opencode

Open source coding agent for the terminal

$ anc audit opencode --json

agent TypeScript anomalyco/opencode
MUST 19 / 28SHOULD 13 / 2113 warningsaudited 2026-06-01 · anc 0.5.0
76pass rate
3/8principles met

Eight principles, scored

Behavioral and source checks. Every non-pass row carries a copy-paste remediation prompt.

  1. P1
    Non-Interactive by Default

    no non-interactive flag found in --help; expected one of: --no-interactive, --non-interactive, -p, --print, --no-input, --batch, --headless, -y, --yes, --assume-yes · 16 flag(s) found in --help but no `[env: NAME]` bindings advertised

    Remediation · P1
    Make opencode satisfy P1 (Non-Interactive by Default) from the agent-native CLI standard. Address:
    - Non-interactive gate flag advertised in --help (no non-interactive flag found in --help; expected one of: --no-interactive, --non-interactive, -p, --print, --no-input, --batch, --headless, -y, --yes, --assume-yes)
    - Flags advertise env-var bindings in --help (16 flag(s) found in --help but no `[env: NAME]` bindings advertised)
    Requirements: https://anc.dev/p1
    warn
  2. P2
    Structured, Parseable Output

    no --json or --jsonl short alias found. Agents and pipelines benefit from short forms alongside the canonical `--output` enum. · no `--raw` flag advertised. MAY-tier — useful for pipelines that want to strip formatting before piping to other tools.

    Remediation · P2
    Make opencode satisfy P2 (Structured, Parseable Output) from the agent-native CLI standard. Address:
    - --json / --jsonl short aliases for --output (no --json or --jsonl short alias found. Agents and pipelines benefit from short forms alongside the canonical `--output` enum.)
    - `--raw` flag for pipe-safe unformatted output (no `--raw` flag advertised. MAY-tier — useful for pipelines that want to strip formatting before piping to other tools.)
    - Bad invocation exits with structured usage-error code (2) (bad invocation exited with code 1. The 0/1/2/77/78 convention reserves code 2 for usage errors; using a different non-zero code (often 1) blurs the distinction between usage errors and general failure.)
    Requirements: https://anc.dev/p2
    warn
  3. P3
    Progressive Help Discovery

    --help output exists but no examples section detected · no `examples` subcommand or `--examples` flag found. MAY-tier — a curated usage block keeps agents from hunting through long help text.

    Remediation · P3
    Make opencode satisfy P3 (Progressive Help Discovery) from the agent-native CLI standard. Address:
    - Help flag produces useful output (--help output exists but no examples section detected)
    - `examples` subcommand or `--examples` flag for curated usage patterns (no `examples` subcommand or `--examples` flag found. MAY-tier — a curated usage block keeps agents from hunting through long help text.)
    - Help text pairs human and `--output json` example invocations (no paired text + `--output json` example found within 5 lines in top-level or any subcommand `--help`. Pairing keeps agents from reverse-engineering the JSON invocation from the text one.)
    Requirements: https://anc.dev/p3
    warn
  4. P4pass
  5. P5pass
  6. P6
    Composable, Predictable Command Structure

    pager referenced in --help but no --no-pager escape hatch advertised · 0/22 subcommand(s) follow standard verb names. Non-standard: opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode. MAY-tier — community-standard verbs (get/list/create/update/delete) help agents predict subcommand behavior across CLIs.

    Remediation · P6
    Make opencode satisfy P6 (Composable, Predictable Command Structure) from the agent-native CLI standard. Address:
    - Pager-using CLI ships --no-pager escape hatch (pager referenced in --help but no --no-pager escape hatch advertised)
    - Subcommand verbs follow community-standard names (0/22 subcommand(s) follow standard verb names. Non-standard: opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode. MAY-tier — community-standard verbs (get/list/create/update/delete) help agents predict subcommand behavior across CLIs.)
    - `--color` flag for explicit color control (no `--color` flag advertised. MAY-tier — `auto|always|never` lets agents and pipelines override the TTY-based default.)
    Requirements: https://anc.dev/p6
    warn
  7. P7
    Bounded, High-Signal Responses

    no --quiet/-q flag detected in --help output · no TTY-aware language found in `--help`. MAY-tier — automatic verbosity reduction when stdout is piped or redirected lets agents skip the explicit `--quiet` flag. Behavioral probes cannot simulate a real TTY without a pty crate, so this audit relies on documented intent.

    Remediation · P7
    Make opencode satisfy P7 (Bounded, High-Signal Responses) from the agent-native CLI standard. Address:
    - Quiet mode available (no --quiet/-q flag detected in --help output)
    - Help text advertises TTY-aware verbosity behavior (no TTY-aware language found in `--help`. MAY-tier — automatic verbosity reduction when stdout is piped or redirected lets agents skip the explicit `--quiet` flag. Behavioral probes cannot simulate a real TTY without a pty crate, so this audit relies on documented intent.)
    Requirements: https://anc.dev/p7
    warn
  8. P8pass

All Audits

P1: Non-Interactive by Default

PASSNon-interactive by default
WARNNon-interactive gate flag advertised in --helpno non-interactive flag found in --help; expected one of: --no-interactive, --non-interactive, -p, --print, --no-input, --batch, --headless, -y, --yes, --assume-yes
WARNFlags advertise env-var bindings in --help16 flag(s) found in --help but no `[env: NAME]` bindings advertised
PASSSecret-bearing flags expose stdin or *-file companion
PASS`--help` advertises default values for flags
PASSRich-TUI affordance for TTY contexts

P2: Structured, Parseable Output

OPT-OUTStructured output supportno --output/--format flag detected in any subcommand — tool does not ship structured output.
N/AStructured-output CLI exposes its schema at runtimeantecedent `p2-json-output` is opt_out: no --output/--format flag detected in any subcommand — tool does not ship structured output.
WARN--json / --jsonl short aliases for --outputno --json or --jsonl short alias found. Agents and pipelines benefit from short forms alongside the canonical `--output` enum.
WARN`--raw` flag for pipe-safe unformatted outputno `--raw` flag advertised. MAY-tier — useful for pipelines that want to strip formatting before piping to other tools.
SKIP`--output` advertises additional formats beyond text/jsonno `--output` or `--format` flag advertised; vacuous skip for MAY-tier extra formats.
WARNBad invocation exits with structured usage-error code (2)bad invocation exited with code 1. The 0/1/2/77/78 convention reserves code 2 for usage errors; using a different non-zero code (often 1) blurs the distinction between usage errors and general failure.
SKIPErrors emit JSON envelope with `error`/`kind`/`message` under `--output json`binary does not advertise `--output json` in --help; MUST applies only to CLIs that opt into the JSON contract.
SKIPJSON success and error envelopes share their non-payload key setbinary does not advertise `--output json` in --help; envelope-consistency only applies to CLIs that opt into the JSON contract.

P3: Progressive Help Discovery

WARNHelp flag produces useful output--help output exists but no examples section detected
PASSVersion flag works (`--version` plus short alias)
PASSVersion flag works (`--version` plus short alias)
WARN`examples` subcommand or `--examples` flag for curated usage patternsno `examples` subcommand or `--examples` flag found. MAY-tier — a curated usage block keeps agents from hunting through long help text.
SKIPShort `-h` summary differs from `--help` long formone or both of `-h` / `--help` produced empty output
PASSEach subcommand's `--help` ships at least one invocation example
WARNHelp text pairs human and `--output json` example invocationsno paired text + `--output json` example found within 5 lines in top-level or any subcommand `--help`. Pairing keeps agents from reverse-engineering the JSON invocation from the text one.

P4: Fail-Fast, Actionable Errors

PASSRejects invalid arguments
PASSError messages include a hint or remediation phrase
SKIP`--output json` produces JSON-formatted errorsbinary does not advertise `--output json` in --help; SHOULD applies only to CLIs that opt into the JSON contract.

P5: Safe Retries & Mutation Boundaries

SKIPDestructive subcommands require `--force` or `--yes`no destructive subcommands detected; MUST applies conditionally to CLIs with destructive operations.
SKIPRead and write surfaces are both visible in subcommand listno recognizable read or write subcommand verbs; the read/write distinction is unobservable from the help surface alone.

P6: Composable, Predictable Command Structure

PASSHandles SIGPIPE gracefully
WARNPager-using CLI ships --no-pager escape hatchpager referenced in --help but no --no-pager escape hatch advertised
PASSRespects NO_COLOR
WARNSubcommand verbs follow community-standard names0/22 subcommand(s) follow standard verb names. Non-standard: opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode, opencode. MAY-tier — community-standard verbs (get/list/create/update/delete) help agents predict subcommand behavior across CLIs.
WARN`--color` flag for explicit color controlno `--color` flag advertised. MAY-tier — `auto|always|never` lets agents and pipelines override the TTY-based default.
SKIPInput-accepting commands read from stdin when no file is givenno input-accepting subcommand detected (process/parse/convert/transform/analyze/validate/format/lint/audit); vacuous skip for the conditional SHOULD.
PASSSubcommand naming follows a consistent verb/noun convention
PASSOperations are subcommands, not verb-shaped flags

P7: Bounded, High-Signal Responses

WARNQuiet mode availableno --quiet/-q flag detected in --help output
PASS`--verbose` flag for diagnostic escalation
SKIP`--limit` / `--max-results` flag for list operationsno list-style subcommand detected (list/ls/search/query/find/show/get); vacuous skip for the list-only SHOULD.
SKIPCursor-based pagination flags for list traversalno list-style subcommand detected; vacuous skip for the list-only MAY.
SKIP`--timeout` flag for long-running operationsno long-running subcommand detected (serve/daemon/watch/tail/monitor/follow/run/start/stream); vacuous skip for the conditional SHOULD.
WARNHelp text advertises TTY-aware verbosity behaviorno TTY-aware language found in `--help`. MAY-tier — automatic verbosity reduction when stdout is piped or redirected lets agents skip the explicit `--quiet` flag. Behavioral probes cannot simulate a real TTY without a pty crate, so this audit relies on documented intent.

P8: Discoverable Through Agent Skill Bundles

PASSSkill bundle has install path (`tool skill install [<host>]`)
PASS`skill install --all` for multi-runtime install
PASS`skill update` / `skill upgrade` for bundle refresh

Details

Version scored
1.15.13
Audit date
2026-06-01 17:37:10 UTC
Duration
8.8s
Platform
linux/x86_64
Mode
command
Anc build
0.5.0
Install
brew install anomalyco/tap/opencode

Embed the badge

This score (76%) clears the badge floor (70%). Copy this into your README:

[![agent-native](https://anc.dev/badge/opencode.svg)](https://anc.dev/score/opencode)

Preview: agent-native badge for opencode

Reproduce this scorecard for opencode locally and inspect the failing audits:

anc audit --command opencode --output json

Install anc first if you don't have it. Add --output json to get the same JSON shape committed under scorecards/.