REPOSITORY EVIDENCE / INDEXABLE REPORT

anomalyco/opencode — MCP & Agent Security Evidence Report

No MCP configuration evidence was observed in the selected bounded scan. Observed evidence classes: Shell / command execution, Download / install, Agent permissions / behavior, CI/CD automation, Supply-chain / dependencies. Evidence observations are review signals, not a safe/unsafe verdict.

Is anomalyco/opencode safe to run?

ShadowMCP does not issue a safe/unsafe verdict. This report shows bounded repository evidence that can help identify what deserves review before running or approving the project.

Scan identity

Report schemashadowmcp.repo-evidence.v9
Scannershadowmcp.web-repo-scan.v22
Scan completed2026-09-19T16:10:59.960Z
Repository branchdev
Scanned commitfee476bb90043a1012abda156dd9af9e5c71b19d
Indexation gateIndexable quality gate passed.

Evidence summary

Review priority
Priority review

This is a triage priority, not a repository risk rating.

No MCP configuration evidence was observed in the selected bounded scan. Observed evidence classes: Shell / command execution, Download / install, Agent permissions / behavior, CI/CD automation, Supply-chain / dependencies. Evidence observations are review signals, not a safe/unsafe verdict.

Evidence categories

Shell / command execution

Found

Selected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.

  • README.mdsudo
  • package.jsonpowershell

Download / install

Found

Selected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.

  • README.mdcurl, npm install, pnpm, yarn
  • .github/workflows/containers.ymldocker
  • .github/workflows/docs-locale-sync.ymlcurl
  • .github/workflows/duplicate-issues.ymlcurl
  • package.jsoninstall lifecycle: postinstall, prepare

MCP configuration

Not found in scanned scope

No matching evidence was observed in the selected bounded scan scope. This is not proof of absence elsewhere.

Agent permissions / behavior

Found

Selected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.

  • AGENTS.mdagent instruction/config file · tools / permissions, agent instructions, model config
  • .github/workflows/close-issues.ymltools / permissions
  • .github/workflows/close-prs.ymltools / permissions
  • .github/workflows/compliance-close.ymltools / permissions, agent instructions
  • .github/workflows/containers.ymltools / permissions
  • .github/workflows/deploy.ymltools / permissions
  • .github/workflows/docs-locale-sync.ymltools / permissions, agent instructions, model config
  • .github/workflows/docs-update.ymltools / permissions, agent instructions, model config
  • .github/workflows/duplicate-issues.ymltools / permissions, agent instructions
  • .github/workflows/generate.ymltools / permissions
  • .github/workflows/nix-eval.ymltools / permissions

CI/CD automation

Found

Selected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.

  • .github/workflows/close-issues.ymlGitHub Actions workflow
  • .github/workflows/close-prs.ymlGitHub Actions workflow
  • .github/workflows/compliance-close.ymlGitHub Actions workflow
  • .github/workflows/containers.ymlGitHub Actions workflow
  • .github/workflows/deploy.ymlGitHub Actions workflow
  • .github/workflows/docs-locale-sync.ymlGitHub Actions workflow
  • .github/workflows/docs-update.ymlGitHub Actions workflow
  • .github/workflows/duplicate-issues.ymlGitHub Actions workflow
  • .github/workflows/generate.ymlGitHub Actions workflow
  • .github/workflows/nix-eval.ymlGitHub Actions workflow
  • .github/workflows26 direct workflow files

Supply-chain / dependencies

Found

Selected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.

  • package.jsonparsed package manifest · 18 declared dependency entries

Scope and limitations

Scan mode: BOUNDED_ROOT_AND_SELECTED_DEPTH1. General recursive crawl: NO.

  • Public, selected and bounded repository evidence only.
  • FOUND means evidence observed, not risk or malicious behavior proven.
  • NOT_FOUND_IN_SCANNED_SCOPE is not proof of absence outside the bounded scan.
  • Trust/community metadata is descriptive context, not a security guarantee.
  • Zero selected dependency evidence does not mean zero dependencies.
  • No repository clone or target-code execution.
  • No raw source-file bodies or secret/token values are included in this report.
  • No general recursive crawl.
  • No CVE lookup, package reputation lookup or package registry lookup.
  • No numeric security score and no safe/unsafe verdict.

Repository context

Trust/community metadata is descriptive context only; it is not a security guarantee.

Repository age / activitycreated 2025-04-30 · 506 days old · last push 2026-09-19 · 0 days since last push
Community signalsstars 208573 · forks 27452 · open issues 5960
OwnershipOrganization · anomalyco
LicenseMIT
Repository statearchived NO · fork NO · default branch dev

Continue the review