OpenCode Governance
SSG governance integration for OpenCode — `ssg init --client=opencode` writes opencode.json, the pre-tool-hook plugin, and an AGENTS.md governance block. Tool calls are intercepted before execution; denied calls are aborted. Fail-closed by default.
Verified
integrations
v1.0.7
Install
~/your-project
$ ssg plugins install opencode-governance
✓ Verified Ed25519 signature against sigmashakeinc
✓ Installed v1.0.7 into ~/.sigmashake/plugins/opencode-governance/
$ Open the dashboard → Plugins to enable
The CLI verifies SHA-256 + Ed25519 signature against the publisher's fingerprint before extracting the tarball. See trust model.
OpenCode Governance wires SSG into the OpenCode AI coding agent as a host integration. Running `ssg init --client=opencode` writes three artefacts into your project: opencode.json (a permission block transpiled from your .rules files plus mcp.ssg-governance), .opencode/plugins/ssg-governance.js (the plugin asset), and an AGENTS.md governance block. The plugin hooks `tool.execute.before`: when SSG evaluates a tool call as DENY, the hook throws and OpenCode aborts the tool call before execution — a real pre-execution deny gate. Allowed calls proceed; ASK verdicts pause for human confirmation. `tool.execute.after` records an audit entry for every completed call. On eval error the gate fails closed; set SSG_HOOK_FAIL_OPEN=1 to override (operator escape hatch only). Honest boundary: the gate is in-process to the OpenCode host. It does NOT fire inside `task`-spawned subagents (OpenCode issue #5894) — sub-agent calls are not intercepted by this hook. This is a documented limitation in the parity roadmap; do not represent this integration as tamper-proof, offering full containment, or unbypassable. The plugin asset is free to download and install via the paid-funnel CDN. Governance value — rule evaluation, verdict enforcement, audit log — requires an active SigmaShake subscription at runtime.