setup
>-
Install this skill
or
60/100
Security score
The setup skill was audited on Aug 27, 2026 and we found 4 security issues across 4 threat categories, including 2 high-severity. Review the findings below before installing.
Categories Tested
Security Issues
high line 63
Piping content to bash shell
SourceSKILL.md
| 61 | If it is missing: |
| 62 | ``` |
| 63 | curl -fsSL https://opencode.ai/install | bash |
| 64 | ``` |
| 65 | (or `npm install -g opencode-ai` if they'd rather use npm). Nothing to pay |
medium line 63
Curl to non-GitHub URL
SourceSKILL.md
| 61 | If it is missing: |
| 62 | ``` |
| 63 | curl -fsSL https://opencode.ai/install | bash |
| 64 | ``` |
| 65 | (or `npm install -g opencode-ai` if they'd rather use npm). Nothing to pay |
medium line 146
Access to home directory dotfiles
SourceSKILL.md
| 144 | rotated at the provider — a leaked key is not un-leaked by deleting a message. |
| 145 | |
| 146 | Keys live outside this plugin's folder, in `~/.claude/multi/providers.env`, |
| 147 | which `scripts/setup.sh` sets to permission `600` — only their own user can |
| 148 | read it. On Windows/MSYS and on some mounts (exFAT, some NTFS) `chmod` is |
high line 63
Curl pipe to interpreter
SourceSKILL.md
| 61 | If it is missing: |
| 62 | ``` |
| 63 | curl -fsSL https://opencode.ai/install | bash |
| 64 | ``` |
| 65 | (or `npm install -g opencode-ai` if they'd rather use npm). Nothing to pay |
Scanned on Aug 27, 2026
View Security Dashboard