oy is not a sandbox. It adds a coding agent and repository review workflows to OpenCode.
OpenCode and the user control models, provider credentials, permissions, edits, shell commands, web access, and sessions. The oy plugin does not add permission overrides.
The oy CLI can:
- read eligible files inside the selected workspace;
- run read-only Git commands for target-diff reviews;
- write
.oy/runs/evidence, reports, and private workflow metadata; - update OpenCode configuration during explicit setup or upgrade;
- launch OpenCode and optional mise-managed installers.
Prepared source text may be sent to the model provider configured in OpenCode. Treat prompts, reports, OpenCode logs/sessions, and setup backups as potentially sensitive.
- Review
docs/install.shbefore piping it to a shell. - Run
oy setup --dry-runbefore changing an existing OpenCode configuration. - Configure OpenCode permissions for the repository you are reviewing.
- Use a disposable container or VM for untrusted repositories.
- Do not mount the host Docker socket into an AI-assisted container.
- Do not keep secrets under the workspace root solely because secret-like filenames are excluded from collection.
- Inspect generated findings before publishing or uploading them.
Setup backs up changed oy-owned configuration and files before replacing them. A machine crash can still interrupt the operation, so keep the reported backup until the new setup is verified.
Open an issue in the public GitHub repository:
https://github.com/adonm/oy-cli/issues/new
Include the affected oy/OpenCode versions, operating system, reproduction steps, impact, and relevant logs. Redact credentials, authorization headers, prompts, private source code, session contents, and local paths that should not be public.