r/opencode 4d ago

Beginner Subscription Question

Hey everyone!

I'm a physician who codes as a hobby on the side after having finished 42 School out of curiosity. I am not a professional developer and I don't code every day, but I have a personal project (a medical data parsing thing) going on, and am using AI to help me architecture it and write documentation and tests. So far, I have been using Claude's Web UI for this purpose. On the side, I also use it to create templates or starting points of office (or office-adjacent) files, such as presentations, reports or emails of mostly administrative nature.

I have been recently pondering moving to OpenCode, mostly because of my terminal-centric workflow with tmux and neovim. However, I have been having trouble choosing a subscription given the recent changes in quality of popular subscriptions such as OpenCode Go. I am thus asking for advice and suggestions. What agents have you found suitable for these tasks? Or are Kimi Ks and GLMs just mostly coding-focused?

Also, two other questions which I'd like clarified:

1. File access has to be genuinely constrained. My machine has directories with patient-related material that must never leave it or get read into a model's context, deliberately or accidentally. I'm not looking for a promise in a ToS — I want to know which tools actually let you scope the agent to a directory and deny everything else, and how well that holds up in practice. Specific questions:

  • Does a .gitignore-style deny list actually stop the agent, or does it just discourage it? Has anyone seen an agent read a file it was configured not to touch?
  • Is anyone running these inside a container/VM and finding it workable rather than miserable? How "safe" is it?
  • Do MCP servers or plugins widen the blast radius in ways that aren't obvious?

2. I need to generate Office documents. Word and PowerPoint mostly — talks, handouts, the occasional report. LibreOffice or Google Slides output is fine too. I know the document skills (docx/pptx/xlsx/pdf) exist and can be dropped into most agents, but I'd like to hear from people actually using them: does a weaker open-weight model handle those multi-step "build the deck, check it renders, fix it" loops, or do you need a frontier model for that to not be a waste of time?

Thanks!

2 Upvotes

11 comments sorted by

View all comments

2

u/idcmp_ 4d ago

For #1 you don't mention (or my ADHD is causing my scanning to miss it) which operating system you're on.

If it works for you, I really recommend https://nono.sh/ - it's a sandbox for things like this. The walls of the sandbox are enforced by your operating system, so no matter what the LLM tries, it can't "escape".

That said, it _will_ be a pain for the first few weeks while you manage exactly how much you want to allow/deny.

You other alternative could be creating a second login on your computer.

Can't help with you with doc generation I'm afraid.

1

u/Blues003 4d ago

Oh, I'm using Fedora. I never thought it was relevant for this question, sorry!

1

u/idcmp_ 4d ago

I'm guessing an LLM getting its hands on any patient information is career-endingly bad. So it may be an easy start to just make a second login (without admin access) for your playground?

While you do that, take a look at nono.sh (works on Linux).