{"id":50064372,"url":"https://github.com/nddev-it-com/rldyour-opencode","last_synced_at":"2026-05-30T13:00:42.609Z","repository":{"id":358636989,"uuid":"1237314465","full_name":"NDDev-it-com/rldyour-opencode","owner":"NDDev-it-com","description":"rldyour AI CLI configuration for OpenCode: local plugins, MCP/LSP, permissions, commands, agents, browser/design workflows, and security review.","archived":false,"fork":false,"pushed_at":"2026-05-29T04:13:28.000Z","size":1831,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-05-29T06:12:27.977Z","etag":null,"topics":["agpl-3","ai-agents","ai-cli","browser-automation","commands","design-system","developer-tools","local-plugins","lsp","mcp","model-context-protocol","nddev","opencode","opencode-ai","permissions","rldyour","sdlc","security-tools","serena"],"latest_commit_sha":null,"homepage":"https://github.com/NDDev-it-com/rldyour-opencode","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"agpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/NDDev-it-com.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":"NOTICE","maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-05-13T04:23:29.000Z","updated_at":"2026-05-28T20:15:54.000Z","dependencies_parsed_at":null,"dependency_job_id":"0df3803e-af1d-40d4-8b3f-9b679b178104","html_url":"https://github.com/NDDev-it-com/rldyour-opencode","commit_stats":null,"previous_names":["nddev-it-com/rldyour-opencode"],"tags_count":31,"template":false,"template_full_name":null,"purl":"pkg:github/NDDev-it-com/rldyour-opencode","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/NDDev-it-com%2Frldyour-opencode","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/NDDev-it-com%2Frldyour-opencode/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/NDDev-it-com%2Frldyour-opencode/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/NDDev-it-com%2Frldyour-opencode/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/NDDev-it-com","download_url":"https://codeload.github.com/NDDev-it-com/rldyour-opencode/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/NDDev-it-com%2Frldyour-opencode/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":33692997,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-05-30T02:00:06.278Z","response_time":92,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["agpl-3","ai-agents","ai-cli","browser-automation","commands","design-system","developer-tools","local-plugins","lsp","mcp","model-context-protocol","nddev","opencode","opencode-ai","permissions","rldyour","sdlc","security-tools","serena"],"created_at":"2026-05-21T22:00:27.069Z","updated_at":"2026-05-30T13:00:42.601Z","avatar_url":"https://github.com/NDDev-it-com.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"# rldyour-opencode\n\nrldyour AI CLI configuration for OpenCode: local plugins, MCP/LSP, permissions, commands, agents, browser/design workflows, and security review. Authored by Danil Silantyev (github:rldyourmnd), CEO NDDev. Russian-first SDLC workflow, Serena integration, MCP transport, code review, design, security, LSP, and engineering rules -- all native to the OpenCode AI coding agent format (no Claude Code or Codex residue).\n\nValidated against OpenCode, `@opencode-ai/plugin`, and `@opencode-ai/sdk` 1.15.12 (May 2026); the OpenCode v1.14.48 -\u003e v1.15.12 plugin pin bumps preserve the runtime hook surface and tool-ID naming while picking up current plugin-loading, config-robustness, and ACP/WebSocket runtime fixes.\n\n## What This Is\n\nA self-contained OpenCode project configuration that provides:\n\n- **33 skills** for automatic workflow routing across 10 domains (SDLC, Serena, rules, explore, browser, design, security, LSP, docs sync, config).\n- **9 subagents** for specialized tasks (6 reviewer tracks, memory sync, deep research, config helper).\n- **10 slash commands** for lifecycle orchestration:\n  - `/ry-init`, `/ry-start`, `/ry-review`, `/ry-repair`, `/ry-newp`, `/ry-deploy`, `/ry-sync`\n  - `/ry-design`, `/ry-explore`, `/ry-sec-review`, `/ry-rules-review`\n- **13 MCP servers** pre-configured (Serena, Sequential Thinking, Playwright, Chrome DevTools, Context7, DeepWiki, Grep, Semgrep, shadcn, dart-flutter, Figma, GitHub, OpenAI docs).\n- **10 TypeScript plugins** for session lifecycle, LLM augmentation, guardrails, and observability:\n  - lifecycle: `ry-bootstrap` (session banner + compaction context + autocontinue), `ry-env-protection` (block sensitive reads with toast), `ry-shell-strategy` (shell env + git push guardrails), `ry-sync-reminder` (idle toast), `ry-flow-hooks` (commit advice + post-commit nudge)\n  - LLM-side: `ry-tools` (5 custom diagnostic tools the LLM can call), `ry-command-audit` (credential-sanitized slash-command audit log), `ry-tool-hints` (routing nudges injected into MCP tool descriptions)\n  - Runtime context + permission events: `ry-system-context` (date + branch + HEAD SHA + dirty state injected into every system prompt), `ry-permission-events` (observability-only `permission.asked` / `permission.replied` event audit)\n- **8 custom LSP servers** on top of OpenCode's 35+ built-ins (ruff, vscode-html, vscode-css, vscode-json, docker, taplo, marksman, qmlls).\n- **Owner-standard full-auto permissions** by default: primary agents allow read/edit/bash/web/LSP/skill/task/external-directory/doom-loop actions without prompts; reviewer subagents are read-only with git-only bash allowlists, and deterministic `tool.execute.before` guardrails still block the repository's high-impact dangerous shell patterns.\n- **Release-safe overlay**: `opencode.release-safe.json` keeps native static read-deny patterns for `.env`, private keys, tokens, credentials, and shell/edit ask posture for public OSS examples and conservative installs. The owner `opencode.json` remains the local YOLO profile.\n\n## Quick Start\n\n1. Clone this repository:\n   ```bash\n   git clone https://github.com/NDDev-it-com/rldyour-opencode.git\n   cd rldyour-opencode\n   ```\n\n2. Copy the configuration into your project:\n   ```bash\n   cp opencode.json /path/to/your/project/opencode.json\n   cp -r .opencode /path/to/your/project/.opencode\n   cp AGENTS.md /path/to/your/project/AGENTS.md\n   ```\n\n3. Authenticate the primary OpenCode provider via TUI (recommended) or env vars:\n   ```bash\n   # primary provider for top-level model `opencode-go/glm-5.1` — log in interactively\n   opencode auth login          # or use /providers inside the TUI\n\n   # MCP env vars (placeholder values — replace with real credentials in your shell or .env)\n   export GITHUB_PERSONAL_ACCESS_TOKEN=YOUR_PLACEHOLDER_TOKEN  # required for GitHub MCP\n   export CONTEXT7_API_KEY=YOUR_PLACEHOLDER_KEY               # optional, higher Context7 rate\n\n   # Alternative OpenCode providers (optional — only when switching the top-level model)\n   # export ANTHROPIC_API_KEY=YOUR_PLACEHOLDER_KEY\n   # export OPENAI_API_KEY=YOUR_PLACEHOLDER_KEY\n   ```\n\n4. Run OpenCode in your project:\n   ```bash\n   cd /path/to/your/project\n   opencode\n   ```\n\n5. Initialize project context:\n   ```\n   /ry-init\n   ```\n\n## Catalog\n\n| Layer | Where | Count |\n|---|---|---|\n| Master config | `opencode.json` | 1 |\n| Cross-tool instructions | `AGENTS.md` | 1 |\n| Claude Code project memory (agent-only) | `.claude/CLAUDE.md` | 1 |\n| Subagents | `.opencode/agents/*.md` | 9 |\n| Skills | `.opencode/skills/\u003cname\u003e/SKILL.md` | 33 |\n| Slash commands | `.opencode/commands/*.md` | 11 |\n| Plugins | `.opencode/plugins/*.ts` | 10 |\n| Custom diagnostic tools | `.opencode/plugins/ry-tools.ts` | 5 |\n| MCP servers | `opencode.json` → `mcp` | 13 |\n| Custom LSP servers | `opencode.json` → `lsp` | 8 |\n| Reference docs (skill/agent contracts + machine contracts) | `references/*` | 22 |\n| Operator guides | `docs/*.md` | 5 (`release-process`, `dependency-updates`, `rollback-restore`, `observability`, `contract-matrix`) |\n| Architecture decision archive | `docs/decisions/*.md` | 10 |\n| Diagnostic scripts (bash + python) | `scripts/` | 30 (17 python files + 13 bash entry points, including `check_plugin_hooks.py` and `validate_contract.py`) |\n| Pytest suites | `scripts/tests/*.py` | 26 (includes plugin hook and adapter contract validators, public-repo CI/CD automation policy, and the release-baseline changelog regression) |\n| CI workflows | `.github/workflows/*.yml` | 11 (`validate`, `dependency-check`, `instruction-docs-check`, `typecheck-plugins`, `lint`, `codeql`, `secret-scan`, `dependency-review`, `release`, `sbom`, `opencode-runtime`) |\n\n### Project structure\n\n```\nrldyour-opencode/\n├── AGENTS.md                   # cross-tool root instructions\n├── opencode.json               # master OpenCode config (model, MCP, LSP, agent, watcher, compaction)\n├── VERSION, CHANGELOG.md\n├── README.md, LICENSE, .env.example\n├── pyrightconfig.json          # Python static type config for scripts/\n├── .claude/CLAUDE.md           # Claude-Code-specific project memory (agent-only)\n├── .opencode/\n│   ├── agents/   *.md          # 9 subagents (6 reviewer, memory-sync, ry-explore, customize-opencode)\n│   ├── skills/   \u003cname\u003e/SKILL.md  # 33 skills across 10 domains\n│   ├── commands/ *.md          # 10 slash commands\n│   ├── plugins/  *.ts          # 10 Bun-runtime plugins\n│   └── package.json            # @opencode-ai/plugin pin\n├── .serena/\n│   ├── memories/  *.md         # 6 verified knowledge files (AREA-NN-SLUG.md taxonomy)\n│   └── project.yml             # Serena project config\n├── references/   *             # durable contracts + machine-readable adapter metadata\n├── docs/\n│   ├── release-process.md, dependency-updates.md, rollback-restore.md, observability.md, contract-matrix.md\n│   └── decisions/  001..010.md # 10 MADR-style ADRs\n├── scripts/                    # 30 bash + python diagnostic / validation / smoke scripts\n│   └── tests/  *.py            # 26 pytest suites\n└── .github/workflows/          # 11 least-privilege, SHA-pinned CI/release workflows\n```\n\n## Commands\n\n| Command | Agent | Purpose |\n|---|---|---|\n| `/ry-init` | `build` | Scoped read-only project context with Serena-first discovery |\n| `/ry-start` | `build` | Full task lifecycle: init → research → plan → implement → verify → sync; review only by explicit request |\n| `/ry-review` | `plan` | Report-only deep review with parallel reviewer subagents |\n| `/ry-repair` | `build` | Repair stale docs, memories, contracts, hooks, MCP/LSP config, CI, and AI-tool context |\n| `/ry-newp` | `build` | Plan a new project (skeptical questions, research, ADRs, architecture docs) |\n| `/ry-deploy` | `build` | Deploy with sync, log checks, fix-forward |\n| `/ry-sync` | `build` | Synchronize memories, docs, git, and fullrepo |\n| `/ry-design` | `build` | End-to-end design: Figma → tokens → FSD → shadcn/ui → browser validation |\n| `/ry-explore` | `ry-explore` (subtask) | Deep multi-source research via Context7 / DeepWiki / Grep / web |\n| `/ry-sec-review` | `plan` | Defensive Mythos-style security review |\n| `/ry-rules-review` | `plan` | Audit implementation against rldyour rules (report-only) |\n\n`build` remains the implementation agent, and its repository configuration uses\nowner-standard full-auto permissions for OpenCode's canonical v1.15.x keys,\nincluding `read`, `edit`, `bash`, `task`, `external_directory`, and\n`doom_loop`. The `plan` primary agent uses the same full-auto baseline. The\nroot owner `oc` launcher mirrors that no-prompt posture through\n`OPENCODE_CONFIG_CONTENT` for the trusted workstation.\nReviewer subagents remain stricter (`edit: \"deny\"`, git-only read bash\nallowlists) because their role contract is report-only review, not\nimplementation.\n\n## Reviewer Subagents\n\nAll reviewer tracks are `mode: subagent`, `hidden: true`, `edit: deny`, with `bash` allowlist limited to read-only git verbs. Invoke directly via `@\u003cname\u003e` or transitively via `/ry-review`; `/ry-start` only routes them when the user explicitly asks for review, audit, security review, or rules review.\n\n| Agent | Color | Focus |\n|---|---|---|\n| `@flow-architecture-review` | `#3b82f6` | Boundaries, dependency direction, public API, data flow |\n| `@flow-quality-review` | `success` | Correctness, edge cases, error handling, resource lifecycle |\n| `@flow-consistency-review` | `#a855f7` | Naming, style, imports, project conventions |\n| `@flow-integration-review` | `warning` | Cross-module contracts, schemas, configs, backward compatibility |\n| `@flow-verification-review` | `#ec4899` | Tests, quality gates, browser/server evidence |\n| `@flow-security-review` | `error` | OWASP Top 10, auth/authz, injection, secrets (defensive-only) |\n| `@flow-memory-sync` | `#eab308` | Fact-only Serena memory synchronization |\n| `@ry-explore` | `info` | Deep multi-source research (90 reasoning steps; inherits top-level `model`) |\n| `@customize-opencode` | `accent` | Safely edit `opencode.json` with validation, backup, rollback |\n\n## MCP Servers\n\nLocal servers timeout 30 s, remote 15 s. Launcher convention: `bunx` for npm, `uvx` for Python, `dart` for Dart SDK — never `npx`.\n\n| Server | Type | Version | Purpose |\n|---|---|---|---|\n| serena | local (uvx) | 1.5.3 | Semantic code navigation, analysis, editing |\n| sequential-thinking | local (bunx) | 2025.12.18 | Structured reasoning |\n| playwright | local (bunx) | 0.0.75 | Browser automation, UI validation |\n| chrome-devtools | local (bunx) | 1.1.1 | Chrome DevTools diagnostics |\n| semgrep | local (uvx) | 1.164.0 | Static analysis and security |\n| shadcn | local (bunx) | 4.8.2 | shadcn/ui registry access |\n| dart-flutter | local (dart) | — | Dart/Flutter project support |\n| context7 | remote | — | Current library documentation |\n| deepwiki | remote | — | Repository documentation |\n| grep | remote | — | Search across public GitHub repos |\n| figma | remote | — | Figma design context |\n| github | remote | toolsets: context,repos,issues,pull_requests,users | GitHub Copilot MCP (requires PAT) |\n| openai-docs | remote | — | Official OpenAI/Codex documentation |\n\n## Models\n\nThe marketplace ships with `opencode-go/glm-5.1` as the top-level default — owner's working provider. Subagents inherit this model (no per-agent override at HEAD). Switch any field to a different provider via `provider/model-id` format.\n\nVersioning note: root `VERSION` is the marketplace/product release version.\n`.opencode/package.json.version` is a private local plugin package version for\nBun dependency resolution and intentionally does not mirror root `VERSION`.\n\n| Slot | Default in this repo | Common Anthropic alternative |\n|---|---|---|\n| `model` (primary) | `opencode-go/glm-5.1` | `anthropic/claude-sonnet-4-6` |\n| `small_model` | `opencode-go/glm-5.1` | `anthropic/claude-haiku-4-5-20251001` |\n| `default_agent` | `build` | `build` |\n| Reviewer / memory-sync / explore subagents | inherit top-level `model` | inherit top-level `model` |\n\nTo switch:\n\n```bash\nopencode auth login                            # authenticate with the new provider\n# edit opencode.json:  \"model\": \"anthropic/claude-sonnet-4-6\"\nopencode debug config | grep -E '\"model\":'     # confirm runtime resolved the change\n```\n\nRun `opencode models \u003cprovider\u003e` to list every accepted ID. All current IDs are validated by `opencode debug config` (the same runtime smoke `scripts/validate_config.sh` invokes when the CLI is on PATH).\n\n## Validation\n\n```bash\nbash scripts/validate_config.sh                            # JSON shape + skill/agent/command frontmatter (strict YAML) + VERSION semver\nuvx --from \"pytest==9.0.3\" --with \"pyyaml==6.0.3\" --with \"jsonschema==4.26.0\" --with \"referencing==0.36.2\" pytest scripts/tests/\nbash scripts/check_deps_freshness.sh --check-freshness     # list pinned MCP dependencies + npm/PyPI freshness\npython3 scripts/check_action_pins.py .github/workflows --remote  # verify SHA-pinned GitHub Actions comments\npython3 scripts/check_plugin_hooks.py                      # verify plugin hook contract; forbids permission.ask as enforcement\npython3 scripts/validate_contract.py                       # verify canonical rldyour adapter contract\npython3 scripts/smoke_mcp_capabilities.py                  # probe every MCP server for reachability\npython3 scripts/validate_instruction_docs.py               # verify AGENTS.md + .claude/CLAUDE.md anchor headings\nbash scripts/doctor_opencode.sh                            # full diagnostics: MCP, LSP binaries, agent/skill/command discovery, git\nbash scripts/check_lsps.sh                                 # 16 language servers + project prereqs\nbash scripts/collect_diagnostics.sh --include-doctor       # local timestamped diagnostic bundle for triage\nopencode debug config                                      # native resolved config (authoritative)\nopencode debug agent \u003cname\u003e                                # validate individual agent\nopencode models anthropic                                  # list available models for the active provider\n```\n\nPublic repositories use automatic CI/CD by default. `opencode.json` loads\n`references/public-repo-ci-policy.md` through `instructions`; keep\n`share: \"manual\"` unchanged because it controls OpenCode session sharing, not\nGitHub Actions execution.\n\nCI mirrors the core checks via `.github/workflows/validate.yml` on every push/PR to `main`. `.github/workflows/dependency-check.yml` runs weekly to surface MCP pin freshness via `GITHUB_STEP_SUMMARY`.\n\nSee `docs/observability.md` for full triage flow.\n\n## Convention\n\n- User-facing communication: **Russian** by default.\n- Repository artifacts (docs, prompts, scripts, commits, memories): **English**.\n- Identifiers: ASCII, kebab-case.\n- Commits: Conventional Commits v1.0.0; atomic per logical unit.\n- Versioning: SemVer; CHANGELOG follows Keep a Changelog 1.1.0.\n- Ignored agent-only files (`AGENTS.md`, `.claude/CLAUDE.md`, `.serena/memories/*`, etc.) are overlaid onto the current `HEAD` tree and published via the generated `fullrepo` branch managed by `scripts/fullrepo_sync.sh`.\n\n## License\n\nAGPL-3.0-or-later\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fnddev-it-com%2Frldyour-opencode","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fnddev-it-com%2Frldyour-opencode","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fnddev-it-com%2Frldyour-opencode/lists"}