Landstrip
OS-level AI command sandboxing for OpenCode with Landstrip
81
近 30 天 +8
1,917
近 7 天 178
61.1
生态多维模型
5 小时前
2026-10-05
快速安装与配置
opencode.json写入当前项目的 opencode.json,只对这个仓库生效。
opencode.json
{
"$schema": "https://opencode.ai/config.json",
"plugin": ["opencode-landstrip@0.19.7"]
}写入 ~/.config/opencode/opencode.json,对所有项目生效。
~/.config/opencode/opencode.json
{
"$schema": "https://opencode.ai/config.json",
"plugin": ["opencode-landstrip@0.19.7"]
}若你要在本地改造这个插件,先装到项目里再从本地路径引用。
shell
pnpm add -D opencode-landstripOpenCode 启动时会通过内嵌运行时自动加载 npm 依赖并缓存至本地目录,无需手动在全局环境执行安装。
landstrip runs commands in an OS-level sandbox using Landlock on Linux,
Seatbelt on macOS, and AppContainer or restricted users on Windows.
Quick start
Install the CLI and native binary for your platform:
npm install --save-dev @landstrip/landstrip-api
For Linux or macOS, save this as policy.json. Windows requires explicit read
grants for the program and its dependencies; see the manual below.
{
"filesystem": {
"allowWrite": ["."],
"denyWrite": ["**/.env", "**/*.pem"],
"denyRead": ["~/.ssh"],
"allowRead": ["~/.ssh/config"]
},
"network": {
"allowNetwork": false,
"allowLocalBinding": false
}
}
npx landstrip run -p policy.json -- cargo test
npx landstrip policy validate -p policy.json
npx landstrip doctor
See landstrip(1) for policy rules, merged-policy inspection, CLI options, and platform limits.
Integrations
- Node.js API: native binary access and trap types.
- OpenCode:
opencode-landstripplugin. - Pi:
pi-landstripextension and subagents.
Development
Run make ci from the repository root.
License
- Native sandbox: LGPL-3.0-or-later.
- Node.js API and agent extensions: Apache-2.0; see each package's
LICENSE.
同类生态推荐
Seatbelt
opencode-seatbelt
macOS Seatbelt (kernel sandbox) for OpenCode. Stops coding agents from reading secrets, enforced by the OS, not by command matching.
V2 Security
opencode-v2-security
Execution-boundary security plugin for OpenCode (v2 plugin API): static + dynamic shell-command classification, bypass leases, and a session read/write permission ceiling.
Goal
@prevalentware/opencode-goal-plugin
OpenCode goal plugin that adds Codex-style long-running goal mode, /goal commands, persistence, and TUI status for AI coding agents.