Skip to content

v2.0.1.2 — Create command dispatch security fix + defensive hardening

Choose a tag to compare

@MichelKerkmeester MichelKerkmeester released this 14 Feb 08:33
· 10134 commits to main since this release

This release updates the OpenCode environment with work on security - create command dispatch fix and hardening, orphaned file. The goal is to make the platform clearer, more reliable, and easier to use day to day.

 

Security - Create Command Dispatch Fix And Hardening

  • Need: This part of the release makes agent behavior more consistent across the supported runtimes.
  • What changed: Critical Fix: create/skill.md had the same two-factor vulnerability - Task in allowed-tools + @Write agent references. Removed Task (not needed for slash command chaining) and added imperative guardrail block. Defensive Hardening: All 6 create commands now have execution protocol guardrails preventing phantom dispatch, even if Task is re-added in the future. Structured Config Files Workflow Assets Marked: All 6 structured config files workflow assets marked as REFERENCE ONLY.
  • Why it matters: That matters because the same instructions now behave more predictably in different runtimes.

 

Orphaned File

  • Need: This part of the release makes agent behavior more consistent across the supported runtimes.
  • What changed: Orphaned File: create_agent.yaml exists but is never loaded by agent.md (inline workflow used instead). Flagged for future cleanup.
  • Why it matters: That matters because the same instructions now behave more predictably in different runtimes.

Files Changed

File or Area Note
.opencode/command/create/skill.md - Task removed from allowed-tools + guardrail added Updated in this release.
.opencode/command/create/agent.md - guardrail added (no-structured config files variant) Updated in this release.
.opencode/command/create/skill_reference.md - guardrail added Updated in this release.
.opencode/command/create/skill_asset.md - guardrail added Updated in this release.
.opencode/command/create/install_guide.md - guardrail added Updated in this release.
.opencode/command/create/folder_readme.md - guardrail added 6 structured config files assets marked: Updated in this release.
.opencode/command/create/assets/create_skill.yaml - REFERENCE ONLY comment Updated in this release.
.opencode/command/create/assets/create_agent.yaml - REFERENCE ONLY comment Updated in this release.
.opencode/command/create/assets/create_skill_reference.yaml - REFERENCE ONLY comment Updated in this release.
.opencode/command/create/assets/create_skill_asset.yaml - REFERENCE ONLY comment Updated in this release.
.opencode/command/create/assets/create_install_guide.yaml - REFERENCE ONLY comment Updated in this release.
.opencode/command/create/assets/create_folder_readme.yaml - REFERENCE ONLY comment Updated in this release.

Upgrade

  • Drop-in replacement. Copy.opencode/command/create/ to your project.
  • --.

Full changelog: .opencode/changelog/