← Back to context

Comment by tancop

1 day ago

Closed source agents are a red flag no matter if its China or America. Always use an open harness with a good reputation and enough users that someone will notice if they push malicious code like this one here. Right now that's Opencode and Pi.

I wouldn't list Opencode as "good reputation".

They had their own unbound "harness scans the whole user directory" oopsie and handled concerns about that by introducing code signing.

Which, yes, does have absolutely nothing to do with that issue.

I guess by now it is better, but to me they seem to lack the engineering culture necessary for a "good reputation" stamp.

__

Ref: https://github.com/anomalyco/opencode/issues/14925#issuecomm...

among other issues.

  • How about the one where if you start a session outside of a Git repository, the "worktree root" is set to /. Bug report closed as "not planned".

    • FWIW, I don't think that they're being malicious. They instead just seem to have no idea nor do they care.

      And the original comment I've replied to proves this strategy right! So from a business standpoint: excellent work.

      6 replies →

  • Their reputation is “bad” but not because of privacy concerns. I personally think they’re trustworthy

    • We use opencode with self hosted llm for privacy reasons. Good, right? Well, no, because opencode by default uses a "free" cloud model to summarize all chats even if a different model was configured as the main one.

      I wonder how many opencode users upload their private secrets to the cloud, while thinking they're using a self hosted model.

      Btw. I don't think this is malicious, just sloppy.

      1 reply →

codex is also open source, though im not so sure about the reputation aspect.

The same can be said about opencode though.