Files
cleveragents-core/opencode.json
T
drew 706178d54b fix(auto-agents): tier-selector pass-through lockdown + local-claude provider
Three coupled fixes from the run-3/4/5 forensic sequence, plus the
local-claude model routing they depend on.

PROVIDER (validated in run-5):
  * opencode.json: local-claude provider uses @ai-sdk/anthropic (was
    @ai-sdk/openai-compatible). The OpenAI-compat adapter dropped
    streaming tool-call args on ~58% of responses — OpenCode saw
    bash({}) schema-errors. The native Anthropic SDK parses the
    proxy's input_json_delta stream correctly. Run-5 confirmed: tool
    args now flow intact (full {command,description} fields observed).
  * apiKey reads {env:LOCAL_ANTHROPIC_API_KEY} (not ANTHROPIC_API_KEY)
    so a shell with a real Anthropic key set cannot leak it to the
    local proxy.
  * .opencode/models/tier-{qwen-med,qwen-large,kimi}.txt point at
    local-claude/claude-{haiku,sonnet,opus}-4-x. These REQUIRE the
    provider block above — committed together to avoid a non-bootable
    intermediate state.

TIER-SELECTOR LOCKDOWN (applied, unvalidated — see below):
  * tier-{qwen-med,qwen-large,kimi}.md: every tool except `task` is
    now denied at the permission-engine level. Run-5 showed an agentic
    model (claude-haiku-4-5) given Read/Grep/Edit/Bash will do the
    implementer work *inside the tier selector*, bypassing
    task-implementor and thrashing against the selector's restrictive
    perms (20+ denials in one Tier 0 cycle; task-implementor never
    spawned). gpt-5-mini honoured the "pure pass-through" prompt;
    Claude-family models do not. The fix makes pass-through
    structural, not prompt-dependent. The 60-line alphabet-kludge
    edit block is also gone.

TASK-IMPLEMENTOR PERMISSION ORDERING (applied, unvalidated):
  * task-implementor.md: edit/write/external_directory rules reordered
    so specific allows precede `*: deny` — the OpenCode permission
    engine evaluates path-perms first-match-wins (confirmed empirically
    from run-4's denial dump; no OpenCode docs exist for this). Path
    globs widened /tmp/* -> /tmp/** since the worktree path is
    multi-segment under /tmp/. This is what was blocking edit/write on
    the dispatcher's pre-cloned worktree.

VALIDATION STATUS: the provider swap is confirmed by run-5 observation.
The two permission changes are UNVALIDATED — run-5 never reached
task-implementor because the tier selector consumed the whole cycle.
The tier-selector lockdown is precisely what unblocks reaching
task-implementor, so the next run validates both at once.

TEST: tests/auto_agents/test_worker_permissions.py gains
TestTierSelectorPassThroughPermissions — 10 tests pinning that all
work-tools are denied, only `task: task-*` is allowed, the bash block
has zero allow rules, and the three selector files stay byte-identical
(they are maintained as a unit; copy-paste drift is the failure mode).
Full suite: 25/25 in test_worker_permissions.py, 1499 passing in
tests/auto_agents/ (3 pre-existing failures in test_pr_comments_cache.py
are a date-rollover time-bomb unrelated to this change).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-14 00:57:11 -04:00

429 lines
17 KiB
JSON

{
"$schema": "https://opencode.ai/config.json",
"permission": "allow",
"instructions": [
".opencode/instructions/*.md"
],
"mcp": {
"context7": {
"type": "local",
"command": [
"npx",
"-y",
"@upstash/context7-mcp"
],
"enabled": true
},
"sequential-thinking": {
"type": "local",
"command": [
"npx",
"@modelcontextprotocol/server-sequential-thinking"
],
"enabled": false
}
},
"provider": {
"anthropic": {
"models": {
"anthropic/claude-opus-4-6": {
"name": "Claude OPUS 4.6",
"limit": {
"context": 200000,
"output": 32768
}
},
"anthropic/claude-haiku-4-5": {
"name": "Claude Haiku 4.5",
"limit": {
"context": 200000,
"output": 32768
}
},
"anthropic/claude-sonnet-4-6": {
"name": "Claude Sonnet 4.6",
"limit": {
"context": 200000,
"output": 32768
}
}
}
},
"local-claude": {
"npm": "@ai-sdk/anthropic",
"options": {
"baseURL": "http://127.0.0.1:3456/v1",
"apiKey": "{env:LOCAL_ANTHROPIC_API_KEY}"
},
"models": {
"claude-sonnet-4-6": {
"name": "Claude Sonnet 4.6 (local proxy)",
"limit": {
"context": 200000,
"output": 32768
},
"tools": true
},
"claude-opus-4-6": {
"name": "Claude Opus 4.6 (local proxy)",
"limit": {
"context": 1000000,
"output": 32768
},
"tools": true
},
"claude-haiku-4-5": {
"name": "Claude Haiku 4.5 (local proxy)",
"limit": {
"context": 200000,
"output": 32768
},
"tools": true
}
}
},
"CleverThis": {
"npm": "@ai-sdk/openai-compatible",
"options": {
"baseURL": "https://ke5ntcikhnj2clcp.us-east-1.aws.endpoints.huggingface.cloud/v1",
"apiKey": "{env:HF_TOKEN}",
"headers": {
"X-HF-Bill-To": "CleverThis",
"Authorization": "Bearer {env:HF_TOKEN}"
}
},
"models": {
"Qwen3-6-35B-A3B-GGUF-BF16": {
"name": "Qwen 3.6 35b A3B GGUF BF16 (Thinking)",
"tools": true
}
}
},
"CleverThis-2": {
"npm": "@ai-sdk/openai-compatible",
"options": {
"baseURL": "https://bqdgwv2uzjgianhe.us-east-2.aws.endpoints.huggingface.cloud/v1",
"apiKey": "{env:HF_TOKEN}",
"headers": {
"X-HF-Bill-To": "CleverThis",
"Authorization": "Bearer {env:HF_TOKEN}"
}
},
"models": {
"MiniMax-M2-7-GGUF-BF16": {
"name": "MiniMax M2.7 GGUF BF16 (Thinking)",
"limit": {
"context": 196608,
"output": 65536
},
"tools": true
}
}
},
"CleverThis-3": {
"npm": "@ai-sdk/openai-compatible",
"options": {
"baseURL": "https://jve0bsgx6csdzln9.us-east-1.aws.endpoints.huggingface.cloud/v1",
"apiKey": "{env:HF_TOKEN}",
"headers": {
"X-HF-Bill-To": "CleverThis",
"Authorization": "Bearer {env:HF_TOKEN}"
}
},
"models": {
"Devstral-Small-2-24B-Instruct-GGUF": {
"name": "Devstral Small 2 24B GGUF (Instruct)",
"tools": true
}
}
},
"CleverThis-4": {
"npm": "@ai-sdk/openai-compatible",
"options": {
"baseURL": "https://ntgtpdbn2vuag4yb.us-east-2.aws.endpoints.huggingface.cloud/v1",
"apiKey": "{env:HF_TOKEN}",
"headers": {
"X-HF-Bill-To": "CleverThis",
"Authorization": "Bearer {env:HF_TOKEN}"
}
},
"models": {
"Kimi-K2-6-GGUF-Q2-K-XL": {
"name": "Kimi K2.6 GGUF Q2_K_XL (Thinking)",
"tools": true
}
}
},
"CleverThis-5": {
"npm": "@ai-sdk/openai-compatible",
"options": {
"baseURL": "https://fhe4kwehnm1rb275.us-east-1.aws.endpoints.huggingface.cloud/v1",
"apiKey": "{env:HF_TOKEN}",
"headers": {
"X-HF-Bill-To": "CleverThis",
"Authorization": "Bearer {env:HF_TOKEN}"
}
},
"models": {
"Qwen3-Coder-Next-GGUF-BF16": {
"name": "Qwen3 Coder Next GGUF BF16",
"tools": true
}
}
},
"CleverThis-6": {
"npm": "@ai-sdk/openai-compatible",
"options": {
"baseURL": "https://f0oelboag4bzw1zp.us-east-1.aws.endpoints.huggingface.cloud/v1",
"apiKey": "{env:HF_TOKEN}",
"headers": {
"X-HF-Bill-To": "CleverThis",
"Authorization": "Bearer {env:HF_TOKEN}"
}
},
"models": {
"Nemotron-3-Nano-30B-GGUF-Q8-K-XL": {
"name": "Nemotron 3 Nano 30B GGUF Q8_K_XL (Thinking)",
"tools": true
}
}
},
"CleverThis-7": {
"npm": "@ai-sdk/openai-compatible",
"options": {
"baseURL": "https://dfwwzwtekzhnh4fl.us-east-2.aws.endpoints.huggingface.cloud/v1",
"apiKey": "{env:HF_TOKEN}",
"headers": {
"X-HF-Bill-To": "CleverThis",
"Authorization": "Bearer {env:HF_TOKEN}"
}
},
"models": {
"DavidAU/Qwen3.6-40B-Claude-4.6-Opus-Deckard-Heretic-Uncensored-Thinking": {
"name": "Qwen 3.6 40B Uncensored BF16 (Thinking)",
"tools": true
}
}
},
"CleverThis-8": {
"npm": "@ai-sdk/openai-compatible",
"options": {
"baseURL": "https://ki19d58snp1d3qa4.us-east-1.aws.endpoints.huggingface.cloud/v1",
"apiKey": "{env:HF_TOKEN}",
"headers": {
"X-HF-Bill-To": "CleverThis",
"Authorization": "Bearer {env:HF_TOKEN}"
}
},
"models": {
"Qwen3-Coder-Next-GGUF-Q4-0": {
"name": "Qwen3 Coder Next GGUF Q4_0",
"tools": true
}
}
},
"CleverThis-9": {
"npm": "@ai-sdk/openai-compatible",
"options": {
"baseURL": "https://m56026p5kxvout0d.us-east-1.aws.endpoints.huggingface.cloud/v1",
"apiKey": "{env:HF_TOKEN}",
"headers": {
"X-HF-Bill-To": "CleverThis",
"Authorization": "Bearer {env:HF_TOKEN}"
}
},
"models": {
"Qwen3-6-35B-A3B-GGUF-MXFP4-MOE": {
"name": "Qwen 3.6 35b A3B GGUF MXFP4_MOE (Thinking)",
"tools": true
}
}
},
"CleverThis-10": {
"npm": "@ai-sdk/openai-compatible",
"options": {
"baseURL": "https://dirv1cnem5wqzoax.us-east-1.aws.endpoints.huggingface.cloud/v1",
"apiKey": "{env:HF_TOKEN}",
"headers": {
"X-HF-Bill-To": "CleverThis",
"Authorization": "Bearer {env:HF_TOKEN}"
}
},
"models": {
"Qwen3-235B-A22B-INST-GGUF-Q8-0": {
"name": "Qwen3 235b A22B GGUF Q8_0 (Instruct)",
"tools": true
}
}
},
"CleverThis-11": {
"npm": "@ai-sdk/openai-compatible",
"options": {
"baseURL": "https://hueiyrdbly1ff4oo.us-east-1.aws.endpoints.huggingface.cloud/v1",
"apiKey": "{env:HF_TOKEN}",
"headers": {
"X-HF-Bill-To": "CleverThis",
"Authorization": "Bearer {env:HF_TOKEN}"
}
},
"models": {
"Qwen3-235B-A22B-INST-GGUF-UD-Q2-K-XL": {
"name": "Qwen3 235b A22B GGUF UD-Q2_K_XL (Instruct)",
"tools": true
}
}
},
"CleverThis-12": {
"npm": "@ai-sdk/openai-compatible",
"options": {
"baseURL": "https://atocunu78hjdnu3f.us-east-1.aws.endpoints.huggingface.cloud/v1",
"apiKey": "{env:HF_TOKEN}",
"headers": {
"X-HF-Bill-To": "CleverThis",
"Authorization": "Bearer {env:HF_TOKEN}"
}
},
"models": {
"Qwen3-30B-A3B-INST-GGUF-UD-Q8-K-XL": {
"name": "Qwen3 30b A3B GGUF UD-Q8_K_XL (Instruct)",
"tools": true
}
}
},
"CleverThis-13": {
"npm": "@ai-sdk/openai-compatible",
"options": {
"baseURL": "https://dpe3orf5en4581im.us-east-1.aws.endpoints.huggingface.cloud/v1",
"apiKey": "{env:HF_TOKEN}",
"headers": {
"X-HF-Bill-To": "CleverThis",
"Authorization": "Bearer {env:HF_TOKEN}"
}
},
"models": {
"Qwen3-30B-A3B-INST-GGUF-UD-Q5-K-XL": {
"name": "Qwen3 30b A3B GGUF UD-Q5_K_XL (Instruct)",
"tools": true
}
}
},
"CleverThis-14": {
"npm": "@ai-sdk/openai-compatible",
"options": {
"baseURL": "https://jamyigykfzm39bcu.us-east-1.aws.endpoints.huggingface.cloud/v1",
"apiKey": "{env:HF_TOKEN}",
"headers": {
"X-HF-Bill-To": "CleverThis",
"Authorization": "Bearer {env:HF_TOKEN}"
}
},
"models": {
"MiniMax-M2-7-GGUF-UD-Q4-K-XL": {
"name": "MiniMax M2.7 GGUF UD-Q4_K_XL (Thinking)",
"tools": true
}
}
},
"CleverThis-15": {
"npm": "@ai-sdk/openai-compatible",
"options": {
"baseURL": "https://n4u4h8h0fgintms4.us-east-1.aws.endpoints.huggingface.cloud/v1",
"apiKey": "{env:HF_TOKEN}",
"headers": {
"X-HF-Bill-To": "CleverThis",
"Authorization": "Bearer {env:HF_TOKEN}"
}
},
"models": {
"Qwen3-6-35B-A3B-GGUF-UD-Q3-K-XL": {
"name": "Qwen 3.6 35b A3B GGUF UD-Q3_K_XL (Thinking)",
"tools": true
}
}
},
"CleverThis-16": {
"npm": "@ai-sdk/openai-compatible",
"options": {
"baseURL": "https://kcgeda25msp4dkwm.us-east-2.aws.endpoints.huggingface.cloud/v1",
"apiKey": "{env:HF_TOKEN}",
"headers": {
"X-HF-Bill-To": "CleverThis",
"Authorization": "Bearer {env:HF_TOKEN}"
}
},
"models": {
"Qwen3-code-480B-A35B-INST-GGUF-1M-UD-Q3-K-XL": {
"name": "Qwen3 Code 480b A35B GGUF UD-Q3_K_XL (Instruct, 1M Context)",
"tools": true
}
}
},
"openai": {
"models": {
"gpt-5-codex": {
"name": "GPT-5 Codex"
},
"gpt-5-mini": {
"name": "GPT-5 Mini"
},
"gpt-5-nano": {
"name": "GPT-5 Nano"
},
"o4-mini": {
"name": "o4-mini"
}
}
},
"google": {
"models": {
"gemini-2.5-pro": {
"name": "Gemini 2.5 Pro"
}
}
}
},
"agent": {
"async-agent-util": { "model": "{file:./.opencode/models/default.txt}" },
"auto-agents": { "model": "{file:./.opencode/models/default.txt}" },
"conflict-resolver-worker": { "model": "{file:./.opencode/models/default.txt}" },
"estimator-implementation": { "model": "{file:./.opencode/models/default.txt}" },
"git-checkout-util": { "model": "{file:./.opencode/models/default.txt}" },
"git-cleanup-util": { "model": "{file:./.opencode/models/default.txt}" },
"git-clone-util": { "model": "{file:./.opencode/models/default.txt}" },
"git-commit-and-push-util": { "model": "{file:./.opencode/models/default.txt}" },
"git-commit-util": { "model": "{file:./.opencode/models/default.txt}" },
"git-create-commit-util": { "model": "{file:./.opencode/models/default.txt}" },
"git-fetch-util": { "model": "{file:./.opencode/models/default.txt}" },
"git-force-push-with-lease-util": { "model": "{file:./.opencode/models/default.txt}" },
"git-isolator-util": { "model": "{file:./.opencode/models/default.txt}" },
"git-push-util": { "model": "{file:./.opencode/models/default.txt}" },
"git-rebase-and-push-util": { "model": "{file:./.opencode/models/default.txt}" },
"git-rebase-util": { "model": "{file:./.opencode/models/default.txt}" },
"git-stage-util": { "model": "{file:./.opencode/models/default.txt}" },
"implementation-worker": { "model": "{file:./.opencode/models/default.txt}" },
"pr-merge-supervisor": { "model": "{file:./.opencode/models/default.txt}" },
"pr-merge-worker": { "model": "{file:./.opencode/models/default.txt}" },
"pr-review-worker": { "model": "{file:./.opencode/models/default.txt}" },
"session-health-full-util": { "model": "{file:./.opencode/models/default.txt}" },
"session-health-quick-util": { "model": "{file:./.opencode/models/default.txt}" },
"session-health-util": { "model": "{file:./.opencode/models/default.txt}" },
"supervisor": { "model": "{file:./.opencode/models/default.txt}" },
"tier-dispatcher": { "model": "{file:./.opencode/models/default.txt}" },
"work-group-util": { "model": "{file:./.opencode/models/default.txt}" },
"tier-qwen-small": { "model": "{file:./.opencode/models/tier-qwen-small.txt}" },
"tier-qwen-med": { "model": "{file:./.opencode/models/tier-qwen-med.txt}" },
"tier-qwen-large": { "model": "{file:./.opencode/models/tier-qwen-large.txt}" },
"tier-kimi": { "model": "{file:./.opencode/models/tier-kimi.txt}" },
"tier-haiku": { "model": "{file:./.opencode/models/tier-haiku.txt}" },
"tier-sonnet": { "model": "{file:./.opencode/models/tier-sonnet.txt}" },
"tier-opus": { "model": "{file:./.opencode/models/tier-opus.txt}" },
"tier-codex": { "model": "{file:./.opencode/models/tier-codex.txt}" },
"tier-gpt5-mini": { "model": "{file:./.opencode/models/tier-gpt5-mini.txt}" },
"tier-gpt5-nano": { "model": "{file:./.opencode/models/tier-gpt5-nano.txt}" },
"tier-o4-mini": { "model": "{file:./.opencode/models/tier-o4-mini.txt}" },
"ca-test-infra-improver": { "model": "{file:./.opencode/models/ca-test-infra-improver.txt}" }
}
}