The open source AI coding agent.
English | 简体中文 | 繁體中文 | 한국어 | Deutsch | Español | Français | Italiano | Dansk | 日本語 | Polski | Русский | Bosanski | العربية | Norsk | Português (Brasil) | ไทย | Türkçe | Українська | বাংলা | Ελληνικά | Tiếng Việt
This is a CTF-focused fork of OpenCode. The default agent runs offensive-security workflows against a remote Kali Linux sandbox via E2B.
bun install
cp .env.example .env # then fill in E2B_API_KEY
opencode auth login # pick "opencode" → OpenCode Zen (free + paid models, no extra keys)
bun dev /path/to/your-ctf-workspaceModels route through OpenCode Zen by default. The shipped config uses opencode/deepseek-v4-flash-free (primary) and opencode/qwen3.6-plus-free (recon subagent) — both free tier. Swap to opencode/claude-sonnet-4-6 or opencode/gpt-5.4 in .opencode/opencode.jsonc for harder CTFs.
- Default agent:
ctf— methodical recon → enumeration → exploitation → flag capture. - New tool:
e2b— runs commands inside a Kali sandbox (nmap, sqlmap, nikto, gobuster, etc.). Sole execution surface for the model. - Disabled for the CTF agent: local
shell,edit,write,apply_patch,repo_clone. Kept:read,glob,grep,webfetch,websearch,task,todo,skill. - Blocklist: RFC1918,
.gov,.mil, loopback denied unless explicitly allowlisted viaCTF_ALLOWLIST. - Flag detection: passive regex scans every tool result for
flag{...},HTB{...},picoCTF{...}etc.; matches surface in tool metadata and the agent reports them to you.
/target <url-or-ip>— start a CTF run./recon <target>— spawn the recon subagent./exploit <hypotheses>— enter exploitation phase./reset— destroy + recreate the Kali sandbox.
The fork ships .opencode/opencode.jsonc with sensible CTF defaults. Override locally via your own user config or by editing the file.
Upstream: https://github.com/sst/opencode. We track upstream's main and rebase periodically. The CTF code lives under packages/opencode/src/sandbox/ and packages/opencode/src/tool/e2b.ts.
# YOLO
curl -fsSL https://opencode.ai/install | bash
# Package managers
npm i -g opencode-ai@latest # or bun/pnpm/yarn
scoop install opencode # Windows
choco install opencode # Windows
brew install anomalyco/tap/opencode # macOS and Linux (recommended, always up to date)
brew install opencode # macOS and Linux (official brew formula, updated less)
sudo pacman -S opencode # Arch Linux (Stable)
paru -S opencode-bin # Arch Linux (Latest from AUR)
mise use -g opencode # Any OS
nix run nixpkgs#opencode # or github:anomalyco/opencode for latest dev branchTip
Remove versions older than 0.1.x before installing.
OpenCode is also available as a desktop application. Download directly from the releases page or opencode.ai/download.
| Platform | Download |
|---|---|
| macOS (Apple Silicon) | opencode-desktop-mac-arm64.dmg |
| macOS (Intel) | opencode-desktop-mac-x64.dmg |
| Windows | opencode-desktop-windows-x64.exe |
| Linux | .deb, .rpm, or .AppImage |
# macOS (Homebrew)
brew install --cask opencode-desktop
# Windows (Scoop)
scoop bucket add extras; scoop install extras/opencode-desktopThe install script respects the following priority order for the installation path:
$OPENCODE_INSTALL_DIR- Custom installation directory$XDG_BIN_DIR- XDG Base Directory Specification compliant path$HOME/bin- Standard user binary directory (if it exists or can be created)$HOME/.opencode/bin- Default fallback
# Examples
OPENCODE_INSTALL_DIR=/usr/local/bin curl -fsSL https://opencode.ai/install | bash
XDG_BIN_DIR=$HOME/.local/bin curl -fsSL https://opencode.ai/install | bashOpenCode includes two built-in agents you can switch between with the Tab key.
- build - Default, full-access agent for development work
- plan - Read-only agent for analysis and code exploration
- Denies file edits by default
- Asks permission before running bash commands
- Ideal for exploring unfamiliar codebases or planning changes
Also included is a general subagent for complex searches and multistep tasks.
This is used internally and can be invoked using @general in messages.
Learn more about agents.
For more info on how to configure OpenCode, head over to our docs.
If you're interested in contributing to OpenCode, please read our contributing docs before submitting a pull request.
If you are working on a project that's related to OpenCode and is using "opencode" as part of its name, for example "opencode-dashboard" or "opencode-mobile", please add a note to your README to clarify that it is not built by the OpenCode team and is not affiliated with us in any way.
It's very similar to Claude Code in terms of capability. Here are the key differences:
- 100% open source
- Not coupled to any provider. Although we recommend the models we provide through OpenCode Zen, OpenCode can be used with Claude, OpenAI, Google, or even local models. As models evolve, the gaps between them will close and pricing will drop, so being provider-agnostic is important.
- Built-in opt-in LSP support
- A focus on TUI. OpenCode is built by neovim users and the creators of terminal.shop; we are going to push the limits of what's possible in the terminal.
- A client/server architecture. This, for example, can allow OpenCode to run on your computer while you drive it remotely from a mobile app, meaning that the TUI frontend is just one of the possible clients.
