{"contract_version":"1.2.0","rubric_version":"1.0.0","archetype_version":"1.1.0","skill_version":"0.2.0","judge_model":"sonnet","judge_effort":"medium","commit_sha":"3033afba5134c486dc3f8f5ae96c8b653285eeda","filed_at":"2026-07-21T05:38:26.095Z","repo":{"owner":"anomalyco","name":"opencode","default_branch":"dev"},"purpose":{"what_its_for":["terminal-first AI coding agent","multi-provider LLM orchestration","agentic build/plan workflows","companion desktop/web/TUI surfaces"],"purpose_statement":"A CLI-first AI coding agent that lets developers drive an LLM-backed build/plan workflow from the terminal, with desktop, web, and console surfaces layered on top.","audience":"Developers who want an AI pair-programmer driven primarily from the terminal, with optional GUI surfaces.","category_candidates":["ai-coding-agent","terminal-ai-tool","dev-productivity","llm-orchestration","coding-copilot"],"archetype":"cli-tool"},"scores":{"axes":{"concept":{"score":6.5,"grade":"BBB","rationale_ref":"structure"},"usefulness":{"score":8.5,"grade":"AA","rationale_ref":"vitals-readme"},"ergonomics":{"score":6.5,"grade":"BBB","rationale_ref":"vitals-readme"},"maturity":{"score":6,"grade":"BBB","rationale_ref":"test-reality"},"longevity":{"score":7,"grade":"A","rationale_ref":"health-static"},"openness":{"score":5.5,"grade":"BB","rationale_ref":"health-static"},"setup_friction":{"score":9,"grade":"AAA","rationale_ref":"vitals-readme"},"issue_health":{"score":5,"grade":"BB","rationale_ref":"health-static"},"supply_chain":{"score":4,"grade":"B","rationale_ref":"probe-cve"},"hype_substance":{"score":6.5,"grade":"BBB","rationale_ref":"probe-claim-1"}},"rollups":{"dependability":5.6,"craftsmanship":6.4,"docs":7.4,"trust":5.4},"composite":6.7,"grade":"BBB","recommendation":"TRIAL","confidence":"medium"},"summary":{"context_line":"Audited from a 0k-token evidence dossier; 2 files read, 11 probes answered.","intro":["OpenCode is a terminal-first AI coding agent — CLI/TUI core with build and plan agent modes, plus desktop, web, and console surfaces bolted on around it [vitals-readme]. It has scaled fast: 188k stars, daily commits, and roughly monthly-plus release cadence [health-static].","The tension is between how the project ships and how it's reviewed: velocity and install polish are excellent, but the code the dossier could actually read stopped at a test fixture — every real core file exceeded the read budget [coverage-notes] — and the parts that were measured (CVEs, review rate) look thinner than the star count suggests."],"knocks":[{"lead":"The dependency tree carries unresolved critical and high-severity CVEs.","text":"The lockfile scan turns up 2 critical and 46 high-severity CVEs [probe-cve], and the community profile's file list shows no SECURITY.md [health-static] — nothing in the dossier suggests these are engaged or triaged.","refs":["probe-cve","health-static"]},{"lead":"PRs merge with almost no review.","text":"Only 5% of sampled merged PRs had at least one review despite a 45% external-author merge share [health-static], which means a large share of outside contributions land without a second set of eyes — a real risk on a codebase already carrying secrets findings [static digest].","refs":["health-static"]},{"lead":"The evidence base for internal code quality is thin.","text":"The most complex, highest-churn files — provider/transform.ts and provider/provider.ts — were both cut for size [coverage-notes], so the maturity read leans on hotspot metrics and test-reality signal rather than the code itself.","refs":["coverage-notes","health-static"]},{"lead":"Issue and PR timing metrics look automation-driven, not human.","text":"First response is 100% bot on the issue sample and median PR merge time is 0 days [health-static], so the near-zero triage latency likely reflects bots rather than maintainer attention, and the dossier can't distinguish the two.","refs":["health-static"]}],"holds_up":[{"lead":"Install is genuinely frictionless across every platform.","text":"README covers npm/bun/pnpm/yarn, brew, scoop, choco, pacman, nix, and mise, plus explicit install-directory override precedence [vitals-readme], and a beta desktop app ships alongside the CLI with its own package-manager installers.","refs":["vitals-readme"]},{"lead":"The test infrastructure is unusually rigorous for a project this size.","text":"The one complete file the dossier could read in full is a deterministic e2e fixture harness for timeline stability, and a companion benchmark spec measures cold/hot session-switch latency with CDP throttling [test-reality]; the graph-central utility effect.ts is referenced by 337 test files [probe-top-tested].","refs":["test-reality","probe-top-tested"]},{"lead":"The dependency footprint stays lean despite the product's scope.","text":"Only 6 direct dependencies sit behind a committed lockfile [probe-deps], and CI runs 26 workflows including a deploy pipeline that pins third-party actions by commit SHA [manifests-ci] — disciplined supply-chain hygiene even where the CVE scan is not.","refs":["probe-deps","manifests-ci"]},{"lead":"Adoption and shipping cadence are hard to argue with.","text":"188k stars, a commit yesterday, and 100 releases in the last 24 months with 100% release-note coverage [health-static] point to a maintained, actively used project rather than a stalled one.","refs":["health-static"]}],"bottom_line":"A fast-moving, widely adopted AI coding agent whose install polish outpaces its visible supply-chain and review discipline."},"use_cases":{"reach_for_it":["Terminal-first developers who want an AI pair-programmer with build/plan agent modes","Teams that want one install across every major OS and package manager","Users who want a lean, single-binary-style tool with few direct dependencies"],"look_elsewhere":[{"when":"you need a vetted, low-CVE dependency chain for a regulated environment","instead":"a smaller, more conservatively-dependencied CLI agent with an active SECURITY.md and CVE triage record"},{"when":"you want confidence that every merged PR was reviewed by a human","instead":"a project with a visibly higher review-coverage rate on its PR sample"}]},"alternatives_note":"Compare against other terminal-first AI coding agents on install breadth, CVE hygiene, and PR review rate before adopting at scale."}