Pre-Alpha Fixes (10 items):
- Fix credential file permissions in calendar.ts (mode: 0o600)
- Add socket close handler in ipc-server.ts (memory leak prevention)
- Add event unsubscribe in daemon.stop() (memory leak prevention)
- Wrap Qdrant init with retry logic and graceful degradation
- Fix ALWAYS-ON-PERSONAS.md gateway architecture documentation
- Remove legacy spawn('claude') in tiara executor-sdk.ts
- Filter environment variables via safe-env.ts utility
- Add error boundary around IPC socket writes
- Update tiara README.md and INDEX.md version references
- Create zee gateway external-gateway.md documentation
Beta Security Fixes (6 items):
- CRITICAL: Fix command injection via persona parameter validation
- HIGH: Fix terminal escape sequence injection in setPaneTitle
- HIGH: Fix command escaping in sendCommand and canvas manager
- HIGH: Add secret redaction for copilot auth logging
- MEDIUM: Fix echo -e ANSI escape injection in status display
- MEDIUM: Strengthen prompt injection defense in fact-extractor
New Utilities:
- src/util/safe-env.ts: Environment variable filtering for child processes
- src/util/shell-escape.ts: Shell escaping, persona validation, secret redaction
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Agent-Core
Fork of sst/opencode — Built on OpenCode. All credit goes to the brilliant SST team and the OpenCode contributors for creating an exceptional open-source AI coding agent. This fork extends OpenCode with a specialized personas system, semantic memory, and multi-surface orchestration. Please use the upstream repository for official releases and support; use this fork at your own risk.
Agent-Core is a CLI agent engine that powers the Personas system (Zee, Stanley, Johny). Built on OpenCode's excellent foundation, it adds persona-based routing, semantic memory, and orchestration capabilities.
Quick Start
Prerequisites
Installation
# Clone the repository
git clone https://github.com/yourusername/agent-core.git ~/.local/src/agent-core
# Install dependencies
cd ~/.local/src/agent-core
bun install
# Build the project
cd packages/agent-core
bun run build
# Install the binary (optional)
cp dist/agent-core-linux-x64/bin/agent-core ~/bin/agent-core
Configuration
- Copy the environment template:
cp .env.example .env
- Edit
.envand add your API keys:
ANTHROPIC_API_KEY=sk-ant-...
OPENAI_API_KEY=sk-... # For embeddings
QDRANT_URL=http://localhost:6333
- Start Qdrant (if running locally):
docker run -p 6333:6333 qdrant/qdrant
Running
Interactive TUI:
agent-core
Daemon mode (for Zee gateway):
agent-core daemon --gateway --hostname 127.0.0.1 --port 3210
Architecture
agent-core/
├── packages/agent-core/ # Main CLI and TUI (OpenCode fork)
├── src/
│ ├── personas/ # Persona logic and routing
│ ├── memory/ # Qdrant semantic memory
│ ├── daemon/ # HTTP/IPC daemon
│ └── domain/ # Domain tools (zee/, stanley/)
├── vendor/tiara/ # Orchestration layer (SPARC methodology)
└── .claude/skills/ # Persona skill definitions
Personas
| Persona | Domain | Description |
|---|---|---|
| Zee | Personal Assistant | Memory, messaging, calendar, notifications |
| Stanley | Investing | Markets, portfolio, trading strategies |
| Johny | Learning | Knowledge graphs, spaced repetition |
Key Features
- Semantic Memory: Vector-based memory with Qdrant for context persistence
- Multi-Persona Routing: Route messages to specialized personas
- Orchestration: SPARC methodology via tiara for complex tasks
- External Gateway: HTTP API for messaging platform integration
Usage with Zee Gateway
The Zee Gateway handles messaging platforms (WhatsApp, Telegram, Discord, etc.) and routes to agent-core:
# Terminal 1: Start agent-core daemon
agent-core daemon --gateway
# Terminal 2: Start zee gateway
cd ~/Repositories/personas/zee
pnpm zee gateway
Messages mentioning @stanley or @johny are routed to those personas; all others go to Zee.
Development
# Run tests
bun test
# Build
bun run build
# Type check
bun run typecheck
Wide events
Agent-core emits wide event JSONL logs for per-request diagnostics:
agent-core logs wide --lines 50
agent-core logs wide --where sessionId=session_123
Credits
- OpenCode by SST - The foundation this project builds on
- Claude-Flow - SPARC orchestration patterns
License
Same as upstream OpenCode - see LICENSE file.