OpenCode Tools

OpenCode's core capabilities come not only from the large model itself, but also from thetools it can invoke。

The essence of tools: turning LLM from being able to talk to being able to do things.

Tools = OpenCode's execution capability, while permissions = security boundaries.


1. What are Tools

Tools are the capability interfaces for LLM to perform operations in a project, for example:

  • Reading code
  • Modifying files
  • Executing commands
  • Searching code
  • Accessing the network

Without tools: can only generate code

With tools: candirectly manipulate the project


2. Tool Permission Control (Most Important)

By default:

  • All tools are enabled
  • And can be executed without confirmation

Production environments must configure permissions!

1. Basic Permission Configuration

{
  "$schema": "https://opencode.ai/config.json",
  "permission": {
    "edit": "deny",
    "bash": "ask",
    "webfetch": "allow"
  }
}
Permission Value Description
allow Allow direct execution
deny Completely prohibited
ask Requires manual confirmation before execution

2. Wildcard Control

You can control tools in batches:

{
  "permission": {
    "mymcp_*": "ask"
  }
}

All tools from MCP require approval


3. Built-in Tools Explained

OpenCode comes with a complete set of engineering-grade tools:

1. bash (Command Execution)

{
  "permission": {
    "bash": "allow"
  }
}

Purpose:

  • Execute shell commands
  • Such as npm install, git status

Risk:High (recommended to set to ask)

2. edit (Core Tool)

{
  "permission": {
    "edit": "allow"
  }
}

Purpose:

  • Modify existing files
  • Based on precise text replacement

Note:This is the core capability for AI to modify code

3. write (File Creation)

Purpose:

  • Create new files
  • Overwrite existing files

Note:

write is controlled by the edit permission

4. read (Read File)

{
  "permission": {
    "read": "allow"
  }
}

Purpose:

  • Read code files
  • Supports reading line by line

Risk:Low (recommended to always allow)

5. grep (Content Search)

{
  "permission": {
    "grep": "allow"
  }
}

Purpose:

  • Search code with regular expressions

6. glob (File Matching)

Purpose:

  • Find file paths (e.g., src/**/*.ts)

7. list (Directory Browsing)

Purpose:

  • List directory structure

8. patch (Patch Application)

Purpose:

  • Apply diff patches

Note:Controlled by the edit permission

9. lsp (Experimental)

Purpose:

  • Intelligent code analysis (jump to definition, find references)

How to enable:

OPENCODE_EXPERIMENTAL_LSP_TOOL=true

10. skill (Skill Loading)

Purpose:

  • Load SKILL.md
  • Enhance AI behavior

11. todowrite (Task Management)

Purpose:

  • Maintain task lists
  • Track complex workflows

12. webfetch (Web Page Reading)

Purpose:

  • Fetch content from a specified URL

13. websearch (Online Search)

How to enable:

OPENCODE_ENABLE_EXA=1 opencode

Purpose:

  • Search internet information

Difference:

  • websearch: find information (discovery)
  • webfetch: read content (fetching)

14. question (Interactive Questioning)

Purpose:

  • Ask the user questions
  • Collect requirements

Suitable for:

  • Unclear requirements
  • When user decisions are needed

4. Custom Tools

You can define your own tools to let AI execute custom logic.

For example:

  • Calling internal APIs
  • Operating databases
  • Executing business logic

Essence:Letting the LLM call functions


5. MCP Servers (Advanced Capabilities)

MCP (Model Context Protocol) allows you to connect external systems:

  • Databases
  • Third-party APIs
  • Internal services

This is equivalent to connecting "external capabilities" to AI


6. Underlying Mechanism (Important)

OpenCode uses ripgrep as its search engine:

  • Follows .gitignore
  • Ignores directories like node_modules by default

How to Override Ignore Rules

Create a file:

.ignore

Example:

!node_modules/
!dist/
!build/

Forcefully include these directories


7. Best Practices (Highly Recommended)

  • read / grep / glob → allow
  • edit → ask (development phase)
  • bash → ask (production environment)
  • webfetch → allow

Core principles:

  • Reading can be open
  • Modifications must be controlled
  • Be cautious with command execution
Other Extensions