Report security-sensitive installer behavior through GitHub private vulnerability reporting instead of a public issue.
Please include the affected OpenCode version, operating system, installation command, and reproduction steps. Do not include tokens, private configuration, or unrelated files from your home directory.