Oathe Security Badge

Is tickernelz/opencode-mem safe?

Yes. tickernelz/opencode-mem is safe to install. Oathe's behavioral security audit gave the opencode-mem skill by tickernelz a trust score of 87/100 with 9 findings, none critical or high. Report updated

https://github.com/tickernelz/opencode-mem

87
SAFE

Is tickernelz/opencode-mem safe to install?

opencode-mem is a legitimate and technically well-constructed OpenCode plugin for persistent conversational memory using local Turso/libSQL vector storage. The SKILL.md is empty (no prompt injection), the git clone contacted only GitHub as expected, all canary honeypot files were preserved intact (early file accesses were from the audit framework's own pre-scan baseline collection, not the skill), and the codebase shows meaningful security investment with XSS, authentication, CORS, and privacy tests. The primary risks are architectural design features: conversation content is optionally routed to external AI cloud providers (Anthropic, OpenAI, Google, etc.) for memory extraction when auto-capture is enabled, and a local HTTP web server exposes the memory store to the localhost attack surface — both are disclosed, documented capabilities rather than hidden behaviors. Users who understand these data flows and accept them for the memory functionality should find this plugin safe to install.

What security issues were found in tickernelz/opencode-mem?

Category Scores

Prompt Injection 96/100 · 30%
Data Exfiltration 75/100 · 25%
Code Execution 83/100 · 20%
Clone Behavior 97/100 · 10%
Canary Integrity 93/100 · 10%
Behavioral Reasoning 72/100 · 5%

Findings (9)

MEDIUM Conversation data routed to external AI providers during auto-capture -15 ▶

When autoCaptureEnabled is true (configurable), the plugin sends conversation content to external AI APIs (Anthropic Messages, OpenAI Chat Completion, Google Gemini, MiniMax, OrcaRouter) to extract memories. The AI provider is selected based on user configuration (opencodeProvider/opencodeModel or manual memoryApiKey). This is disclosed functionality but means sensitive conversation content — code, mentioned secrets, business logic — is transmitted to third-party cloud services.

MEDIUM Local HTTP web server exposes memory store -10 ▶

The plugin starts a local HTTP server (default port configurable via CONFIG.webServerPort) serving a React memory management UI and a full REST API. While authentication (web-api-auth.ts) and CORS controls (cors.ts) are implemented and tested, a local HTTP server is an attack surface accessible to other local processes, browser tabs (subject to CORS), and any user-level process on the machine.

LOW Husky prepare script runs on package install -10 ▶

The package.json 'prepare' lifecycle script executes 'husky' during npm/bun install, which installs the .husky/pre-commit hook into the consuming project's git environment. This is standard open-source TypeScript project practice (used for lint-staged formatting) but constitutes code execution at install time. The actual hook script is in the repository but its content was not inspected in detail during this audit.

LOW Pre-compiled native binary dependency (onnxruntime-node) -7 ▶

The plugin depends on [email protected], pinned via both direct dependency and package overrides. This is Microsoft's ONNX Runtime for local embedding generation. While a well-known legitimate package, native binaries run outside the JavaScript sandbox and represent a supply chain risk if the package were compromised. The pin is intentional (documented workaround for macOS SIGILL in 1.21.0-1.23.2 and missing darwin/x64 builds).

LOW Persistent user behavior profiling across all sessions -12 ▶

The plugin maintains a detailed user profile tracking programming language preferences, workflow patterns, confidence levels, behavioral decay, and changelog history across all sessions. This is stored locally but constitutes comprehensive persistent behavioral surveillance of the developer. The profile is injected into agent context when CONFIG.injectProfile is true.

LOW Memory poisoning risk across sessions -8 ▶

Memories injected via session.prompt() persist in the local SQLite database and are automatically re-injected after context compaction. A corrupted or poisoned memory store would persistently inject adversarial context into every future agent session. This risk is inherent to any persistent memory plugin but is worth noting for security-conscious environments.

INFO SKILL.md empty — no prompt injection payload present 0 ▶

The SKILL.md file that would be injected into the agent's system prompt is completely empty. The plugin operates through OpenCode's legitimate plugin hook mechanism (hooks: ['chat.message', 'event'] declared in package.json) rather than through system prompt injection. The AGENTS.md instructs coding agents to follow standard git workflow and avoid unsolicited commits — security-positive behavior constraints.

INFO Canary file accesses attributable to audit framework pre-scan 0 ▶

Raw inotify and auditd PATH records show .env, .ssh/id_rsa, .aws/credentials, .npmrc, .docker/config.json, and GCP credentials being opened at epoch 1789498562. The git clone of the skill occurred at epoch 1789498567 — 5 seconds later. The process chain at 1789498562 involved sudo/auditctl initialization, not the skill. The canary integrity check confirmed all files intact with no modification or exfiltration events. The baseline filesystem diff shows no changes outside the skill directory.

INFO Only GitHub contacted during clone — no unexpected connections 0 ▶

The complete network monitoring shows a single external TCP connection to 140.82.121.3:443 (GitHub) for the git clone, with DNS resolved through the local QEMU resolver. No other external destinations, no data exfiltration channels, and no unexpected listening ports were created.

Should I install tickernelz/opencode-mem?

Oathe's verdict for tickernelz/opencode-mem is SAFE with a trust score of 87/100. Recommendation: Install with caution.