Skip to content

policy: deny shell * on custom agent breaks free tier with "can only be used from within OpenCode" #50627

Description

@Saka-CS

Summary

Enabling permissions: [{action: shell, resource: "*", effect: deny}] on a custom primary agent makes every request fail on all free-tier models with OpenCode's free tier can only be used from within OpenCode, even though the request originates from inside OpenCode TUI.

Environment

  • opencode version: v2.0.13
  • OS: Linux saka 7.2.5-3-omarchy feat: compact and other improvements #1 SMP PREEMPT_DYNAMIC Mon, 14 Sep 2026 19:55:01 +0000 x86_64 GNU/Linux
  • Terminal: TERM=xterm-256color, TERM_PROGRAM=ghostty, COLORTERM=truecolor
  • Shell: /usr/bin/bash
  • Install/channel: latest
  • Active plugins: none found

Reproduction

  1. Use TUI with custom primary agent at ~/.config/opencode/agents/search.md with frontmatter:
permissions:
  - action: edit
    resource: "*"
    effect: deny
  - action: shell
    resource: "*"
    effect: deny
  - action: subagent
    resource: "*"
    effect: deny
  - action: subagent
    resource: "explore"
    effect: allow
  - action: subagent
    resource: "general"
    effect: allow
  - action: websearch
    resource: "*"
    effect: allow
  - action: webfetch
    resource: "*"
    effect: allow
  - action: read
    resource: "*"
    effect: allow
  - action: glob
    resource: "*"
    effect: allow
  - action: grep
    resource: "*"
    effect: allow
  1. Send any message to that agent on any Console free-tier model via TUI.
  2. Observe Error: Error from provider (Console): OpenCode's free tier can only be used from within OpenCode.
  3. Comment out the shell: "*" deny lines -> works again.

Expected Behavior

Shell deny should only block shell tool calls; the LLM request itself should still authenticate as in-OpenCode free-tier use.

Actual Behavior

Entire session fails with free-tier origin error on every message, before any tool use. Always reproducible; removal fixes. Affects all free models. Error is single line only.

Additional Context

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions