This kit configures coding agents and an optional Open Design workbench. Treat both as powerful developer tools.
- Use Open Design on localhost, a trusted LAN, VPN, Tailscale, WireGuard, or behind an authenticated reverse proxy.
- Do not expose Open Design directly to the public Internet without authentication and network controls.
- Keep OpenCode auth files, provider credentials, sessions, logs, and
.envfiles out of git.
The canonical threat model inventories protected assets, trust boundaries, agent capabilities, abuse cases, controls, evidence, and residual risks. OpenCode permissions are policy controls, not an operating-system sandbox.
Open an issue with a minimal reproduction and no secrets. If the report contains sensitive information, contact the maintainer privately before publishing details.
Open Design can run agent CLIs that read and write files in the project workspace. Review prompts and target directories before running generation on private repositories.