Why Sandbox OpenCode?
OpenCode has full access to your filesystem and can run arbitrary commands. Without isolation:- It could access files outside your project directory
- A malicious prompt or compromised dependency could exfiltrate credentials
- Unintended writes could affect configuration or system files
Quick Start
- Read+write access to the current working directory
- Read+write access to
~/.config/opencode(configuration) - Read+write access to
~/.cache/opencode(cache) - Read+write access to
~/.local/share/opencode(data) - Network access enabled (required for AI provider API calls)
Custom Profile
Create~/.config/nono/profiles/opencode.toml for different permissions:
