opencode is an open-source AI coding agent that people run from a terminal on their Mac, and it is a frequent subject of searches such as “opencode security mac”, “is opencode safe” and “opencode network access”. Its documentation is direct about the permission model and about the one feature that uploads a conversation to a server. This article sets out those documented facts, then explains how FireAI, an on-device firewall for macOS made by HisnLabs, watches the connections the program makes and what it cannot do.
What opencode is
opencode describes itself as “the open source AI coding agent”. The GitHub repository, which has moved from the sst organisation to anomalyco, carries an MIT licence. It ships as a terminal interface, a desktop application (marked beta in the README) and an IDE extension, and includes two built-in agents: build, a full-access agent that is the default, and plan, a read-only agent that asks for permission [1]. Users connect it to model providers with API keys; the introduction recommends OpenCode Zen, a curated list of models tested by the opencode team [2].
How opencode runs on macOS
The README lists several ways to install on macOS: the script curl -fsSL https://opencode.ai/install | bash, npm, bun, pnpm or yarn, Homebrew, and a DMG for the desktop app. For a command-line install, the program you launch is named opencode, which is how the process appears to the system.
What it can access and how it is controlled
The permission system has three states: allow, ask and deny. Rules can be set globally or per tool, and can match patterns of the tool input, with the last matching rule winning. The documentation states that most permissions default to allow; doom_loop and external_directory default to ask, and .env files are blocked by default. The --auto flag approves requests automatically unless an explicit deny rule applies [3].
The external_directory permission governs paths outside the project workspace. These permissions govern what the agent does with tools, such as reading, editing and running commands. They are not described as a network allow-list.
Where it connects
The page on sharing documents the one feature that sends a conversation to opencode’s servers. The /share command creates a public URL and syncs the conversation history, messages, responses and session metadata to them. Sharing is manual by default, so nothing is sent without that command; it can be turned off with "share": "disabled" in opencode.json, and shared sessions remain accessible until /unshare is used [4]. The pages read for this article do not list further domains, so beyond your model provider and anything a tool contacts, treat other destinations as undocumented here.
Watching opencode with FireAI
FireAI is a firewall for macOS that runs on the Mac. Its Agent profile feature recognises 19 AI agents, learns where each normally connects and flags what is new. FireAI’s Agent profile page lists opencode among the command-line agents recognised by the name of their program. Connections made by a program named opencode, and by its child processes such as a shell or git, are therefore attributed to opencode.
- For the first 3 days FireAI learns the destinations the agent normally contacts, grouped by domain, so api.anthropic.com becomes anthropic.com. Nothing is flagged during this period.
- After that, the first-ever destination outside the baseline is flagged for review in Suggestions, in the AI agents card and in Quick Review. Swipe left to block, or right for “It’s fine”.
- An upload spike is flagged too: an hour in which the agent uploaded at least 4 times its busiest hour so far, and never less than 25 MB.
- FireAI uses metadata only, meaning host names and byte counts. It never reads the payload of a connection.
Setting up FireAI for opencode
- Install FireAI and use the agent as you normally do. The 3-day learning period starts on its own and flags nothing.
- Open Suggestions and find the AI agents card. After the learning period, a flag for the agent appears there and in Quick Review.
- Review each flag. Choose Block to create a rule for the process that connected, or “It’s fine” to add the destination to the agent’s baseline.
- To keep the agent to the places it already uses, choose Agent profile in the security mode menu, next to Home, Coffee shop, Paranoid and Under attack. Your rules apply as in Home, and a connection to a destination outside the baseline is blocked instead of flagged once the agent has finished learning.
- A blocked destination appears in the AI agents card with Allow and Keep blocked. Allow adds it to the baseline and the agent reaches it right away. Keep blocked creates a block rule that holds in every mode.
An allow rule you wrote for a website, domain or address still wins, and DNS and your local network are never blocked. For an agent FireAI does not list, write a rule for its program by hand in per-app rules. The Agent profile mode needs FireAI 1.0.3 or later, and recognition of opencode needs 1.0.4.
Limits
- opencode’s permission rules decide which tool calls are approved, and in
--automode they approve most of them. FireAI works at the connection layer instead, so the two complement each other rather than overlap. - opencode is recognised by the name of its program, which means it is labelled, not verified: only Claude Code, Claude and Cursor are checked against their developer’s signature.
- FireAI does not stop prompt injection. It limits the damage by flagging, and letting you block, the path data would take out of your Mac.
- FireAI cannot see prompts, the contents of MCP tools, file access or skills. TLS hides the payload, and FireAI is not inside the agent.
- Child processes that exit very quickly may be missed, and they are matched by path, not by signature.
- During the 3-day learning period nothing is flagged, and upload spikes are flagged, not blocked.
- In the Agent profile mode, a connection made to a bare IP address with no host name is matched by its address, so a new address for a service the agent normally uses is blocked until you allow it.
Other agents
The same approach applies to every agent FireAI recognises. See the other guides: Claude Code, the Claude desktop app, Cursor, the ChatGPT Mac app, OpenAI Codex CLI, OpenClaw, Hermes Agent, Gemini CLI, GitHub Copilot CLI, Amp, Qwen Code, Aider, Goose, Crush, Windsurf, Kiro, Trae, Muse from Meta, any other AI agent running on python or node. The full feature description is on the Agent profile documentation page, published by HisnLabs.
How FireAI and HisnLabs fit in
FireAI learns where opencode normally connects on your Mac and flags a first-ever destination or an upload spike, without reading your data.
FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac.
You can read the technical decisions behind it, or try FireAI for 17 days, at FireAI, by HisnLabs.
