Complete toolkit for configuring and extending OpenCode: agent creation, custom slash commands, configuration management, plugin development, and SDK usage.
98
98%
Does it follow best practices?
Impact
Pending
No eval scenarios have been run
Advisory
Suggest reviewing before use
A developer added their project's npm run deploy:prod command to the global OpenCode allowlist at ~/.config/opencode/opencode.json because they were tired of seeing permission prompts. Now other projects on their machine are also allowed to run npm run deploy:prod without prompting.
Explain why this is a problem and show the correct way to configure this permission.