Landstrip
OS-level AI command sandboxing for OpenCode with Landstrip
81
+8 in 30 days
1,917
178 in 7 days
61.1
Multi-signal model
5 hours ago
2026-10-05
Install and configure
opencode.jsonWrites to this project's opencode.json — applies to this repository only.
opencode.json
{
"$schema": "https://opencode.ai/config.json",
"plugin": ["opencode-landstrip@0.19.7"]
}Writes to ~/.config/opencode/opencode.json — applies to every project.
~/.config/opencode/opencode.json
{
"$schema": "https://opencode.ai/config.json",
"plugin": ["opencode-landstrip@0.19.7"]
}If you want to modify the plugin locally, install it into the project and reference the local path.
shell
pnpm add -D opencode-landstripOpenCode loads npm dependencies through its embedded runtime on startup and caches them locally — no manual global install needed.
landstrip runs commands in an OS-level sandbox using Landlock on Linux,
Seatbelt on macOS, and AppContainer or restricted users on Windows.
Quick start
Install the CLI and native binary for your platform:
npm install --save-dev @landstrip/landstrip-api
For Linux or macOS, save this as policy.json. Windows requires explicit read
grants for the program and its dependencies; see the manual below.
{
"filesystem": {
"allowWrite": ["."],
"denyWrite": ["**/.env", "**/*.pem"],
"denyRead": ["~/.ssh"],
"allowRead": ["~/.ssh/config"]
},
"network": {
"allowNetwork": false,
"allowLocalBinding": false
}
}
npx landstrip run -p policy.json -- cargo test
npx landstrip policy validate -p policy.json
npx landstrip doctor
See landstrip(1) for policy rules, merged-policy inspection, CLI options, and platform limits.
Integrations
- Node.js API: native binary access and trap types.
- OpenCode:
opencode-landstripplugin. - Pi:
pi-landstripextension and subagents.
Development
Run make ci from the repository root.
License
- Native sandbox: LGPL-3.0-or-later.
- Node.js API and agent extensions: Apache-2.0; see each package's
LICENSE.
Similar plugins
Seatbelt
opencode-seatbelt
macOS Seatbelt (kernel sandbox) for OpenCode. Stops coding agents from reading secrets, enforced by the OS, not by command matching.
V2 Security
opencode-v2-security
Execution-boundary security plugin for OpenCode (v2 plugin API): static + dynamic shell-command classification, bypass leases, and a session read/write permission ceiling.
Goal
@prevalentware/opencode-goal-plugin
OpenCode goal plugin that adds Codex-style long-running goal mode, /goal commands, persistence, and TUI status for AI coding agents.