Skip to content

Security: okuyam2y/opencode-nofc

Security

SECURITY.md

Security

Upstream

This is a fork of anomalyco/opencode. For security issues in the upstream codebase, please report to the upstream security advisories.

This Fork

For security issues specific to this fork (tool parser middleware, streaming tag filter, document extraction, OCR, etc.), please open a GitHub issue with the label security.

If the issue is sensitive, please email okuyam2y@gmail.com.

Threat Model

See the upstream SECURITY.md for the full threat model. The same considerations apply to this fork. In particular:

  • OpenCode does not sandbox the agent
  • Server mode is opt-in and requires user-configured authentication
  • The tool parser middleware does not change the trust boundary — it translates text-based tool calls into the same tool execution path

There aren't any published security advisories