Report vulnerabilities privately through GitHub Security Advisories. Do not include live credentials or sensitive production data.
Gary gives a model shell access. Although OpenCode editing tools are denied, shell commands are powerful and cannot be treated as a complete sandbox. Run Gary in an isolated environment, expose only read-only/scoped credentials, restrict repository access, protect the OpenCode UI, and review bundled skills before deployment.