Stop Using OpenCode: A Security Nightmare and Performance Disaster

Stop Using OpenCode

85alekq💬 58

I tested OpenCode, the popular AI coding agent, and found it to be a security risk filled with performance flaws. Its poor prompt cache management causes massive delays, while aggressive context pruning deletes critical instructions. The tool's design decisions are frustrating, and its security posture is dangerously weak. Everyone should stop using it immediately.

"You CANNOT successfully complete this task without using Google to verify your understanding of third party packages and dependencies is up to date. You cannot. It's just impossible."

HN discussion

  • Practitioners argue that executing build artifacts and running tests is essential for autonomous agent loops, citing implementations in Claude Code, Codex, Aider, and Devin where agents iteratively validate their own code.
  • Critics highlight a significant supply-chain vulnerability in 'vibe-coded' tools like OpenCode, noting that daily updates and thousands of un-audited NPM dependencies create a high risk of catastrophic failure.
  • Users report that despite the tool's perceived security flaws and 'vibe-coded' nature, its effectiveness in local development makes switching to alternatives unjustifiable for many workflows.
  • Some developers express frustration with default system prompts that enforce 'self-documenting code' by stripping inline comments, viewing this as a counterproductive opinion that hinders future maintenance.
  • Privacy-conscious users mitigate cloud data risks by simply disabling internet access when running local models with OpenCode, though others reject this workaround due to default session title uploads.

More from this day · 2026-07-20