• nix98@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 day ago

    This is where tools like bubblewrap (bwrap) come in. For opencode, I heavily limit what it can see and what is has access to. No access to my ssh keys or aws credentials or anything else.

    • B0rax@feddit.org
      link
      fedilink
      English
      arrow-up
      2
      ·
      14 hours ago

      Yes, that is what you do. But not what the majority does… heck it even asks if it can get access to 1password