Stop Using OpenCode
A critical critique of the open-source AI coding agent 'OpenCode' argues that the tool is insecure and poorly designed. The author warns that the software's architecture poses significant risks to user systems.
Why it matters
This highlights the growing security concerns surrounding the rapid adoption of AI-driven coding assistants that may lack robust safety protocols.
If you don’t know what OpenCode is, imagine a boot stamping on a human face forever. The boot is made of TypeScript and the face is everything we have learned about security and systems software since the invention of the electronic computer in the 1940s. The creators describe it as an AI coding agent. As far as I can tell it’s the most popular open-source coding agent, and it currently has 161k stars on GitHub.
I’ve tried out OpenCode with a local LLM. My conclusion is that OpenCode is clown-car turboslop with a security posture of “let me bend over for you daddy”. Everyone using it should stop using it.
There are two parts to this post: annoying things and alarming things . The second part is longer. I wrote this post with reference to source code from OpenCode git version baef5cd4 .
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in