REAL THREATS
Critical — Immediate Exploitation Risk
API Keys in Plaintext (0-2): The installer stores API keys in
~/.config/opencode/.env with mode 600. While 600 restricts file permissions, the keys are still stored in plaintext on disk — any process running as the same user, or via privilege escalation, can read them. This is a credential exposure vulnerability.
No Tenant Isolation (3, 10, 11, 13, 46, 64): The entire system operates without any tenant context. All agents share state files (
~/.work/state.json,
~/.work/agent-lru.json), session configurations, and cache keys. In a multi-user or CI/CD environment, this allows cross-tenant data leakage and state corruption.
Auto-Approve Shell Commands (5, 18, 20, 22): The orchestrator automatically approves shell permission prompts within ~15 seconds. This bypasses all user consent for command execution. An attacker who compromises the orchestrator or injects a malicious prompt can execute arbitrary shell commands without user awareness.
Deny Policy Bypass via File Tools (6, 27, 31, 66, 70, 71): The Gemini deny policy only blocks destructive shell commands but explicitly instructs reviewers to use
write_file/
replace tools instead — which are auto-approved. This means
write_file can overwrite any file in the workspace, including source code, configuration, and credentials. The system path protection only covers
/etc,
/usr,
/var, etc., but misses
/home,
/root,
~/.ssh, and the entire workspace.
OpenCode Agent Compromise (7, 38-44, 47-52): The OpenCode permission model grants unrestricted
external_directory access,
websearch,
webfetch, and a wildcard bash allow-list with a catch-all
"*": "ask". This allows an attacker to read arbitrary files, exfiltrate data via web requests, execute arbitrary commands (the allow-list includes
echo,
sed,
awk,
for,
while which can all be used for file writes and command execution), and perform SSRF attacks.
Unrestricted Web Search/Fetch (8, 39, 45, 49): OpenCode has
websearch and
webfetch set to
"allow" with no restrictions. This enables data exfiltration to attacker-controlled servers, SSRF against internal services, and cost-inflating API calls.
High — Significant Architectural Weaknesses
No Authentication for Work Orchestrator (16, 19): The
/work command and orchestrator binaries have no authentication or authorization. Any user who can invoke Claude Code can trigger the full multi-LLM pipeline, including code review, git operations, and PR creation.
No Session Management (17): LLM agent sessions have no timeout or token expiry. A session left open indefinitely can be hijacked or accumulate sensitive context.
No Credential Sanitization (21, 42, 58, 62): Review outputs, logs, and agent sessions may capture API keys, tokens, and secrets from code context. There is no redaction or sanitization layer.
Model Supply Chain Risk (15): HuggingFace model loading without pinned revision allows supply chain attacks via model repository compromise.
False Confidence in Self-Review (24, 35, 43, 52, 71): The pre-merge checklist is self-reported by the same model that created the code. The deny policy and auto-edit mode claim safety but provide no actual protection against the tools they explicitly allow. The bash allowlist includes commands like
echo and
sed which can write arbitrary files.
No Data Retention/Deletion Policy (26): Review findings and agent session logs may contain sensitive code context with no documented retention or deletion policy.
Proxy Header Trust (30): The system trusts
X-Forwarded-For headers without validation, enabling IP spoofing.
Denial of Wallet (45, 48, 61): Unbounded web search/fetch permissions and no budget circuit breaker allow an attacker to inflate API costs by triggering expensive operations.
No Containerization/Sandboxing (56, 60): Agents run directly on the host without container isolation. A compromised agent has full access to the user's filesystem and credentials.
ATTACK CHAINS
Chain 1: Full Pipeline Compromise via Orchestrator Hijacking (4, 5, 16, 19, 20, 22)
1. Attacker gains access to Claude Code session (no auth on /work)
2. Attacker invokes /work with a malicious task
3. Orchestrator auto-approves shell commands within ~15 seconds
4. Attacker executes arbitrary commands on the host
5. Attacker reads API keys from ~/.config/opencode/.env (plaintext)
6. Attacker uses stolen keys to access external services (OpenAI, Google AI, Moonshot, DeepSeek)
7. Attacker modifies code, creates malicious PRs, or exfiltrates data
Chain 2: Data Exfiltration via OpenCode (7, 8, 38, 39, 49, 50)
1. Attacker injects a prompt that triggers OpenCode review
2. OpenCode has unrestricted external_directory access — reads ~/.ssh/id_rsa, ~/.aws/credentials, etc.
3. OpenCode has unrestricted webfetch — sends data to attacker-controlled server
4. OpenCode has unrestricted bash with wildcard allow — executes curl or wget to exfiltrate
5. No audit logging captures the exfiltration
Chain 3: Deny Policy Bypass via File Write Tools (6, 27, 31, 66, 70, 71)
1. Gemini deny policy blocks rm -rf, sudo, etc.
2. But the GEMINI.snippet.md explicitly tells reviewers to use write_file/replace instead
3. write_file is auto-approved by auto_edit mode
4. System path protection only covers /etc, /usr, /var, /boot, /sys, /proc, /root, /opt, /bin, /sbin, /lib
5. Attacker writes to ~/.ssh/authorized_keys, ~/.bashrc, /home/user/.config/, or workspace files
6. No protection against overwriting source code with malicious content
Chain 4: Cross-Tenant Data Leakage (3, 10, 11, 13, 46, 64)
1. Multiple users or CI/CD pipelines share the same installation
2. All agents share ~/.work/state.json, ~/.work/agent-lru.json, ~/.config/agent-sessions/agents.json
3. No tenant namespace in cache/state keys
4. Agent session logs capture sensitive code context from all tenants
5. A malicious tenant can read another tenant's code, credentials, and review findings
VERDICT
This codebase is critically vulnerable and should NOT be deployed in any production, shared, or multi-user environment without significant remediation.The most urgent issues are:
1. Immediate: Remove plaintext API key storage. Use a secret manager or encrypted credential store.
2. Immediate: Remove the auto-approve mechanism for shell commands. Require explicit user consent for every command.
3. Immediate: Restrict OpenCode permissions — remove wildcard bash allow, restrict external_directory to specific paths, add URL allowlists for webfetch/websearch.
4. Immediate: Add tenant isolation — namespace all state files, cache keys, and session data.
5. High Priority: Add authentication to the /work orchestrator and all agent endpoints.
6. High Priority: Implement credential sanitization/redaction in all logs and review outputs.
7. High Priority: Add containerization/sandboxing for agent execution.
8. High Priority: Fix the deny policy to cover write_file/replace tools, not just shell commands. Extend path protection to cover /home, /root, ~/.ssh, and workspace directories.
9. Medium Priority: Add session timeouts, budget circuit breakers, and audit logging.
10. Medium Priority: Pin model versions in supply chain and add integrity verification for installation.
The architectural pattern of "allow everything, block nothing meaningful" combined with "auto-approve dangerous operations" creates a system where a single compromise leads to full host takeover and credential theft. This is a design-level failure, not just a configuration issue.