Repository navigation
Conversation
|
This PR doesn't fully meet our contributing guidelines and PR template. What needs to be fixed:
Please edit this PR description to address the above within 2 hours, or it will be automatically closed. If you believe this was flagged incorrectly, please let a maintainer know. |
|
The following comment was made by an LLM, it may be inaccurate: I found one potentially related PR: PR #33698: feat: Introducing skills and agents marketplace for opencode CLI This earlier PR may be related as it also addresses marketplace functionality for skills and agents installation. However, based on the PR description, the current PR #40085 appears to be a comprehensive rewrite that unifies marketplace functionality across multiple component types (plugins, skills, agents, commands, MCP servers, instructions) with a redesigned architecture, security model, and user experience. PR #33698 may represent earlier work on a similar feature that has been superseded or significantly evolved in the current PR. |
|
This pull request has been automatically closed because it was not updated to meet our contributing guidelines within the 2-hour window. Feel free to open a new pull request that follows our guidelines. |
Summary
Adds a unified OpenCode Marketplace for installing and managing plugins, skills, agents and subagents, slash commands, MCP servers, instruction files, and reusable bundles.
Original issue: anomalyco/opencode#28696.
The branch has been rebuilt as 10 focused commits directly on the current
devhead. It includes the original desktop/TUI experience plus the completed security, reproducibility, Codex compatibility, control-plane, and reliability work.Why
Marketplace packages can contain executable plugins, local MCP commands, and model-influencing instructions. The implementation therefore keeps discovery separate from activation and preserves a strict ownership boundary:
Marketplace operations never persist generated Marketplace entries into
opencode.jsonoropencode.jsonc. User edits remain user-owned and survive package updates, disables, and uninstalls.Architecture
Core domain and compatibility
opencode.marketplace/v1catalog and install-plan model..agents/plugins/marketplace.jsoncatalogs and.codex-plugin/plugin.jsonmanifests into the same install pipeline.Registry and runtime overlay
SQLite/Drizzle is the source of truth for:
Writes are transactional and compare-and-swap revision aware. Stale clients receive a revision conflict instead of replacing newer state.
Active plans are projected into
plugin,skills,agent,command,mcp, andinstructionsonly in memory. Explicit package priority determines conflict resolution; disabling the active provider exposes the next eligible provider.Immutable plan/apply lifecycle
Install, aggregate update, and profile import use the same two-phase flow:
plan_id.Aggregate update planning prepares all eligible updates before one atomic apply. Component choices are preserved where the updated package still declares the component, and updates never perform an implicit semantic-version downgrade.
Content-addressed cache
Catalogs, manifests, icons, plugin files, skills, and instructions are stored and verified by SHA-256 digest.
The cache additionally:
file://artifacts;408,429, and server errors;401,403, or404;Private source secrets use
header_envenvironment-variable bindings. Secret values are resolved only at request time and are never written to SQLite, returned by the API, or exported.Profiles, locks, and audit
opencode.marketplace.profile/v2profiles.opencode.marketplace.lock/v1locks containing package, materialization, and artifact digests.User experience
Desktop
TUI
CLI
Marketplace API
Desktop, TUI, and CLI use the domain control plane rather than replacing global configuration:
Mutations accept
expected_revision; install/update/profile apply operations also require a one-timeplan_id. Listing supports cursor pagination. Public responses redact resolved headers, materialized plans, internal artifact references, and machine-local state.The Effect HttpApi definitions are the source of truth, and both generated JavaScript clients were regenerated.
Source and catalog behavior
Sources may be HTTPS catalogs, loopback development catalogs, GitHub shorthand/repositories, conventional GitLab/Gitea repository URLs, local catalog files/directories, or
file://URLs.Directory discovery supports:
.opencode/marketplace.json;marketplace.json;.agents/plugins/marketplace.json;.claude-plugin/marketplace.json.Official and verified provenance cannot be spoofed by user configuration. Installed packages remain visible, toggleable, and removable when a source is disabled, unavailable, removed, or no longer publishes the item.
Additional reliability fixes
The final branch also retains validated fixes discovered while stabilizing the feature:
opencode runevent subscriptions;Security model
Marketplace is a discovery, materialization, and configuration mechanism, not a sandbox.
The UI exposes provenance, publisher, requested capabilities, compatibility failures, setup notes, and planned configuration before activation.
Migration policy
Marketplace has not shipped with the intermediate development formats. The final Drizzle migrations create the Marketplace registry and audit tables. OpenCode intentionally does not import experimental
registry.jsonfiles, receipt snapshots, or Marketplace fields written into configuration by earlier branch revisions.Validation
Current rewritten head was published only after the repository pre-push hook completed the full monorepo typecheck successfully: 30 tasks across the 36-package workspace scope.
Focused local validation also passed:
git diff --check.The documentation is intentionally English-only. Temporary export, diagnostic, and validation workflows are not part of the final diff.