Skip to content

agents: markdown frontmatter "permissions" (V2) parsed but never applied to sessions #50598

Description

@MikeCHOKKI

Summary

In opencode 2.0.12, a custom Markdown agent's V2 permissions: frontmatter list is parsed into agent.request.body.permissions but never merged into the effective session permissions. Deny rules have no effect and the agent keeps the default allow-all tools. The legacy permission: block is still applied correctly.

Environment

  • opencode version: 2.0.12
  • OS: Linux 7.0.0-31-generic (linux x64)
  • Terminal: xterm-256color, COLORTERM=truecolor
  • Shell: /usr/bin/zsh
  • Install/channel: latest
  • Active plugins: none found in config

Reproduction

  1. Create ~/.config/opencode/agents/reviewer.md:

    ---
    description: read-only reviewer
    mode: subagent
    permissions:
      - action: edit
        resource: "*"
        effect: deny
      - action: shell
        resource: "*"
        effect: deny
    ---
    Review the changes. Do not edit files.
  2. Reload (file is re-discovered at service start) and query the resolved agent:

    opencode service restart
    opencode api get /api/agent/reviewer
  3. In the response, compare the two permission fields:

    • data.request.body.permissions contains the declared rules (edit * deny, shell * deny).
    • data.permissions (the merged list the session runner uses) does not contain them — it ends with global rules and the built-in default * → allow.
  4. Run a session with that agent (e.g. opencode run --agent reviewer) and attempt write/shell — both succeed.

Contrast: using the legacy frontmatter permission: { edit: deny, bash: ask } produces matching rules in data.permissions, and edit is denied at session level.

Expected Behavior

permissions: in Markdown agent frontmatter should be applied: data.permissions should include the agent rules (appended after global permissions, last-match-wins), and sessions with that agent should deny the listed tools — same as documented for JSONC agents and for the legacy permission: block.

Actual Behavior

The frontmatter permissions: list is parsed but only stored in request.body.permissions, which the session runner does not use. Session permissions stay allow-by-default; write, edit, and shell remain available to an agent that declared them denied.

Observed API evidence (redacted):

// data.request.body.permissions — parsed but inert
[ { "action": "*", "resource": "*", "effect": "deny" },
  { "action": "edit", "resource": "*", "effect": "deny" } ]

// data.permissions (tail) — agent rules absent, default allow wins
[ ..., { "action": "edit", "resource": "*", "effect": "ask" },
       { "action": "read",   "resource": "*", "effect": "allow" } ]

Additional Context

  • Config: global ~/.config/opencode/opencode.jsonc; agents as .md files in ~/.config/opencode/agents/.
  • Workaround: keep using the legacy permission: frontmatter block; v2.0.12 still applies it (edit → edit * deny, bash patterns → shell * rules, task → subagent * allow).
  • Reproducible consistently on every reload.
  • Related: docs page https://opencode.ai/v2/docs/agents documents permissions: for Markdown frontmatter.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions