a day ago
- OpenCode is a popular open-source AI coding agent with 161k stars on GitHub.
- The author criticizes OpenCode for poor design, security vulnerabilities, and usability issues.
- Annoying aspects include inefficient prompt caching, flawed context pruning, broken subagent interactions, and a buggy text UI.
- Alarming security issues include trivial bypasses of command filters, unsafe default permissions, and a history of CVEs allowing remote code execution.
- The author advises users to stop using OpenCode and calls for better security practices in coding agents.
- A postscript discusses local LLMs, noting they avoid cloud dependence but still pose risks to code integrity.