opencode-audit

Audit OpenCode configurations against a 100-point rubric and generate prioritized remediation plans.

10|1|Updated Jan 18, 2026
One-click install
npx skills add https://github.com/Awish021/opencode --skill opencode-audit
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: opencode-audit
Source: https://github.com/Awish021/opencode/tree/main/skills/opencode-audit
Command: npx skills add https://github.com/Awish021/opencode --skill opencode-audit

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This skill addresses the challenge of ensuring OpenCode configurations are secure, efficient, and adhere to best practices, preventing potential misconfigurations and security vulnerabilities.

Core Features & Use Cases

  • Comprehensive Auditing: Evaluates OpenCode setups against a 100-point rubric covering rules, permissions, agent design, commands, skills, MCP, plugins, and configuration hygiene.
  • Actionable Remediation: Provides concrete, copy-pasteable commands and configuration snippets for fixing identified issues.
  • Prioritized Improvement Plan: Delivers a phased 7-day action plan to guide users toward a hardened and optimized OpenCode environment.
  • Use Case: A team is preparing to roll out a new OpenCode agent configuration to production. They use this skill to perform a pre-deployment audit, identify critical security gaps, and ensure the configuration meets organizational standards.

Quick Start

Use the opencode-audit skill to audit the current OpenCode configuration and provide a remediation plan.

Frequently Asked Questions about opencode-audit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit OpenCode configurations for security and quality?

Auditing OpenCode configurations involves analyzing agent definitions, command routing, skill implementations, and MCP integrations against a 100-point rubric to identify security vulnerabilities and operational inefficiencies across project and global scopes.

What is the best way to fix OpenCode misconfigurations and security vulnerabilities?

The best way to fix OpenCode misconfigurations is to follow a phased 7-day action plan that delivers prioritized, concrete configuration snippets and commands to harden agent definitions, command routing, and plugin reliability.

How do I check OpenCode agent definitions and command routing before production deployment?

Checking OpenCode agent definitions and command routing before production requires a comprehensive pre-deployment audit that scores setup quality and identifies critical security gaps to ensure configurations meet organizational standards.

Does the OpenCode audit evaluate MCP integrations and plugin reliability?

Yes, the OpenCode audit evaluates MCP integrations and plugin reliability, analyzing these specific components across project and global scopes to ensure they adhere to safety, operability, and best practice standards.

How do I get a score and grade for my OpenCode setup quality?

To get a score and grade for your OpenCode setup quality, audit the configuration using a detailed rubric to generate a performance evaluation alongside a prioritized 7-day action plan for targeted improvement.