classes, variables, etc.)", {
server.tool("opencode_file_list", "List files and directories at a path", {
server.tool("opencode_file_read", "Read the content of a file", {
server.tool("opencode_file_status", "Get status for tracked files (VCS changes: modified, added, deleted, etc.)", {
server.tool("opencode_health", "Check server health and version", {
server.tool("opencode_question_list", "List pending OpenCode questions, optionally filtered to a session.", {
server.tool("opencode_question_reply", "Answer an OpenCode question request. Supply one array of selected labels or free text per question.", {
server.tool("opencode_question_reject", "Reject a pending OpenCode question explicitly.", {
server.tool("opencode_job_list", "List locally retained jobs in this OpenCode server and credential scope.", {
server.tool("opencode_job_input", "Respond to a job's pending questions or permissions. Omit responses to request MCP forms when supported, or receive manual response instructions. Never approves automatically.", {
server.tool("opencode_message_list", "List all messages in a session with formatted output showing roles and content", {
server.tool("opencode_message_get", "Get details of a specific message in a session", {
server.tool("opencode_message_send", "Send a prompt message to a session and wait for the AI response. Use parts to send text, and optionally specify a model.", {
server.tool("opencode_message_send_async", "Send a prompt asynchronously and return its messageId. Pass sessionId and messageId to opencode_wait to observe this exact turn.", {
server.tool("opencode_command_execute", "Execute a slash command in a session (e.g. /init, /undo, /redo)", {
server.tool("opencode_shell_execute", "Run a shell command through the opencode session", {

Why it matters: Just context — review which tools it offers and their permissions.

Fix: Review the declared MCP tools and their permissions.

How attackers abuse these capabilities

Interactive labs on the attack class behind the rules above. They show the technique, not anything found in opencode-mcp.

Check your own component

Run the same evidence-backed scan on any MCP server, agent skill, or package.

Scan your own component

How we determine this: deterministic static analysis (regex + AST), evidence-anchored, no code execution. Methodology →