opencode-mcp
npm
v1.11.0
Published by alaeddinemessadi — no publish provenance, so origin is unverified, but the source is public: the repository link below is self-declared yet readable, so you can inspect the code before adopting it.
MCP server that wraps the OpenCode AI headless server API — 80 tools, 10 resources, 6 prompts with multi-project support for any MCP client
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 7 = 93. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −6 | capability blast radius (high) — client exposure if the model is manipulated |
| −1 | publisher verification (public source) — no provenance, but the source is public and inspectable |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
Tools that read sensitive data ([opencode_file_list]) and tools that can send data out ([opencode_shell_execute, opencode_project_init, opencode_tui_execute_command]) are exposed together. An agent can move private data to the sink.
Evidence: sources [opencode_file_list] → sinks [opencode_shell_execute, opencode_project_init, opencode_tui_execute_command]
Fix: Keep secret-reading and egress capabilities on separate, separately-approved servers.
Location: flow opencode_file_list → opencode_shell_execute
Tool "opencode_shell_execute" appears to run shell commands or evaluate code (keyword "shell" in tool name). Arbitrary execution driven by model input is one of the most dangerous MCP capabilities; combined with any untrusted input it becomes RCE.
Fix: Sandbox execution, allowlist commands/arguments, and never pass model output to a shell unescaped.
Location: tool opencode_shell_execute
Tool "opencode_tui_execute_command" appears to run shell commands or evaluate code (keyword "execute command" in tool name). Arbitrary execution driven by model input is one of the most dangerous MCP capabilities; combined with any untrusted input it becomes RCE.
Fix: Sandbox execution, allowlist commands/arguments, and never pass model output to a shell unescaped.
Location: tool opencode_tui_execute_command
Tool "opencode_shell_execute" can mutate/egress but declares no destructiveHint. Clients that don't default to spec-safe behavior may not prompt before running it.
Fix: Declare accurate annotations, and gate destructive tools on user confirmation regardless.
Location: tool opencode_shell_execute
Tool "opencode_tui_execute_command" can mutate/egress but declares no destructiveHint. Clients that don't default to spec-safe behavior may not prompt before running it.
Fix: Declare accurate annotations, and gate destructive tools on user confirmation regardless.
Location: tool opencode_tui_execute_command
Each tool and what it can reach — statically extracted from the published source.
opencode_file_listreads sensitive dataopencode_project_initnetwork egressopencode_shell_executeruns code / shellopencode_tui_execute_commandruns code / shellopencode_agent_listno sensitive capabilityopencode_askno sensitive capabilityopencode_auth_setno sensitive capabilityopencode_checkno sensitive capabilityopencode_command_executeno sensitive capabilityopencode_command_listno sensitive capabilityopencode_config_getno sensitive capabilityopencode_config_providersno sensitive capabilityopencode_config_updateno sensitive capabilityopencode_contextno sensitive capabilityopencode_conversationno sensitive capabilityopencode_events_pollno sensitive capabilityopencode_file_readno sensitive capabilityopencode_file_statusno sensitive capabilityopencode_find_fileno sensitive capabilityopencode_find_symbolno sensitive capabilityopencode_find_textno sensitive capabilityopencode_fireno sensitive capabilityopencode_formatter_statusno sensitive capabilityopencode_healthno sensitive capabilityopencode_instance_disposeno sensitive capabilityopencode_logno sensitive capabilityopencode_lsp_statusno sensitive capabilityopencode_mcp_addno sensitive capabilityopencode_mcp_statusno sensitive capabilityopencode_message_getno sensitive capabilityopencode_message_listno sensitive capabilityopencode_message_sendno sensitive capabilityopencode_message_send_asyncno sensitive capabilityopencode_path_getno sensitive capabilityopencode_permission_listno sensitive capabilityopencode_project_currentno sensitive capabilityopencode_project_listno sensitive capabilityopencode_provider_auth_methodsno sensitive capabilityopencode_provider_listno sensitive capabilityopencode_provider_modelsno sensitive capabilityopencode_provider_oauth_authorizeno sensitive capabilityopencode_provider_oauth_callbackno sensitive capabilityopencode_provider_testno sensitive capabilityopencode_replyno sensitive capabilityopencode_review_changesno sensitive capabilityopencode_runno sensitive capabilityopencode_session_abortno sensitive capabilityopencode_session_childrenno sensitive capabilityopencode_session_createno sensitive capabilityopencode_session_deleteno sensitive capabilityopencode_session_diffno sensitive capabilityopencode_session_forkno sensitive capabilityopencode_session_getno sensitive capabilityopencode_session_initno sensitive capabilityopencode_session_listno sensitive capabilityopencode_session_permissionno sensitive capabilityopencode_session_revertno sensitive capabilityopencode_session_searchno sensitive capabilityopencode_session_shareno sensitive capabilityopencode_session_statusno sensitive capabilityopencode_session_summarizeno sensitive capabilityopencode_session_todono sensitive capabilityopencode_session_unrevertno sensitive capabilityopencode_session_unshareno sensitive capabilityopencode_session_updateno sensitive capabilityopencode_sessions_overviewno sensitive capabilityopencode_setupno sensitive capabilityopencode_statusno sensitive capabilityopencode_tool_idsno sensitive capabilityopencode_tool_listno sensitive capabilityopencode_tui_append_promptno sensitive capabilityopencode_tui_clear_promptno sensitive capabilityopencode_tui_open_helpno sensitive capabilityopencode_tui_open_modelsno sensitive capabilityopencode_tui_open_sessionsno sensitive capabilityopencode_tui_open_themesno sensitive capabilityopencode_tui_show_toastno sensitive capabilityopencode_tui_submit_promptno sensitive capabilityopencode_vcs_infono sensitive capabilityopencode_waitno sensitive capabilityCross-tool combinations that form a data-exfiltration primitive (untrusted input → sensitive source → external sink).
Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v1.11.0 latest |
A 93/100 | 5 | 1.13.0 | 2026-09-07 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan opencode-mcp --online
Independent packages implementing the same tool, scanned with the same engine. Compare all 6 side by side →
MCP server that lets any MCP host (Claude Code, Codex CLI, Cursor, etc.) drive OpenCode and delegate tasks asynchronously to its agents
MCP Server for remote OpenCode HTTP API - Connect OpenClaw to OpenCode agents
MCP server for orchestrating OpenCode instances across machines via SSH reverse tunnels
MCP memory / second brain for Claude Code & OpenCode — captures your coding sessions and distills how your knowledge and habits evolve over time, queryable by your agent.
MCP server for opencode — query github-copilot models via a persistent opencode server.
Hotel booking MCP server — 300K+ properties, real confirmation numbers, loyalty programs. Builders monetize every booking via Stripe Connect. The first MCP server that completes real hotel reservations inside AI conversations.
Manage AdGuard Home through AI assistants
Read-only Azure DevOps for MCP clients using only your existing browser session — no PAT, no Azure CLI. Browse work items, pull requests, comments, attachments and Artifacts feeds across every project, repo and feed you can access.
MCP server for Adobe Experience Manager Assets integration development
Servidor MCP para el tiempo oficial de España (API pública OpenData de AEMET). Predicción, observación y avisos como herramientas MCP tipadas.
A standalone MCP stdio bridge for Affinity by Canva's local MCP SSE server.