# opencode Security on Mac: Monitor Network Access with FireAI

> opencode is an open-source terminal coding agent with a permissive default permission model and an optional share feature. Learn what it can reach on a Mac and how FireAI flags new destinations.

FireAI Security & Research Team (HisnLabs) · Published 2026-10-04
Canonical: https://hisnlabs.com/en/blog/monitor-opencode-network-mac-fireai

opencode is an open-source AI coding agent that people run from a terminal on their Mac, and it is a frequent subject of searches such as “opencode security mac”, “is opencode safe” and “opencode network access”. Its documentation is direct about the permission model and about the one feature that uploads a conversation to a server. This article sets out those documented facts, then explains how FireAI, an on-device firewall for macOS made by HisnLabs, watches the connections the program makes and what it cannot do.

## What opencode is

opencode describes itself as “the open source AI coding agent”. The GitHub repository, which has moved from the sst organisation to anomalyco, carries an MIT licence. It ships as a terminal interface, a desktop application (marked beta in the README) and an IDE extension, and includes two built-in agents: build, a full-access agent that is the default, and plan, a read-only agent that asks for permission [[1]](https://github.com/sst/opencode). Users connect it to model providers with API keys; the introduction recommends OpenCode Zen, a curated list of models tested by the opencode team [[2]](https://opencode.ai/docs/).

## How opencode runs on macOS

The README lists several ways to install on macOS: the script `curl -fsSL https://opencode.ai/install | bash`, npm, bun, pnpm or yarn, Homebrew, and a DMG for the desktop app. For a command-line install, the program you launch is named `opencode`, which is how the process appears to the system.

## What it can access and how it is controlled

The permission system has three states: allow, ask and deny. Rules can be set globally or per tool, and can match patterns of the tool input, with the last matching rule winning. The documentation states that most permissions default to allow; `doom_loop` and `external_directory` default to ask, and `.env` files are blocked by default. The `--auto` flag approves requests automatically unless an explicit deny rule applies [[3]](https://opencode.ai/docs/permissions/).

The `external_directory` permission governs paths outside the project workspace. These permissions govern what the agent does with tools, such as reading, editing and running commands. They are not described as a network allow-list.

## Where it connects

The page on sharing documents the one feature that sends a conversation to opencode’s servers. The `/share` command creates a public URL and syncs the conversation history, messages, responses and session metadata to them. Sharing is manual by default, so nothing is sent without that command; it can be turned off with `"share": "disabled"` in `opencode.json`, and shared sessions remain accessible until `/unshare` is used [[4]](https://opencode.ai/docs/share/). The pages read for this article do not list further domains, so beyond your model provider and anything a tool contacts, treat other destinations as undocumented here.

> **Note:** This article reports what opencode’s own documentation says and what it leaves out. We list no domain, incident or vulnerability that the sources above do not state.

## Watching opencode with FireAI

FireAI is a firewall for macOS that runs on the Mac. Its [Agent profile](https://hisnlabs.com/en/docs/agent-profile) feature recognises 19 AI agents, learns where each normally connects and flags what is new. FireAI’s Agent profile page lists opencode among the command-line agents recognised by the name of their program. Connections made by a program named `opencode`, and by its child processes such as a shell or git, are therefore attributed to opencode.

- For the first 3 days FireAI learns the destinations the agent normally contacts, grouped by domain, so api.anthropic.com becomes anthropic.com. Nothing is flagged during this period.
- After that, the first-ever destination outside the baseline is flagged for review in Suggestions, in the AI agents card and in Quick Review. Swipe left to block, or right for “It’s fine”.
- An upload spike is flagged too: an hour in which the agent uploaded at least 4 times its busiest hour so far, and never less than 25 MB.
- FireAI uses metadata only, meaning host names and byte counts. It never reads the payload of a connection.

> Want a firewall that tells you when opencode reaches somewhere new? FireAI learns each agent’s normal destinations on your Mac. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Setting up FireAI for opencode

1. Install FireAI and use the agent as you normally do. The 3-day learning period starts on its own and flags nothing.
2. Open Suggestions and find the AI agents card. After the learning period, a flag for the agent appears there and in Quick Review.
3. Review each flag. Choose Block to create a rule for the process that connected, or “It’s fine” to add the destination to the agent’s baseline.
4. To keep the agent to the places it already uses, choose Agent profile in the security mode menu, next to Home, Coffee shop, Paranoid and Under attack. Your rules apply as in Home, and a connection to a destination outside the baseline is blocked instead of flagged once the agent has finished learning.
5. A blocked destination appears in the AI agents card with Allow and Keep blocked. Allow adds it to the baseline and the agent reaches it right away. Keep blocked creates a block rule that holds in every mode.

An allow rule you wrote for a website, domain or address still wins, and DNS and your local network are never blocked. For an agent FireAI does not list, write a rule for its program by hand in [per-app rules](https://hisnlabs.com/en/docs/per-app-rules). The Agent profile mode needs FireAI 1.0.3 or later, and recognition of opencode needs 1.0.4.

## Limits

- opencode’s permission rules decide which tool calls are approved, and in `--auto` mode they approve most of them. FireAI works at the connection layer instead, so the two complement each other rather than overlap.
- opencode is recognised by the name of its program, which means it is labelled, not verified: only Claude Code, Claude and Cursor are checked against their developer’s signature.
- FireAI does not stop prompt injection. It limits the damage by flagging, and letting you block, the path data would take out of your Mac.
- FireAI cannot see prompts, the contents of MCP tools, file access or skills. TLS hides the payload, and FireAI is not inside the agent.
- Child processes that exit very quickly may be missed, and they are matched by path, not by signature.
- During the 3-day learning period nothing is flagged, and upload spikes are flagged, not blocked.
- In the Agent profile mode, a connection made to a bare IP address with no host name is matched by its address, so a new address for a service the agent normally uses is blocked until you allow it.

## Other agents

The same approach applies to every agent FireAI recognises. See the other guides: [Claude Code](https://hisnlabs.com/en/blog/monitor-claude-code-network-mac-fireai), [the Claude desktop app](https://hisnlabs.com/en/blog/monitor-claude-desktop-app-network-mac-fireai), [Cursor](https://hisnlabs.com/en/blog/monitor-cursor-network-mac-fireai), [the ChatGPT Mac app](https://hisnlabs.com/en/blog/monitor-chatgpt-mac-app-network-fireai), [OpenAI Codex CLI](https://hisnlabs.com/en/blog/monitor-openai-codex-cli-network-mac-fireai), [OpenClaw](https://hisnlabs.com/en/blog/monitor-openclaw-network-mac-fireai), [Hermes Agent](https://hisnlabs.com/en/blog/monitor-hermes-agent-network-mac-fireai), [Gemini CLI](https://hisnlabs.com/en/blog/monitor-gemini-cli-network-mac-fireai), [GitHub Copilot CLI](https://hisnlabs.com/en/blog/monitor-github-copilot-cli-network-mac-fireai), [Amp](https://hisnlabs.com/en/blog/monitor-amp-agent-network-mac-fireai), [Qwen Code](https://hisnlabs.com/en/blog/monitor-qwen-code-network-mac-fireai), [Aider](https://hisnlabs.com/en/blog/monitor-aider-network-mac-fireai), [Goose](https://hisnlabs.com/en/blog/monitor-goose-agent-network-mac-fireai), [Crush](https://hisnlabs.com/en/blog/monitor-crush-agent-network-mac-fireai), [Windsurf](https://hisnlabs.com/en/blog/monitor-windsurf-network-mac-fireai), [Kiro](https://hisnlabs.com/en/blog/monitor-kiro-network-mac-fireai), [Trae](https://hisnlabs.com/en/blog/monitor-trae-network-mac-fireai), [Muse from Meta](https://hisnlabs.com/en/blog/monitor-muse-meta-network-mac-fireai), [any other AI agent running on python or node](https://hisnlabs.com/en/blog/monitor-any-ai-agent-mac-python-node-fireai). The full feature description is on the [Agent profile documentation page](https://hisnlabs.com/en/docs/agent-profile), published by HisnLabs.

> See every connection your Mac makes — and decide which ones go through. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## How FireAI and HisnLabs fit in

FireAI learns where opencode normally connects on your Mac and flags a first-ever destination or an upload spike, without reading your data.

FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac.

You can read the technical decisions behind it, or try FireAI for 17 days, at [FireAI, by HisnLabs](https://hisnlabs.com/en/download).

## Sources

- [opencode: project repository and README (GitHub)](https://github.com/sst/opencode)
- [opencode documentation: introduction](https://opencode.ai/docs/)
- [opencode documentation: permissions](https://opencode.ai/docs/permissions/)
- [opencode documentation: share](https://opencode.ai/docs/share/)
- [FireAI docs: Agent profile](https://hisnlabs.com/en/docs/agent-profile)
- [FireAI docs: Rules](https://hisnlabs.com/en/docs/per-app-rules)
