Description
The V2 subagent tool exposes an optional model argument to the parent model. The tool description tells the parent model not to set this field unless the user explicitly requests a particular model, but that instruction is advisory prompt text rather than an enforced runtime constraint.
In OpenCode v2.0.15, a parent-supplied model is resolved and used with the following precedence:
const model = override ?? agent.model ?? parent.model
The subagent permission check only includes the agent ID:
permission.assert({
action: name,
resources: [agent.id],
// ...
})
The model provider, model ID, and variant are not included in the permission resource or otherwise checked against user authorization.
As a result, a primary agent can silently route a child session to another provider/model/variant based on its own judgment. The user does not have to configure that model or explicitly approve the change. This can unexpectedly change cost, provider, and data-routing behavior.
This is not a request to remove dynamic model selection. It is a request to enforce the boundary between model selection and user authorization: an override should either be rejected unless explicitly user-authorized, or be included in the subagent permission prompt/allowlist.
Plugins
superpowers@git+https://github.com/obra/superpowers.git
OpenCode version
2.0.15
Steps to reproduce
- Run OpenCode v2.0.15.
- Do not configure
agents.general.model; verify that the built-in general agent has no configured model.
- Start a primary session using
opencode-go/space-bunny-free.
- Ask the primary agent to delegate an ordinary task to the
general subagent without naming or requesting any model.
- Inspect the parent session's
subagent tool call and the child session metadata.
- In the observed run, the parent supplied
model values such as:
opencode-go/deepseek-v4-pro
opencode-go/deepseek-v4.1-flash
- The child sessions then ran using those same models, even though the user prompt did not request a model and
general had no configured model.
- Observe that the subagent permission request identifies the agent, but does not identify or authorize the selected model.
The exact parent prompt can affect whether the parent chooses to emit the optional field; the defect is that OpenCode accepts the field without enforcing the stated authorization rule.
Screenshot and/or share link
No screenshot. The issue can be reproduced by inspecting the parent subagent tool input and the child session model through the session API.
Operating System
macOS (Darwin 25.6.0, arm64)
Terminal
VS Code integrated terminal (TERM_PROGRAM=vscode, TERM=xterm-256color)
Additional context
Relevant v2.0.15 implementation:
packages/core/src/tool/plugin/subagent.ts
Input.model says “NEVER set this unless the user explicitly asks...” (lines 36–38)
- permission assertion covers only
agent.id (lines 138–151)
input.model is resolved as an override (line 168)
- the child model is selected as
override ?? agent.model ?? parent.model (line 184)
Source:
https://github.com/anomalyco/opencode/blob/6f3639d82ed0760091792189b78f8eeb44f699b1/packages/core/src/tool/plugin/subagent.ts
Related existing discussion:
#6651
Description
The V2
subagenttool exposes an optionalmodelargument to the parent model. The tool description tells the parent model not to set this field unless the user explicitly requests a particular model, but that instruction is advisory prompt text rather than an enforced runtime constraint.In OpenCode v2.0.15, a parent-supplied model is resolved and used with the following precedence:
The subagent permission check only includes the agent ID:
The model provider, model ID, and variant are not included in the permission resource or otherwise checked against user authorization.
As a result, a primary agent can silently route a child session to another provider/model/variant based on its own judgment. The user does not have to configure that model or explicitly approve the change. This can unexpectedly change cost, provider, and data-routing behavior.
This is not a request to remove dynamic model selection. It is a request to enforce the boundary between model selection and user authorization: an override should either be rejected unless explicitly user-authorized, or be included in the subagent permission prompt/allowlist.
Plugins
superpowers@git+https://github.com/obra/superpowers.git
OpenCode version
2.0.15
Steps to reproduce
agents.general.model; verify that the built-ingeneralagent has no configured model.opencode-go/space-bunny-free.generalsubagent without naming or requesting any model.subagenttool call and the child session metadata.modelvalues such as:opencode-go/deepseek-v4-proopencode-go/deepseek-v4.1-flashgeneralhad no configured model.The exact parent prompt can affect whether the parent chooses to emit the optional field; the defect is that OpenCode accepts the field without enforcing the stated authorization rule.
Screenshot and/or share link
No screenshot. The issue can be reproduced by inspecting the parent
subagenttool input and the child session model through the session API.Operating System
macOS (Darwin 25.6.0, arm64)
Terminal
VS Code integrated terminal (
TERM_PROGRAM=vscode,TERM=xterm-256color)Additional context
Relevant v2.0.15 implementation:
packages/core/src/tool/plugin/subagent.tsInput.modelsays “NEVER set this unless the user explicitly asks...” (lines 36–38)agent.id(lines 138–151)input.modelis resolved as an override (line 168)override ?? agent.model ?? parent.model(line 184)Source:
https://github.com/anomalyco/opencode/blob/6f3639d82ed0760091792189b78f8eeb44f699b1/packages/core/src/tool/plugin/subagent.ts
Related existing discussion:
#6651