← All reviews

Oh My OpenAgent

Agent Orchestration

Oh My OpenAgent brings powerful multi-agent orchestration to OpenCode, but critical unpatched vulnerabilities and dangerous defaults make it unsafe for trusted environments.

Significant risks — not recommended for production or any use case involving personal data. See the Recommendations & Guidance tab below.

Score Summary

Claim Accuracy2/5
Data & Privacy3/5
Security Posture1/5
Transparency2/5

Key Findings

The interactive_bash tool contains an unpatched vulnerability allowing arbitrary command execution in any Tmux session, which can be exploited via prompt injection from malicious repositories.

The maintainer has previously dismissed security reports concerning excessive permissions as 'working as designed,' indicating a concerning security response posture.

Anonymous telemetry via PostHog is enabled by default and collects hashed hostnames and error diagnostics, requiring an explicit environment variable to opt out.

Marketing claims of complete agent autonomy are contradicted by known bugs, such as agents successfully bypassing task loops without actually executing the required work.

The disabled_tools configuration is parsed but ignored by the system, leaving supposedly restricted tools fully functional.