• Sources: wren.wtf write-up, HN discussion
  • Summary: A widely discussed write-up published 2026-07-19 argues that the OpenCode coding agent's safety controls are weak. The author reports that its bash-permission filter, which parses commands with a tree-sitter syntax tree, is bypassable through pipes, environment variables, aliases, absolute paths, base64 encoding, heredocs, and subprocess calls, and that a persisted "always" approval applies to an entire command prefix. The post also reports file-path validation that shell redirections and some build tools evade, remote models wired to a local shell by default, and cites CVE-2026-22812 for a previously exposed local HTTP server. It separately lists prompt-cache and terminal-UI issues as lower-severity annoyances.
  • Comments: HN commenters split on the thesis: some argue textual command filtering is inherently security theater and endorse isolating agents at the OS or container level, while others say the critique overreaches and defend OpenCode's free-model tier as their reason for using it.
  • Why it matters: Coding-agent permission prompts are widely treated as a sandbox, so a concrete account of how easily one popular agent's command filters are bypassed argues for OS-level isolation over in-agent allowlists.

send feedback on this story