{"_id":"@ax0l0tl/agent-governance-opencode","_rev":"9-9ca479908ab39c54b76c56a6b477bdb6","name":"@ax0l0tl/agent-governance-opencode","dist-tags":{"latest":"4.0.7"},"versions":{"4.0.0":{"name":"@ax0l0tl/agent-governance-opencode","version":"4.0.0","keywords":["opencode","agent","governance","security","policy","mcp"],"author":{"name":"Microsoft Corporation","email":"agentgovtoolkit@microsoft.com"},"license":"MIT","_id":"@ax0l0tl/agent-governance-opencode@4.0.0","maintainers":[{"name":"ax0l0tl","email":"wiedemann@bluehands.de"}],"homepage":"https://github.com/microsoft/agent-governance-toolkit/tree/main/agent-governance-opencode","bugs":{"url":"https://github.com/microsoft/agent-governance-toolkit/issues"},"dist":{"shasum":"0a55106c476d5490f7bb4ee2bc02b7c3405dfcca","tarball":"https://registry.npmjs.org/@ax0l0tl/agent-governance-opencode/-/agent-governance-opencode-4.0.0.tgz","fileCount":10,"integrity":"sha512-nhR5eXB95KkD0DY14/0nfh/T+Bg3gIdPXqQMwfKUy3Ghf56laAUxKzSjms7BJtfFo44vbKqRS1DRimANitWC9Q==","signatures":[{"sig":"MEQCIByjWyGKx07FVziVnN8MSGb7mhSjKISddNekpPSdkDfTAiAQzAMZ/9BGW+Eu1J2ny+YUF8GHPYYMY0nMLjP3dRyPFg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":71451},"main":"src/index.mjs","type":"module","engines":{"node":">=22.0.0"},"exports":{".":"./src/index.mjs","./policy":"./lib/policy.mjs","./mcp-server":"./server/agt-mcp.mjs"},"gitHead":"730ffbb060c44362485b786c63aa08439c49d7e1","scripts":{"test":"node --test ./test/*.test.mjs","build":"npm run check","check":"node --check ./src/index.mjs && node --check ./lib/audit.mjs && node --check ./lib/poisoning.mjs && node --check ./lib/policy.mjs && node --check ./server/agt-mcp.mjs && node --test ./test/*.test.mjs"},"_npmUser":{"name":"ax0l0tl","email":"wiedemann@bluehands.de"},"repository":{"url":"git+https://github.com/microsoft/agent-governance-toolkit.git","type":"git","directory":"agent-governance-opencode"},"_npmVersion":"11.13.0","description":"Public Preview — OpenCode CLI governance plugin for Agent Governance Toolkit developer protection policies (fork with OpenCode contract fixes)","directories":{},"_nodeVersion":"24.16.0","dependencies":{"@microsoft/agent-governance-sdk":"3.7.0"},"_hasShrinkwrap":false,"devDependencies":{"@opencode-ai/plugin":"^1.17.1"},"_npmOperationalInternal":{"tmp":"tmp/agent-governance-opencode_4.0.0_1781106373619_0.5970160982513149","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"4.0.1":{"name":"@ax0l0tl/agent-governance-opencode","version":"4.0.1","keywords":["opencode","agent","governance","security","policy","mcp"],"author":{"name":"Microsoft Corporation","email":"agentgovtoolkit@microsoft.com"},"license":"MIT","_id":"@ax0l0tl/agent-governance-opencode@4.0.1","maintainers":[{"name":"ax0l0tl","email":"wiedemann@bluehands.de"}],"homepage":"https://github.com/microsoft/agent-governance-toolkit/tree/main/agent-governance-opencode","bugs":{"url":"https://github.com/microsoft/agent-governance-toolkit/issues"},"dist":{"shasum":"716e530e643a6d500e08cdc3d619afec1a4c2b4d","tarball":"https://registry.npmjs.org/@ax0l0tl/agent-governance-opencode/-/agent-governance-opencode-4.0.1.tgz","fileCount":10,"integrity":"sha512-ZnpyWkrj+lPF1tR9vkjlInq/Glj+iS876UKHqQ3YhuadXQxgK69/1bS/5qHjpaXD+V14WJyBuIDBwUfuN6juxQ==","signatures":[{"sig":"MEYCIQD0wQPPj6swkoi3zeAzhQH8aX43tUydWw3xTPTFmRnfvAIhANrQf52G049Hg4Lyh2vYlt0nad9izxGrZ9Ej/goANQrv","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":71473},"main":"src/index.mjs","type":"module","engines":{"node":">=22.0.0"},"exports":{".":"./src/index.mjs","./policy":"./lib/policy.mjs","./mcp-server":"./server/agt-mcp.mjs"},"gitHead":"730ffbb060c44362485b786c63aa08439c49d7e1","scripts":{"test":"node --test ./test/*.test.mjs","build":"npm run check","check":"node --check ./src/index.mjs && node --check ./lib/audit.mjs && node --check ./lib/poisoning.mjs && node --check ./lib/policy.mjs && node --check ./server/agt-mcp.mjs && node --test ./test/*.test.mjs"},"_npmUser":{"name":"ax0l0tl","email":"wiedemann@bluehands.de"},"repository":{"url":"git+https://github.com/microsoft/agent-governance-toolkit.git","type":"git","directory":"agent-governance-opencode"},"_npmVersion":"11.13.0","description":"TEST ONLY — Do not install. Temporary fork of @microsoft/agent-governance-opencode published to verify OpenCode plugin contract fixes before upstreaming to Microsoft.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"@opencode-ai/plugin":"^1.17.1","@microsoft/agent-governance-sdk":"3.7.0"},"_hasShrinkwrap":false,"devDependencies":{},"_npmOperationalInternal":{"tmp":"tmp/agent-governance-opencode_4.0.1_1781107452909_0.25085159512949406","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"4.0.2":{"name":"@ax0l0tl/agent-governance-opencode","version":"4.0.2","keywords":["opencode","agent","governance","security","policy","mcp"],"author":{"name":"Microsoft Corporation","email":"agentgovtoolkit@microsoft.com"},"license":"MIT","_id":"@ax0l0tl/agent-governance-opencode@4.0.2","maintainers":[{"name":"ax0l0tl","email":"wiedemann@bluehands.de"}],"homepage":"https://github.com/microsoft/agent-governance-toolkit/tree/main/agent-governance-opencode","bugs":{"url":"https://github.com/microsoft/agent-governance-toolkit/issues"},"dist":{"shasum":"ee31d30977eb04fc3c9543b9d88aa25bcc2be363","tarball":"https://registry.npmjs.org/@ax0l0tl/agent-governance-opencode/-/agent-governance-opencode-4.0.2.tgz","fileCount":10,"integrity":"sha512-4l1UYb2yPlh0c6AsKCDS3NNzTkoTCMV17h69/5GZ83G5XW1ce7wxchqs2WAC00Sk44nb0FxwmEgahaIMB2Jedg==","signatures":[{"sig":"MEUCIH1WI78xXcXQZOrohX/MNcEM3SESRyAPOBrHde3PVwLMAiEAwrMd9JIY9maDqpxCa1KUYC9hyTENxbA8vebsc7QA8Pk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":71262},"main":"src/index.mjs","type":"module","engines":{"node":">=22.0.0"},"exports":{".":"./src/index.mjs","./policy":"./lib/policy.mjs","./mcp-server":"./server/agt-mcp.mjs"},"gitHead":"730ffbb060c44362485b786c63aa08439c49d7e1","scripts":{"test":"node --test ./test/*.test.mjs","build":"npm run check","check":"node --check ./src/index.mjs && node --check ./lib/audit.mjs && node --check ./lib/poisoning.mjs && node --check ./lib/policy.mjs && node --check ./server/agt-mcp.mjs && node --test ./test/*.test.mjs"},"_npmUser":{"name":"ax0l0tl","email":"wiedemann@bluehands.de"},"repository":{"url":"git+https://github.com/microsoft/agent-governance-toolkit.git","type":"git","directory":"agent-governance-opencode"},"_npmVersion":"11.13.0","description":"Public Preview — OpenCode CLI governance plugin for Agent Governance Toolkit developer protection policies","directories":{},"_nodeVersion":"24.16.0","dependencies":{"@opencode-ai/plugin":"1.17.1","@microsoft/agent-governance-sdk":"3.7.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agent-governance-opencode_4.0.2_1781161072911_0.23660676121269053","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"4.0.3":{"name":"@ax0l0tl/agent-governance-opencode","version":"4.0.3","keywords":["opencode","agent","governance","security","policy","mcp"],"author":{"name":"Microsoft Corporation","email":"agentgovtoolkit@microsoft.com"},"license":"MIT","_id":"@ax0l0tl/agent-governance-opencode@4.0.3","maintainers":[{"name":"ax0l0tl","email":"wiedemann@bluehands.de"}],"homepage":"https://github.com/microsoft/agent-governance-toolkit/tree/main/agent-governance-opencode","bugs":{"url":"https://github.com/microsoft/agent-governance-toolkit/issues"},"dist":{"shasum":"878e3ccd3c6ddfbbc103ec5f003e4ba604870ae3","tarball":"https://registry.npmjs.org/@ax0l0tl/agent-governance-opencode/-/agent-governance-opencode-4.0.3.tgz","fileCount":10,"integrity":"sha512-GY9EDRmohB++Ywb3VRfU0KVF4aBNNbyqsxUUbRjunGj/iP4sfswVXGY37Gcn20Gs+z6jpgntFhPiEUldEJx0Xw==","signatures":[{"sig":"MEQCIA/tHZACUMGp9XNxCnqd3AgduBaNTSsE9D+dL3tzJX0eAiBtR0aRgxOlPn8igA8OsMfw5XvoLt7RL7rGFhtnV4nOOw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":71330},"main":"src/index.mjs","type":"module","engines":{"node":">=22.0.0"},"exports":{".":"./src/index.mjs","./policy":"./lib/policy.mjs","./mcp-server":"./server/agt-mcp.mjs"},"gitHead":"730ffbb060c44362485b786c63aa08439c49d7e1","scripts":{"test":"node --test ./test/*.test.mjs","build":"npm run check","check":"node --check ./src/index.mjs && node --check ./lib/audit.mjs && node --check ./lib/poisoning.mjs && node --check ./lib/policy.mjs && node --check ./server/agt-mcp.mjs && node --test ./test/*.test.mjs"},"_npmUser":{"name":"ax0l0tl","email":"wiedemann@bluehands.de"},"repository":{"url":"git+https://github.com/microsoft/agent-governance-toolkit.git","type":"git","directory":"agent-governance-opencode"},"_npmVersion":"11.13.0","description":"Public Preview — OpenCode CLI governance plugin for Agent Governance Toolkit developer protection policies","directories":{},"_nodeVersion":"24.16.0","dependencies":{"@opencode-ai/plugin":"1.17.1","@microsoft/agent-governance-sdk":"3.7.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agent-governance-opencode_4.0.3_1781175616884_0.5878964915987128","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"4.0.4":{"name":"@ax0l0tl/agent-governance-opencode","version":"4.0.4","keywords":["opencode","agent","governance","security","policy","mcp"],"author":{"name":"Microsoft Corporation","email":"agentgovtoolkit@microsoft.com"},"license":"MIT","_id":"@ax0l0tl/agent-governance-opencode@4.0.4","maintainers":[{"name":"ax0l0tl","email":"wiedemann@bluehands.de"}],"homepage":"https://github.com/microsoft/agent-governance-toolkit/tree/main/agent-governance-opencode","bugs":{"url":"https://github.com/microsoft/agent-governance-toolkit/issues"},"dist":{"shasum":"0508c1403e6aeb737be0b3fdf918a7222994fd9d","tarball":"https://registry.npmjs.org/@ax0l0tl/agent-governance-opencode/-/agent-governance-opencode-4.0.4.tgz","fileCount":10,"integrity":"sha512-2Ju5hW+FwqCkqUN/OYPhMMSVT4olsiv4E3g9Ui9gS4X2/HLckYniyQy9uFoHGJ0ON46e5dsavxuO6ANBGQ9Q+Q==","signatures":[{"sig":"MEUCIQCu+3ptTj2kLl8+yHL1nLEB1oBiNcdFNnaCPhxZJ9z1jgIgAuLLhL4UGkNpD2ucG6ex1gErKzJvjHoMtNoB0GBiTK8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":70605},"main":"src/index.mjs","type":"module","engines":{"node":">=22.0.0"},"exports":{".":"./src/index.mjs","./policy":"./lib/policy.mjs","./mcp-server":"./server/agt-mcp.mjs"},"gitHead":"730ffbb060c44362485b786c63aa08439c49d7e1","scripts":{"test":"node --test ./test/*.test.mjs","build":"npm run check","check":"node --check ./src/index.mjs && node --check ./lib/audit.mjs && node --check ./lib/poisoning.mjs && node --check ./lib/policy.mjs && node --check ./server/agt-mcp.mjs && node --test ./test/*.test.mjs"},"_npmUser":{"name":"ax0l0tl","email":"wiedemann@bluehands.de"},"repository":{"url":"git+https://github.com/microsoft/agent-governance-toolkit.git","type":"git","directory":"agent-governance-opencode"},"_npmVersion":"11.13.0","description":"Public Preview — OpenCode CLI governance plugin for Agent Governance Toolkit developer protection policies","directories":{},"_nodeVersion":"24.16.0","dependencies":{"@opencode-ai/plugin":"1.17.1","@microsoft/agent-governance-sdk":"3.7.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agent-governance-opencode_4.0.4_1781253690225_0.034006684373967255","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"4.0.5":{"name":"@ax0l0tl/agent-governance-opencode","version":"4.0.5","keywords":["opencode","agent","governance","security","policy","mcp"],"author":{"name":"Microsoft Corporation","email":"agentgovtoolkit@microsoft.com"},"license":"MIT","_id":"@ax0l0tl/agent-governance-opencode@4.0.5","maintainers":[{"name":"ax0l0tl","email":"wiedemann@bluehands.de"}],"homepage":"https://github.com/microsoft/agent-governance-toolkit/tree/main/agent-governance-opencode","bugs":{"url":"https://github.com/microsoft/agent-governance-toolkit/issues"},"dist":{"shasum":"64fd2a80543057de3e88ef8e72b8863ed1864e7d","tarball":"https://registry.npmjs.org/@ax0l0tl/agent-governance-opencode/-/agent-governance-opencode-4.0.5.tgz","fileCount":10,"integrity":"sha512-gbnns7dk+l1ZS8c8m52nxidA+bVYCETO58ecKwPtL77QhTp1KqJae27vb3TOHk9IvpiQjv9EoGR+fxBMWbrTqQ==","signatures":[{"sig":"MEUCIHLfBF8jHu615lVFq+uljrNViD9CsdpXBC7un64Oxj+XAiEA6G0jveJoPE+bIGgkwDBRaa7sXxLJB+9ebYBOlOF5Kus=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":70009},"main":"src/index.mjs","type":"module","engines":{"node":">=22.0.0"},"exports":{".":"./src/index.mjs","./policy":"./lib/policy.mjs","./mcp-server":"./server/agt-mcp.mjs"},"gitHead":"53597d47995ecf7445a1b28672df77ce1fd755fc","scripts":{"test":"node --test ./test/*.test.mjs","build":"npm run check","check":"node --check ./src/index.mjs && node --check ./lib/audit.mjs && node --check ./lib/poisoning.mjs && node --check ./lib/policy.mjs && node --check ./server/agt-mcp.mjs && node --test ./test/*.test.mjs"},"_npmUser":{"name":"ax0l0tl","email":"wiedemann@bluehands.de"},"repository":{"url":"git+https://github.com/microsoft/agent-governance-toolkit.git","type":"git","directory":"agent-governance-opencode"},"_npmVersion":"11.13.0","description":"Public Preview — OpenCode CLI governance plugin for Agent Governance Toolkit developer protection policies","directories":{},"_nodeVersion":"24.16.0","dependencies":{"@microsoft/agent-governance-sdk":"3.7.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agent-governance-opencode_4.0.5_1781256698465_0.46406669171276826","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"4.0.6":{"name":"@ax0l0tl/agent-governance-opencode","version":"4.0.6","keywords":["opencode","agent","governance","security","policy","mcp"],"author":{"name":"Microsoft Corporation","email":"agentgovtoolkit@microsoft.com"},"license":"MIT","_id":"@ax0l0tl/agent-governance-opencode@4.0.6","maintainers":[{"name":"ax0l0tl","email":"wiedemann@bluehands.de"}],"homepage":"https://github.com/microsoft/agent-governance-toolkit/tree/main/agent-governance-opencode","bugs":{"url":"https://github.com/microsoft/agent-governance-toolkit/issues"},"dist":{"shasum":"416bac218b314fef125a7b4d8ddb03e6c5d71a0b","tarball":"https://registry.npmjs.org/@ax0l0tl/agent-governance-opencode/-/agent-governance-opencode-4.0.6.tgz","fileCount":10,"integrity":"sha512-IIPIjIM6aetcSw5QznwIsYMNGZEJgi6OPAunZMDtLFDv+0gnS3ziGpjYrTpkD9ftzx1ILwGUHazQtNgtClY1tQ==","signatures":[{"sig":"MEYCIQC2b4x6HTsLrZsNJPVOv4f0JAGBQXr393hCuaR1D49xiQIhAIRFtaAXlvx8hc1YxskLLt86+d4ixjow+sSA7Ysr+eVB","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":70515},"main":"src/index.mjs","type":"module","engines":{"node":">=22.0.0"},"exports":{".":"./src/index.mjs","./policy":"./lib/policy.mjs","./mcp-server":"./server/agt-mcp.mjs"},"gitHead":"ac3514f94d0b28083619a7037fb1bbe2edfc7e18","scripts":{"test":"node --test ./test/*.test.mjs","build":"npm run check","check":"node --check ./src/index.mjs && node --check ./lib/audit.mjs && node --check ./lib/poisoning.mjs && node --check ./lib/policy.mjs && node --check ./server/agt-mcp.mjs && node --test ./test/*.test.mjs"},"_npmUser":{"name":"ax0l0tl","email":"wiedemann@bluehands.de"},"repository":{"url":"git+https://github.com/microsoft/agent-governance-toolkit.git","type":"git","directory":"agent-governance-opencode"},"_npmVersion":"11.13.0","description":"Public Preview — OpenCode CLI governance plugin for Agent Governance Toolkit developer protection policies","directories":{},"_nodeVersion":"24.16.0","dependencies":{"@microsoft/agent-governance-sdk":"3.7.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agent-governance-opencode_4.0.6_1781266897646_0.4914858915673035","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"4.0.7":{"name":"@ax0l0tl/agent-governance-opencode","version":"4.0.7","keywords":["opencode","agent","governance","security","policy","mcp"],"author":{"name":"Microsoft Corporation","email":"agentgovtoolkit@microsoft.com"},"license":"MIT","_id":"@ax0l0tl/agent-governance-opencode@4.0.7","maintainers":[{"name":"ax0l0tl","email":"wiedemann@bluehands.de"}],"homepage":"https://github.com/microsoft/agent-governance-toolkit/tree/main/agent-governance-opencode","bugs":{"url":"https://github.com/microsoft/agent-governance-toolkit/issues"},"dist":{"shasum":"cc1a321e9ebc1a715b2a984f9519d8cbe83713b9","tarball":"https://registry.npmjs.org/@ax0l0tl/agent-governance-opencode/-/agent-governance-opencode-4.0.7.tgz","fileCount":10,"integrity":"sha512-rLfR14rlUoInA1Dtn1G72+TrjcK3P+/fPlqC/fxCbP63rr5E2pbBJtomsy/V/FAco25gkQhUfT/+cYDy21iBzA==","signatures":[{"sig":"MEUCIFtVPg5eOnxp44fi23CLHyvjyve6oKzB5B5gaig495QXAiEAqVKfYVSthRC4uSJoMC20p+JRotXv0+YLQvqpNCbX7Bw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":70533},"main":"src/index.mjs","type":"module","engines":{"node":">=22.0.0"},"exports":{".":"./src/index.mjs","./policy":"./lib/policy.mjs","./mcp-server":"./server/agt-mcp.mjs"},"gitHead":"ac3514f94d0b28083619a7037fb1bbe2edfc7e18","scripts":{"test":"node --test ./test/*.test.mjs","build":"npm run check","check":"node --check ./src/index.mjs && node --check ./lib/audit.mjs && node --check ./lib/poisoning.mjs && node --check ./lib/policy.mjs && node --check ./server/agt-mcp.mjs && node --test ./test/*.test.mjs"},"_npmUser":{"name":"ax0l0tl","email":"wiedemann@bluehands.de"},"repository":{"url":"git+https://github.com/microsoft/agent-governance-toolkit.git","type":"git","directory":"agent-governance-opencode"},"_npmVersion":"11.13.0","description":"Public Preview — OpenCode CLI governance plugin for Agent Governance Toolkit developer protection policies","directories":{},"_nodeVersion":"24.16.0","dependencies":{"@microsoft/agent-governance-sdk":"3.7.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agent-governance-opencode_4.0.7_1781267292917_0.7616120186218356","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."}},"time":{"created":"2026-06-10T15:46:13.241Z","modified":"2026-06-15T06:00:03.886Z","4.0.0":"2026-06-10T15:46:13.750Z","4.0.1":"2026-06-10T16:04:13.052Z","4.0.2":"2026-06-11T06:57:53.094Z","4.0.3":"2026-06-11T11:00:17.065Z","4.0.4":"2026-06-12T08:41:30.352Z","4.0.5":"2026-06-12T09:31:38.601Z","4.0.6":"2026-06-12T12:21:37.786Z","4.0.7":"2026-06-12T12:28:13.080Z"},"bugs":{"url":"https://github.com/microsoft/agent-governance-toolkit/issues"},"author":{"name":"Microsoft Corporation","email":"agentgovtoolkit@microsoft.com"},"license":"MIT","homepage":"https://github.com/microsoft/agent-governance-toolkit/tree/main/agent-governance-opencode","keywords":["opencode","agent","governance","security","policy","mcp"],"repository":{"url":"git+https://github.com/microsoft/agent-governance-toolkit.git","type":"git","directory":"agent-governance-opencode"},"description":"Public Preview — OpenCode CLI governance plugin for Agent Governance Toolkit developer protection policies","maintainers":[{"name":"ax0l0tl","email":"wiedemann@bluehands.de"}],"readme":"# AGT OpenCode Plugin\n\nThis package is the **production package surface** for Agent Governance Toolkit\non [OpenCode](https://github.com/anomalyco/opencode).\n\nIt ships an OpenCode plugin that uses:\n\n- OpenCode's in-process plugin hooks for deterministic session, prompt, tool,\n  and output governance\n- a bundled stdio MCP server (`server/agt-mcp.mjs`) for operator-facing AGT\n  inspection tools\n- the AGT TypeScript SDK for policy evaluation, prompt defense, and MCP threat\n  scanning\n\n> Public Preview — APIs and policy schema may change.\n\n## What this package is\n\n- a first-party OpenCode plugin package\n- a parity layer for the existing Antigravity and Claude Code governance\n  packages, adapted to OpenCode's richer in-process hook contract\n- a publishable npm package (`@microsoft/agent-governance-opencode`) that can\n  also be loaded locally from a workspace `.opencode/plugins/` directory\n\n## What this package is not\n\n- a Copilot-style extension\n- a universal governance layer for every IDE surface\n- a guarantee of full Copilot CLI feature parity\n\n## Why OpenCode benefits from in-process governance\n\nUnlike Claude Code (subprocess hooks) and Antigravity (subprocess hooks),\nOpenCode loads plugins **in-process** as async TypeScript/JavaScript functions.\nThat means this package can:\n\n- enforce policy on `tool.execute.before` without an extra subprocess round trip\n- **redact** secrets from `tool.execute.after` output before the model sees it\n  (a parity win over Claude Code, which cannot rewrite tool output)\n- expose custom tools like `agt_policy_status` directly to the model without\n  needing a separate MCP server\n\nThe stdio MCP server is still shipped for operators who want to invoke\ngovernance tools from external workflows.\n\n## Current scope\n\nThis initial package enforces:\n\n- `session.start`           — injects AGT governance context into the session\n- `event` (chat-style)      — scans submitted prompts; throws to block\n- `tool.execute.before`     — allow / review / deny tool calls\n- `tool.execute.after`      — scans tool output and redacts known secret\n                              patterns (AWS, GitHub PAT, OpenAI, JWT, PEM\n                              private keys, Azure storage keys)\n- `tool.execute.error`      — records audit entry for failed tool calls\n\nIt also exposes two custom tools (in-process **and** via the stdio MCP server):\n\n- `agt_policy_status` — return the active AGT policy snapshot\n- `agt_policy_check_text` — inspect arbitrary text for prompt-injection and\n  context-poisoning findings\n\n## Local development\n\nRun these commands from the package directory:\n\n```powershell\ncd agent-governance-opencode\nnpm install\nnpm run check\n```\n\n## Loading the plugin in OpenCode\n\nOpenCode loads plugins from:\n\n1. `opencode.json` `plugin` entries (npm specifiers)\n2. `~/.config/opencode/plugins/*.{ts,js,mjs}` (user-global)\n3. `.opencode/plugins/*.{ts,js,mjs}` (workspace-local)\n\n### Option A — workspace `opencode.json`\n\n```json\n{\n  \"$schema\": \"https://opencode.ai/config.json\",\n  \"plugin\": [\"@microsoft/agent-governance-opencode\"]\n}\n```\n\n### Option B — workspace plugin file (no install required)\n\nCreate `.opencode/plugins/agt.mjs`:\n\n```js\nexport { default } from \"../../agent-governance-opencode/src/index.mjs\";\n```\n\n### Option C — install the bundled MCP server\n\nIn `opencode.json`:\n\n```json\n{\n  \"$schema\": \"https://opencode.ai/config.json\",\n  \"mcp\": {\n    \"agt-governance\": {\n      \"type\": \"local\",\n      \"command\": [\n        \"node\",\n        \"./node_modules/@microsoft/agent-governance-opencode/server/agt-mcp.mjs\"\n      ]\n    }\n  }\n}\n```\n\n## Configuration\n\nThe plugin loads policy from (in order):\n\n1. `AGT_OPENCODE_POLICY_PATH` environment variable\n2. `./.agt/policy.json` in the working directory\n3. `~/.config/opencode/agt/policy.json`\n4. The bundled `config/default-policy.json` (enforce mode, fail-closed)\n\nAudit log path defaults to `~/.config/opencode/agt/audit.json` and can be\noverridden via `AGT_OPENCODE_AUDIT_PATH`.\n\n## Important parity notes\n\n- OpenCode's in-process plugin contract does not currently expose a server-side\n  \"ask the user\" decision from inside `tool.execute.before`. When AGT decides\n  `review`, this plugin marks the args with `__agt_review_reason` and lets\n  OpenCode's normal permission flow run. Operators who want hard-deny behaviour\n  on review should set `toolPolicies.defaultEffect: \"deny\"` in their policy.\n- Output redaction is conservative: only well-known credential patterns are\n  redacted. The audit entry records that a redaction occurred but never the\n  redacted value.\n- AGT fails **closed** by default. If the policy file is corrupt or evaluation\n  throws, requests are denied. Set `denyOnPolicyError: false` in policy to opt\n  into advisory mode.\n","readmeFilename":"README.md"}