Security fixes are supported for the latest published version of
opencode-acpx.
Please report suspected vulnerabilities using GitHub private vulnerability reporting. Include the plugin, OpenCode and ACP-agent versions and a minimal, redacted reproduction. Do not include credentials, raw environment values or unredacted protocol traces in an issue.
See docs/security.md for the plugin's trust boundaries and default safeguards.