npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

oc-auto-perms

v0.1.3

Published

Intent-aware OpenCode permissions powered by TypeSafe AI's Jev model.

Downloads

647

Readme

oc-auto-perms

Intent-aware permissions for OpenCode V2, powered by TypeSafe AI's Jev decision model.

Unlike static permission rules, oc-auto-perms evaluates the policy, recent user requests, and full tool input together. A rule such as “only access google.com” therefore applies whether the agent uses webfetch, curl, or another tool.

Setup

npm install oc-auto-perms

By default the plugin uses TypeSafe directly. Set JEV_API_KEY in .env or the OpenCode server environment, then add the plugin to opencode.jsonc:

{
  "$schema": "https://opencode.ai/config.json",
  "plugins": [
    {
      "package": "oc-auto-perms",
      "options": {
        "guardedTools": ["shell", "webfetch", "websearch"],
        "permissions": [
          {
            "tools": ["shell"],
            "effect": "allow",
            "examples": ["git status", "git diff --stat"],
            "when": "Only inspects repository status."
          },
          {
            "effect": "allow",
            "examples": ["curl https://google.com", "!curl https://example.com"],
            "when": "Only accesses web content from google.com or its subdomains."
          },
          { "effect": "deny", "when": "Sends secrets or credentials over the network." }
        ]
      }
    }
  ]
}

Jev gateways

The plugin supports TypeSafe, OpenRouter, Vercel AI Gateway, and OpenCode Zen through their native System One endpoints. Gateway accounts already connected through OpenCode are reused automatically, so their keys do not need to be duplicated in plugin configuration.

{
  "plugins": [
    {
      "package": "oc-auto-perms",
      "options": {
        "gateway": "opencode",
        "permissions": [
          { "effect": "allow", "when": "Only inspects the current repository." }
        ]
      }
    }
  ]
}

| Gateway | gateway | Default model | Authentication | | --- | --- | --- | --- | | TypeSafe | "typesafe" | jev-latest | JEV_API_KEY | | OpenRouter | "openrouter" | jev-latest | Connected OpenRouter account, then JEV_API_KEY | | Vercel AI Gateway | "vercel" | typesafe-ai/jev | Connected Vercel account, then JEV_API_KEY | | OpenCode Zen | "opencode" | jev-1.13 | Connected OpenCode account, then JEV_API_KEY |

For OpenRouter, Vercel, and Zen, the plugin first tries the active account configured through OpenCode's /connect. If none is available, every gateway falls back to the same JEV_API_KEY environment variable. TypeSafe uses JEV_API_KEY directly because it is not an OpenCode provider.

The plugin verifies that a credential exists when it starts and fails to load with a gateway-specific setup error when none is available. A later evaluation failure—such as rejected credentials, insufficient credits, rate limiting, an unavailable model, timeout, or provider outage—never silently allows or denies the action: the permission falls back to user confirmation with an actionable error message. Existing native OpenCode ask and deny decisions remain unchanged.

Calls still go directly to each gateway's typed System One endpoint rather than OpenCode's text-generation route. This preserves Jev's choice and confidence response.

Policy rules

  • effect and when are required.
  • tools is optional and defaults to every guarded tool. It accepts "all" or a list of tool names.
  • examples are optional hints, not an exhaustive allowlist. Prefix counterexamples with !.
  • Rules are ordered; the last applicable rule wins.
  • If no allow rule matches, the action is denied.

Jev judges intent across tools, so switching from webfetch to curl does not bypass a rule.

Supported tools

oc-auto-perms supports the following permission-exposed OpenCode tools:

  • read
  • edit, write, and patch
  • glob and grep
  • shell
  • subagent
  • skill
  • question
  • webfetch and websearch
  • MCP and custom plugin tools

External-directory checks made by these tools are evaluated too. Use guardedTools: "all" to cover every supported tool, including tools added by plugins or MCP servers.

Options

| Option | Default | Description | | --- | --- | --- | | gateway | "typesafe" | "typesafe", "openrouter", "vercel", or "opencode" | | model | gateway-specific | Jev model sent to the gateway | | guardedTools | "all" | "all" or the tool names Jev should evaluate | | permissions | required | Ordered policy rules | | minConfidence | 0.8 | Confidence required for an automatic decision | | historyLimit | 3 | Recent user messages included as context |

OpenCode remains the outer permission layer: native deny is final, native ask always prompts, and Jev can narrow a native allow. Low-confidence decisions and API errors also fall back to ask.

Note: Agents can use Code Mode execute to bypass these policies because OpenCode does not expose Code Mode programs to plugins. Use native OpenCode permissions to restrict Code Mode when needed.

Keep deterministic OpenCode rules for hard boundaries and use Jev for semantic policies. The policy, recent user messages, permission resources, and tool input are sent to the selected gateway for evaluation.