@httpx-ru/opencode-restrictions-plugin
v0.1.3
Published
Opencode plugin for restricting agents, models, and skills via a whitelist
Maintainers
Readme
@httpx-ru/opencode-restrictions-plugin
Opencode plugin for restricting agents, models, and skills via a whitelist.
Installation
npm install @httpx-ru/opencode-restrictions-pluginUsage
Add the plugin with a pinned version to your project's opencode.json:
// opencode.json
{
"plugin": ["@httpx-ru/[email protected]"]
}Pinning the exact version prevents issues caused by opencode's plugin cache — it does not automatically check npm for updates on every launch. Using @latest or omitting the version entirely may cause the plugin to stall on an older cached version even after a newer one is published.
After changing the pinned version, clear the cache before launching:
rm -rf ~/.cache/opencode/packages/@httpx-ruCreate .opencode/restrict.json with your whitelist rules:
// .opencode/restrict.json
{
"agents": {
"allowed": ["build", "plan", "code-reviewer"]
},
"models": {
"allowed": ["bothub/deepseek-v4-flash"]
},
"skills": {
"allowed": ["code-review"]
}
}Behavior
| Section | Missing | allowed: [] | allowed: [...] |
|---------|---------|---------------|------------------|
| agents | no restriction | disables all file-based agents | disables all except listed |
| models | no restriction | denies all models | allows only listed |
| skills | no restriction | denies all skills | allows only listed |
How it works
| Resource | Mechanism | Enforcement |
|----------|-----------|-------------|
| Agents | cfg.agent[name] = { disable: true } via config() hook | hard |
| Models | enabled_providers + provider.whitelist | hard |
| Skills | permission.skill deny-rules on all agents via config() hook | hard |
Requirements
- opencode >= 1.17
- Node.js >= 22
Development
git clone https://github.com/httpx-ru/opencode-restrictions-plugin
cd opencode-restrictions-plugin
npm install
npm run buildIntegration tests
BOTHUB_API_KEY=your-key bash test/integration.shLicense
MIT
