OpenCode Tools
OpenCode's core capabilities come not only from the large model itself, but also from thetools it can invoke。
The essence of tools: turning LLM from being able to talk to being able to do things.
Tools = OpenCode's execution capability, while permissions = security boundaries.
1. What are Tools
Tools are the capability interfaces for LLM to perform operations in a project, for example:
- Reading code
- Modifying files
- Executing commands
- Searching code
- Accessing the network
Without tools: can only generate code
With tools: candirectly manipulate the project
2. Tool Permission Control (Most Important)
By default:
- All tools are enabled
- And can be executed without confirmation
Production environments must configure permissions!
1. Basic Permission Configuration
{
"$schema": "https://opencode.ai/config.json",
"permission": {
"edit": "deny",
"bash": "ask",
"webfetch": "allow"
}
}
| Permission Value | Description |
|---|---|
| allow | Allow direct execution |
| deny | Completely prohibited |
| ask | Requires manual confirmation before execution |
2. Wildcard Control
You can control tools in batches:
{
"permission": {
"mymcp_*": "ask"
}
}
All tools from MCP require approval
3. Built-in Tools Explained
OpenCode comes with a complete set of engineering-grade tools:
1. bash (Command Execution)
{
"permission": {
"bash": "allow"
}
}
Purpose:
- Execute shell commands
- Such as npm install, git status
Risk:High (recommended to set to ask)
2. edit (Core Tool)
{
"permission": {
"edit": "allow"
}
}
Purpose:
- Modify existing files
- Based on precise text replacement
Note:This is the core capability for AI to modify code
3. write (File Creation)
Purpose:
- Create new files
- Overwrite existing files
Note:
write is controlled by the edit permission
4. read (Read File)
{
"permission": {
"read": "allow"
}
}
Purpose:
- Read code files
- Supports reading line by line
Risk:Low (recommended to always allow)
5. grep (Content Search)
{
"permission": {
"grep": "allow"
}
}
Purpose:
- Search code with regular expressions
6. glob (File Matching)
Purpose:
- Find file paths (e.g., src/**/*.ts)
7. list (Directory Browsing)
Purpose:
- List directory structure
8. patch (Patch Application)
Purpose:
- Apply diff patches
Note:Controlled by the edit permission
9. lsp (Experimental)
Purpose:
- Intelligent code analysis (jump to definition, find references)
How to enable:
OPENCODE_EXPERIMENTAL_LSP_TOOL=true
10. skill (Skill Loading)
Purpose:
- Load SKILL.md
- Enhance AI behavior
11. todowrite (Task Management)
Purpose:
- Maintain task lists
- Track complex workflows
12. webfetch (Web Page Reading)
Purpose:
- Fetch content from a specified URL
13. websearch (Online Search)
How to enable:
OPENCODE_ENABLE_EXA=1 opencode
Purpose:
- Search internet information
Difference:
- websearch: find information (discovery)
- webfetch: read content (fetching)
14. question (Interactive Questioning)
Purpose:
- Ask the user questions
- Collect requirements
Suitable for:
- Unclear requirements
- When user decisions are needed
4. Custom Tools
You can define your own tools to let AI execute custom logic.
For example:
- Calling internal APIs
- Operating databases
- Executing business logic
Essence:Letting the LLM call functions
5. MCP Servers (Advanced Capabilities)
MCP (Model Context Protocol) allows you to connect external systems:
- Databases
- Third-party APIs
- Internal services
This is equivalent to connecting "external capabilities" to AI
6. Underlying Mechanism (Important)
OpenCode uses ripgrep as its search engine:
- Follows .gitignore
- Ignores directories like node_modules by default
How to Override Ignore Rules
Create a file:
.ignore
Example:
!node_modules/ !dist/ !build/
Forcefully include these directories
7. Best Practices (Highly Recommended)
- read / grep / glob → allow
- edit → ask (development phase)
- bash → ask (production environment)
- webfetch → allow
Core principles:
- Reading can be open
- Modifications must be controlled
- Be cautious with command execution