We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent a3a06ff commit b05d88aCopy full SHA for b05d88a
1 file changed
SECURITY.md
@@ -24,6 +24,7 @@ Server mode is opt-in only. When enabled, set `OPENCODE_SERVER_PASSWORD` to requ
24
| **Sandbox escapes** | The permission system is not a sandbox (see above) |
25
| **LLM provider data handling** | Data sent to your configured LLM provider is governed by their policies |
26
| **MCP server behavior** | External MCP servers you configure are outside our trust boundary |
27
+| **Malicious config files** | Users control their own config; modifying it is not an attack vector |
28
29
---
30
0 commit comments