mirror of
https://github.com/anomalyco/opencode.git
synced 2026-02-01 14:44:46 +00:00
docs: clarify that malicious config files are not an attack vector
This commit is contained in:
@@ -24,6 +24,7 @@ Server mode is opt-in only. When enabled, set `OPENCODE_SERVER_PASSWORD` to requ
|
|||||||
| **Sandbox escapes** | The permission system is not a sandbox (see above) |
|
| **Sandbox escapes** | The permission system is not a sandbox (see above) |
|
||||||
| **LLM provider data handling** | Data sent to your configured LLM provider is governed by their policies |
|
| **LLM provider data handling** | Data sent to your configured LLM provider is governed by their policies |
|
||||||
| **MCP server behavior** | External MCP servers you configure are outside our trust boundary |
|
| **MCP server behavior** | External MCP servers you configure are outside our trust boundary |
|
||||||
|
| **Malicious config files** | Users control their own config; modifying it is not an attack vector |
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user