<- Back
Comments (231)
- LaurensBERI feel that a better title for this article would be: "Some minor annoyances that, when fixed, would improve OpenCode"# Prompt Cache Misses> It globs your filesystem and re-reads AGENTS.md (injected in turn-0 system prompt) on every SSE turn. If you put a quick note in AGENTS.md to be read in the next session, you immediately force a full re-evaluation.> Personal favourite: it puts the current date in the turn-0 system prompt and re-evaluates every SSE turn. If you’re using OpenCode at midnight you get a full prompt cache miss.Okay, I can live with those.# Compaction> Want to sit for 10 minutes while the LLM server prefills the entire session with a new prompt prefixed to it, just to turn it into 5 bullet points that go at the top of a new session? Me neither. I get what they are going for, but I’ve not seen it work well. Neither compaction nor pruning is implemented well, and they interact poorly.Is this an OpenCode specific issue? I've seen the same with Codex and Claude# System Prompts> The default system prompt is opinionated (fine) but it has shit opinions (not fine). It took me a while to figure out why my agent kept saying “Use ABSOLUTELY NO COMMENTS” when dispatching subagents.Okay, so change it? Any LLM is opinionated, this system prompt enforces consistency across different models which seems reasonable.
- lucideerThis is a good summary of the dangers of using agentic clis, but the title & general focus on opencode is odd for two reasons:1. Most obviously & importantly this is a complaint without a straightforward suggested alternative. A sibling commenter mentions suggesting fixes to Opencode would be more productive: I don't necessarily agree since many of these issues are fundamental & would likely require an almost ground up rethink & rewrite, but the issue is that the article contains no constructive proposal at all: it may as well be titled "Stop Using LLMs"2. None of the major issues listed are unique to OpenCode. At least the full list within the "Alarming Things" seems in my mind to apply to Claude CLI, & I would guess most other agents from frontier model providers.Granted it's worthwhile documenting these issues as a plea for someone to build better tooling from the ground up, so the article is far from worthless - on the contrary I've bookmarked it & will be sharing & referencing it widely & often. But the title & focus is just very odd & seems misguided, especially when the contents of the piece is otherwise so good.
- chuckadams> If you don’t know what OpenCode is, imagine a boot stamping on a human face forever. The boot is made of TypeScript and the face is everything we have learned about security and systems software since the invention of the electronic computer in the 1940s.I nominate this for a Bulwer-Lytton prize in the Tortured Metaphor category.
- dboonThis prose feels extremely angry and ungenerous; abstractly, I agree with a lot of the points, but when I read this:> My conclusion is that OpenCode is clown-car turboslop with a security posture of “let me bend over for you daddy”. Everyone using it should stop using it.I do not want to keep reading. There are regular people who wrote this software. When did it become normal to talk about open source like this? How would you feel if someone wrote this about some software that you wrote? Reading this article made me feel extremely gross
- nirinorI use CC at a client because that's their stack. I use (a particular version of) OpenCode for my own work, because it is so much better. Reading this post makes me sad.Because everything matches and explains oddities I've seen and forgiven. So despite the hyperbole and the places where the authors' general sentiment are not mine, he's basically right, and I need to find a different harness.If the post resonates for you too and you've found something better, happy for recommendations. pi seems to get the most mentions here, anyone feel it (or another option) is specifically better on these architectural aspects?
- drdexebtjlRegardless of its flaws, OpenCode is the harness I’ve been the most productive with by far, and I’ve tried them all.These are all just some minor annoyances, some disagreements, and most importantly, a fundamental misunderstanding of the point of command filtering. It is not for security, it’s for steering.Anyway, it didn’t sound like the author tried building anything with OpenCode, and if they did, they said nothing about the most important part: how well did it do?
- volf_I switched from OpenCode to Pi and there was a big improvement in terms of tool calling performance and I find the experience less buggy.OpenCode has also seemed to have disappeared from https://openrouter.ai/apps/category/coding
- overgard> The default system prompt is opinionated (fine) but it has shit opinions (not fine). It took me a while to figure out why my agent kept saying “Use ABSOLUTELY NO COMMENTS” when dispatching subagents.GAH!!! So that's why its been deleting comments. That is annoying as hell.FWIW though, I think this applies to other harnesses also (not the annoying bits, but the security risks). I was thinking this morning about how much of a supply-chain vulnerability these tools are. Like, basically, they have a ton of data, they're updated practically daily, and given their vibe coded nature I really doubt anyone is auditing the 10,000 NPM dependencies they drag in. It really will just take one left-pad incident for this to be an absolute disaster.
- simonwIncluding the date in the system prompt - at the cost of a cache invalidation at midnight - is an entirely reasonable decision. Most other harnesses do the same thing.Including the full datetime would be irresponsible, but that's not what OpenCode does.
- thdxrnot too much actionable here. most of the more glaring issues are already fixed in our upcoming v2 if you'd like to try beta: https://x.com/thdxr/status/2075636594640376165some things mention are outdated - particularly the tool call pruning feature. this has been disabled by default for a while specifically because of complaints like thiswhen we looked through our data it's not so clear cut that it's net negative https://x.com/thdxr/status/2048268697790300343also i'm pretty excited about our new system prompt approach - can define each component in a way that avoids busting the cache when they change. eg that midnight issue: https://x.com/thdxr/status/2070721003924103651providers (anthropic is the first) are supporting this as a native concept
- KrysophI find it absurd that a TUI desktop app is heavier than a native one AND heavier than most browser based desktop apps, it's so much waste of RAM, CPU, energy/battery just to show text.I've been working on my own AI harness/chat in C++ Qt6[1] and it's lighter than anything else even with lots of features like sub-agents, code diff, terminal emulator, simple editor, markdown preview, translucent background, custom themes, permissions, MCP, git integration(commits, stage, diffs), dock system to move elements and tabs for projects; but it's not released yet as I want to polish it a bit, remove a few bugs I found and simplify the UI.[1]: https://zeteo.krysoph.com/preview.html
- swsieber> Textual command filtering is entirely useless. It is fit for no purpose. Nobody with any instinct or experience in security would even bother to implement this filter because it achieves nothing except a false sense of security.Not if you only use an allow list. E.g. only allow things matching a particular prefix to run. Also, isn't this what every agent does? And by every I mean Codex because I haven't used the others.
- regexorcistThanks for that, I've been using it but some of these are bad. Specially that it sends data to the cloud by default for session titles, since I use my local model exclusively. So I'm done with it, trying maki now which seems promising and it's so much lighter.
- wagslaneI haven't independently verified all the claims in the article, but as a codex, Claude, and opencode user, opencode is easily my favorite harness. From a user perspective it's a dream
- shironandonandOpenCode is pretty awesome. The article appears written by someone who couldn’t handle a glance behind the curtain and definitely should not research how sausages are made.
- wagslaneA more accurate title would be "The Problem with AI Agent Harnesses, and small annoyances with OpenCode specifically"
- singpolyma3This is an anti AI post masquerading as an anti opencode port.Nevertheless I'm curious what people might suggest to use instead with local models.
- lilerjeeI don't know whether other arguments are true, but some arguments in the end are right:> Using LLMs for code generation feels like a dead end. ..., This is hostile to your ability to understand your code, beyond the fact that you didn’t write it.What you get from AI is not worth of what you have invested for it in long period.> Drawing answers directly from knowledge in model weights leads to hallucination even for multi-trillion-parameter models, so why bother making them that big?Current AI is like the film company producing TV series or movies. "If similar stories do not exist or details are missing, screenwriters use imagination to fill in the gaps (remember hallucination? It's just a makeup.)", refer to the article https://devcyc.life/current-ai-is-like-the-film-company-prod...
- whinvikI am afraid this is a very click-baity title. I actually opened the article and thought I would learn something from it.Instead what I read was typical issues about Agentic CLI's in general dubbed as `alarming`. I would have been happy if the title was just `Annoying` which a lot of `OpenCode` is. But adding the `alarming` made it what it became, something that attracts enough eyeballs to get to the front page of HN.
- pelagicAustral> My conclusion is that OpenCode is clown-car turboslop with a security posture of “let me bend over for you daddy”My type of writing.
- alanwreathI’m not really here to defend opencode (or bash it, who has the time?), but in setting up SDD paired with the right tools to both make deterministic black boxes out of certain actions, paired with subagents. I have ran with opencode and qwen 3.2 on a 5090 and I’m getting results on a production codebase of golang where a review of changes from Claude had no changes but acceptance of the solution.I may be missing some aspect of where the local llm’s are losing, but I’m content with draining my local tokens and treating the frontier models like a less junior SWE.
- s_ting765The solution is not to use docker to sandbox Opencode. It is to use flatpak/bubblewrap/flatseal.I have vscode running in flatpak with directory permissions handled by flatseal. Vscode only has access to my dev folders and nothing else. Even the git bundled by vscode cannot call git push because of this (vscode doesn't have permission to read ~/.ssh!).It's an easy sandbox that's provided free of charge courtesy of bubblewrap/flatpak.As someone who uses opencode regularly, the quip about it asking for permission to read logs in /tmp after already writing to the directory is pretty funny.
- archargelodGood sentiment, wrong target. I took some liberties to fix the beginning:> If you don’t know what AI is, imagine a boot stamping on a human face forever. The boot is made of shit and the face is everything we have learned about security and systems software since the invention of the electronic computer in the 1940s.
- throw8394498383When using local only models, OpenCode uploaded prompts and other data, to remote server to generate session titles, with some free tier model.Useless, if you are dealing with privacy compliance and tons of legal requirements.
- arikrahmanThis is why I use the reasonix or whale harness for Deepseek, prefer the hyper optimized cache hits making request converge on almost free.
- mmaunderRe local LLMs: “You avoid the uncanny valley where the model appears to be intelligent before doing something stupid; the stupidity is self-evident and this helps calibrate your interactions.”Making the authors stance on LLMs clear.
- drbsclAdmittedly I prefer Hermes and oh-my-pi, but most of this post is just hyperbole
- sorenjanFor some reason OpenCode doesn't find my local models through LM Studio. Instead it shows three other models that I don't have. I guess I should add the models myself in opencode.json, but I generally dislike hardcoding things when computers are really good at listing things. The model list is right there in the API, please just use it.
- karlmeissnerInteresting article. What are the alternatives that address the issues raised? I see some folk recommending https://pi.dev/. Has anyone used https://aider.chat/ and liked it?
- josh-wraleRelated post of mine: https://news.ycombinator.com/item?id=48946283
- maxlohTheir "OpenCode" naming is controversial too.Quoting moozilla's comment 11 months ago (https://news.ycombinator.com/item?id=44741894):---If anyone is curious on the context: https://x.com/thdxr/status/1933561254481666466 https://x.com/meowgorithm/status/1933593074820891062 https://www.youtube.com/watch?v=qCJBbVJ_wP0Gemini summary of the above:- Kujtim Hoxha creates a project named TermAI using open-source libraries from the company Charm.- Two other developers, Dax (a well-known internet personality and developer) and Adam (a developer and co-founder of Chef, known for his work on open-source and developer tools), join the project.- They rebrand it to OpenCode, with Dax buying the domain and both heavily promoting it and improving the UI/UX.- The project rapidly gains popularity and GitHub stars, largely due to Dax and Adam's influence and contributions.- Charm, the company behind the original libraries, offers Kujtim a full-time role to continue working on the project, effectively acqui-hiring him.- Kujtim accepts the offer. As the original owner of the GitHub repository, he moves the project and its stars to Charm's organization. Dax and Adam object, not wanting the community project to be owned by a VC-backed company.- Allegations surface that Charm rewrote git history to remove Dax's commits, banned Adam from the repo, and deleted comments that were critical of the move.- Dax and Adam, who own the opencode.ai domain and claim ownership of the brand they created, fork the original repo and launch their own version under the OpenCode name.- For a time, two competing projects named OpenCode exist, causing significant community confusion.- Following the public backlash, Charm eventually renames its version to Crush, ceding the OpenCode name to the project now maintained by Dax and Adam.
- alightsoulThis could be a series of issues on the opencode repo
- abalashovI have an MBP M4 Max 128 GB and have encountered these very limitations, though many are averted by using Qwen3.6-35B-A3B. I'm also not sure there's a magical harness out there that obviates these limitations.
- asveikau> My opinion on local LLMs [...] :>You avoid the uncanny valley where the model appears to be intelligent before doing something stupid; the stupidity is self-evident and this helps calibrate your interactions.This seems to be capturing a feeling I am finding messing with local LLMs: popular software around this seems to be slop coded by no talent hacks. It's a common experience to see a python process pegged at 100% CPU with a huge amount of memory allocated, seemingly doing something that could be a simple shell script. That is before stuff reaches the LLM.If that runs on somebody else's machine, you don't notice. When you see it in top it's frustrating.
- jacobgoldI really hope truly open models and local inference are the future.But are there are any reasons a pragmatic and informed developer would use OpenCode vs Claude/Codex as a harness today?I'm not seeing anything competitive in terms of cost/quality/trust?
- codelionFinally good seeing someone else also getting frustrated with OpenCode and posting the issues.
- thomasjbIt's not a great UI, but for messing with ideas in a VM, the free tier is very hard to beat, otherwise I'd be on Claude Code, but still on a VM, because I won't let them near anything I actually care about.
- axegon_There are a number of points I completely agree with in this blog post. Security implications, handing out all your data to anthropic/openai/google, allowing a slop machine to execute arbitrary code on your machine and having full access to your network is something that would have made anyone working in security commit a ritual suicide just thinking about it as recent as 2022-2023. And I am baffled by the fact that we all sign tons of NDA's as part of our employment contracts, just to throw all out the window by giving it all away to anthropic/openai/google etc, at what is effectively a symbolic fee. We all know it costs a lot more than 100 bucks a month or whatever it is they charge.That said, I firmly believe that if AI is to survive, the future HAS TO BE local or near-local. Having said that, statements such as> Docker causes security holes:> It creates a god-service that runs as root.> It deliberately punches a hole in ufw firewalls.Sorry, none of those are correct IF you know what you are doing. Though I will admit, seeing people that know what they are doing is increasingly uncommon.Also there is nothing wrong with developing inside containers. If anything, that is arguably one of the biggest selling points for containers - environment(s) you can crash infinitely at no cost.I still dislike opencode for a bunch of reasons - the assumption that llms are immune to screw ups, being one. As for the default behavior - using cloud by default - I didn't know that(I do not use any AI for direct coding tasks) and if that is the case, yeah, this is bad. Undeniably a horrible decision.
- mutkachAny recommendations for non-typescript-based coding TUI harnesses/agents other than Codex? Given that Codex is open source someone should've built an untethered client?
- dmytrishOn the upside, Opencode has finally nudged me to learn sandboxing via bwrap in Linux and sandbox-exec on Mac.
- 673dfddndI just did the obvious thing and asked an AI to plan / consider and implement improvements / changes in the code based on the article.
- jmkniposted just as I start to use OpenCode haha
- bellowsgulchThis is a time when I don’t want HN to rewrite an article’s title.I understand why the mods do it, but I don’t appreciate it. It’s your space, but it’s not your article.
- rattlesnakedavePi, especially bundled as OhMyPi, performs significantly better than anything else.
- tomaytotomatoMy bet:In a years time the discussions on using CC, Opencode, Pidev etc. will be redundant as we will be building our own tooling with whatever programming language and tooling you want.Some will repurpose a popular opensource tool or harness, others will build it from scratch in an hour or so.
- mring33621There are definitely annoyances with OpenCode.The remote-preferred attitude caught me once. Also, its server APIs don't match its docs, if you want to talk to it programatically.The following config works for me to keep it on a local model:{ "$schema": "https://opencode.ai/config.json", "provider": { "local-llama": { "npm": "@ai-sdk/openai-compatible", "name": "Local llama.cpp Server", "options": { "baseURL": "http://localhost:8080/v1" }, "models": { "Chefs Choice": { "name": "ANY" } } }, ...This allows me to put any model I want on port 8080.
- anonundefined
- slopinthebagIt’s a shame they have such a dominant position in terms of harnesses. There are many much better alternatives that deserve attention. Especially since one of their main devs is such an asshole online.
- acdUse Picode as an alternative to Opencode
- mistic92I have moved to kilo code for now
- htrpDon't use Opencode, Don't use remote models (cloud providers), Don't use Docker to isolate coding agents.May as well write a post saying don't use LLM's for any SWE work.>Conclusion Stop using OpenCode.>Post-script: Local LLMs This is worth its own post – I have multiple attempts in my blog drafts – but it needs to be addressed briefly here. My opinion on local LLMs like Qwen3.6-27B is they are corrosive to the stability and conceptual fidelity of your codebase in the same way as frontier models, with the following three differences:>You avoid the uncanny valley where the model appears to be intelligent before doing something stupid; the stupidity is self-evident and this helps calibrate your interactions.>The weight count is too low to reproduce the training set verbatim, which nudges the calculus on whether the output should be considered tainted. This is distinct from larger models which can reproduce inputs verbatim, but are trained to refuse to.>You avoid supporting or relying upon cloud providers.>I’ve had useful results from input-oriented tasks like: “I think there is a bug in code x with symptoms y, my guess on the mechanism is z. Read all relevant code, come back with a call chain and code citations.” Framing it as a search problem reins in the clanker’s propensity to make shit up.>Using LLMs for code generation feels like a dead end. However thoroughly you think you understand your architecture, your planning is constantly undone by shortcuts like “what if I just move this mutable state into the middle of the design so everyone can share it?” This is hostile to your ability to understand your code, beyond the fact that you didn’t write it.>Drawing answers directly from knowledge in model weights leads to hallucination even for multi-trillion-parameter models, so why bother making them that big? If people were realistic about limitations then we wouldn’t be building new power stations for datacenters, and they wouldn’t be rammed into every product.>The entire software ecosystem around LLMs is completely rotten, and if they do ever become “just a tool” then some actual systems engineering needs to be done around them to turn them into tools instead of security black holes. That work will have to be done by humans.
- ltbarcly3Opencode's cache hit rate is better than claude code. Opencode has in my experience been better than any of the closed source / closed development alternatives and is not locked down.https://news.ycombinator.com/item?id=48883275
- qarl2> It globs your filesystem and re-reads AGENTS.md (injected in turn-0 system prompt) on every SSE turn. If you put a quick note in AGENTS.md to be read in the next session, you immediately force a full re-evaluation.Um. Which then gets immediately cached again.I prefer this behavior. I prefer my changes incorporated immediately, rather than wait for the next session. Call me crazy.(Author is unhinged and this story is upvoted because #AI-HATE.)
- polski-gOpenCode is indeed bad, but it's the least bad agent out there :(Plugin opencode-slim-system can be used to override the system prompt and the tool description for any tool (including bash). It helps a lot to fix their nonsense.magic-context plugin fixes the compaction issues.Run the entire process in landstrip for sandboxing to alleviate any bash concerns.
- TZubiriI'm glad that when I recommended opencode to a friend, I taught them first to install a vm and create an app specific user to boot.Many users did things right the first couple of days and then turned the security off after seeing it 'work fine' on its own.Was a cool thing to use for a couple of weeks in v1, you have to be quite static to keep using it at v68 of self vibecoding while the llm providers like openai already developed their in house alternative.
- alfiedotwtfWeird this is currently #1 on the front page.
- petesergeantYou should absolutely be running your AI agent inside _some_ kind of sandbox. I put together a list of 19 mostly open-source ones here: https://pleasedonotescape.com/ along with a list of non-project-solutions
- rirzeI was taking this semi-seriously until I read his CLI complaints.Author is unhinged.
- rs_rs_rs_rs_rsWith posts like this there's usually priors involved, it's crazy vitriolic.
- LoganDarkCache misses are the one reason I stopped using OpenCode in favor of Pi. OpenCode mutates the system prompt every turn, which is completely unacceptable and betrays such a basic misunderstanding of LLMs that I can't in good conscience trust the rest of the product regardless of how technically impressive it is.
- speedpingIf OpenCode is so terrible it wouldn't be the base for many of the fortune 500's internal cli coding agents, Meta included
- bitwizeWell, out of the agentic harnesses available, OpenCode is the most promising and capable whilst still remaining open; proprietary alternatives like Claude Code have all these problems and more. So I guess the only way out is to just not use LLMs for development at all....[chadjak.png] Your terms are acceptable.
- kristopolousOpencode offers free models with 200/requests over 5 hours. That's why I use it. It is the only reason I care about.What's the alternative there? Gemini used to have free tiers. Qwen used to. AMP used to. Ollama cloud used to. Codebuff used to... None of them have those programs anymoreThe reason I use it is purely financial. I do not have an employer and I'm writing free softwareEdit: pi.dev doesn't have free inference endpoints. That's the constraint.
- ZababaThe mix of humanizing the LLM, calling it "clanker" and being very aggressive towards it is really weird. I don't think it's a good habit to take, it feels like it could bleed into how you interact with people. Many interactions are through text interfaces these days.
- myshapeprotocol[flagged]
- aitchnyu[dead]
- vityah1[flagged]
- catlover76[dead]
- anmolsharma152[flagged]
- rbren[flagged]
- urvaderAbout the caching things. This is a flaw in the backend, not in the Frontend. If the backend is only relying on prefix cache you need to look for more fine grained cache solutions like HiCache or Lmcache. If your backend discards the whole cache because of one date is changed, you really can’t blame it on the Frontend. It is an implementation detail that you push to the wrong side.