Summary
In opencode 2.0.12, a custom Markdown agent's V2 permissions: frontmatter list is parsed into agent.request.body.permissions but never merged into the effective session permissions. Deny rules have no effect and the agent keeps the default allow-all tools. The legacy permission: block is still applied correctly.
Environment
- opencode version: 2.0.12
- OS: Linux 7.0.0-31-generic (linux x64)
- Terminal: xterm-256color, COLORTERM=truecolor
- Shell: /usr/bin/zsh
- Install/channel: latest
- Active plugins: none found in config
Reproduction
-
Create ~/.config/opencode/agents/reviewer.md:
---
description: read-only reviewer
mode: subagent
permissions:
- action: edit
resource: "*"
effect: deny
- action: shell
resource: "*"
effect: deny
---
Review the changes. Do not edit files.
-
Reload (file is re-discovered at service start) and query the resolved agent:
opencode service restart
opencode api get /api/agent/reviewer
-
In the response, compare the two permission fields:
data.request.body.permissions contains the declared rules (edit * deny, shell * deny).
data.permissions (the merged list the session runner uses) does not contain them — it ends with global rules and the built-in default * → allow.
-
Run a session with that agent (e.g. opencode run --agent reviewer) and attempt write/shell — both succeed.
Contrast: using the legacy frontmatter permission: { edit: deny, bash: ask } produces matching rules in data.permissions, and edit is denied at session level.
Expected Behavior
permissions: in Markdown agent frontmatter should be applied: data.permissions should include the agent rules (appended after global permissions, last-match-wins), and sessions with that agent should deny the listed tools — same as documented for JSONC agents and for the legacy permission: block.
Actual Behavior
The frontmatter permissions: list is parsed but only stored in request.body.permissions, which the session runner does not use. Session permissions stay allow-by-default; write, edit, and shell remain available to an agent that declared them denied.
Observed API evidence (redacted):
Additional Context
- Config: global
~/.config/opencode/opencode.jsonc; agents as .md files in ~/.config/opencode/agents/.
- Workaround: keep using the legacy
permission: frontmatter block; v2.0.12 still applies it (edit → edit * deny, bash patterns → shell * rules, task → subagent * allow).
- Reproducible consistently on every reload.
- Related: docs page https://opencode.ai/v2/docs/agents documents
permissions: for Markdown frontmatter.
Summary
In opencode 2.0.12, a custom Markdown agent's V2
permissions:frontmatter list is parsed intoagent.request.body.permissionsbut never merged into the effective session permissions. Deny rules have no effect and the agent keeps the default allow-all tools. The legacypermission:block is still applied correctly.Environment
Reproduction
Create
~/.config/opencode/agents/reviewer.md:Reload (file is re-discovered at service start) and query the resolved agent:
In the response, compare the two permission fields:
data.request.body.permissionscontains the declared rules (edit * deny,shell * deny).data.permissions(the merged list the session runner uses) does not contain them — it ends with global rules and the built-in default* → allow.Run a session with that agent (e.g.
opencode run --agent reviewer) and attemptwrite/shell— both succeed.Contrast: using the legacy frontmatter
permission: { edit: deny, bash: ask }produces matching rules indata.permissions, andeditis denied at session level.Expected Behavior
permissions:in Markdown agent frontmatter should be applied:data.permissionsshould include the agent rules (appended after global permissions, last-match-wins), and sessions with that agent should deny the listed tools — same as documented for JSONC agents and for the legacypermission:block.Actual Behavior
The frontmatter
permissions:list is parsed but only stored inrequest.body.permissions, which the session runner does not use. Session permissions stay allow-by-default;write,edit, andshellremain available to an agent that declared them denied.Observed API evidence (redacted):
Additional Context
~/.config/opencode/opencode.jsonc; agents as.mdfiles in~/.config/opencode/agents/.permission:frontmatter block; v2.0.12 still applies it (edit→edit * deny,bashpatterns →shell * rules,task→subagent * allow).permissions:for Markdown frontmatter.