opencode-safety-classifier
v0.1.2
Published
An opencode plugin that checks every bash command before it runs, on device first and against a safety classifier second, and denies on any failure.
Maintainers
Readme
opencode-safety-classifier
An opencode plugin that checks every bash command before it runs.
Two layers decide. A deterministic on-device layer parses the command with the POSIX shell grammar and answers on its own where it can: read-only commands are allowed without contacting anything, and a never-list of destructive patterns is denied without contacting anything. Whatever it cannot settle goes to a safety classifier model at an endpoint you control. Every failure on the path to a verdict — an unreachable endpoint, a timeout, an unreadable answer, invalid configuration, a command that will not parse — produces a denial, never an allow.
Denials never interrupt the session. The agent is told what was blocked, which layer decided, and to ask you rather than work around it.
Install
{
"plugin": [
[
"opencode-safety-classifier",
{ "endpoint": "http://gpu-box:8080/v1", "model": "stepguard" }
]
]
}Put that in opencode.json (per project) or ~/.config/opencode/opencode.json (per machine), then restart opencode. endpoint and model are the only required settings; every other option has a default.
The endpoint is any server speaking OpenAI-compatible chat completions. Nothing is sent anywhere else, and the plugin emits no telemetry.
Documentation
The full configuration reference, the audit log, the evaluation harness, and the known limitations are in the repository README.
Requirements
opencode 1.18 or newer, on a POSIX shell. PowerShell and cmd are not supported: the analyser reads POSIX shell grammar, so on a non-POSIX shell every command is denied rather than guessed at.
