
Research
/Security News
Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data
Malicious Chrome and Firefox extensions target Axiom Trade and Padre users, stealing session tokens and wallet data.
@honcho-ai/opencode-honcho
Advanced tools
Add AI-native memory to OpenCode
Give OpenCode long-term memory that survives context wipes, session restarts, and fresh chats. Honcho remembers what you're working on, durable preferences, and prior context across your projects.
OpenCode installs the Honcho plugin and adds it to your global OpenCode config.
opencode plugin "@honcho-ai/opencode-honcho" --global
To update an existing plugin install:
opencode plugin "@honcho-ai/opencode-honcho" --force
Existing installs keep directional observation until you choose. After updating, OpenCode prompts you to keep directional or switch to unified (also via /honcho:setup or /honcho:config). If you switch to unified, you can optionally run /honcho:import to reingest local OpenCode transcripts into the new collection.
This command expects the opencode CLI to already be installed and available on your PATH.
If your shell cannot find opencode, restart your shell or source your shell config and run the command again.
/honcho:setupHoncho Cloud option unless you explicitly want a self-hosted or local endpointpeerName/honcho:status to verify the runtime/honcho:import to backfill local historyhoncho-memory skill is installed into OpenCode's skills directory so the agent knows when to pull and save memory on its ownobservationMode, agentObserveMe)OpenCode:
@honcho-ai/opencode-honcho with OpenCodeOpenCode Honcho configuration lives in:
~/.honcho/config.jsonOpenCode reads and writes this shared config file directly. OpenCode-specific defaults live under hosts.opencode in that file.
{
"apiKey": "hch-...",
"peerName": "user",
"baseUrl": "https://api.honcho.dev",
"hosts": {
"opencode": {
"workspace": "opencode",
"aiPeer": "opencode",
"recallMode": "hybrid",
"observationMode": "unified", // new installs; existing configs without this field stay directional
"agentObserveMe": false, // true opts into self-observation on the root agent peer
"sessionStrategy": "per-directory",
"removeUserPrefix": true, // true uses the bare peerName; false (default on upgrade) keeps the legacy user-<peerName> peer
"apiKey": "hch-..." // optional; overrides the root apiKey for this host
}
}
}
For Honcho Cloud:
apiKey is requiredbaseUrl should remain https://api.honcho.devFor self-hosted or local Honcho:
baseUrl should point to your deployment, for example http://127.0.0.1:8000apiKey is required only if that deployment requires authenticationIf OpenCode is running in Docker or another remote environment, localhost may not refer to your machine. The configured baseUrl must be reachable from the OpenCode host runtime.
| Strategy | Behavior | Best for |
|---|---|---|
per-directory | One session per working directory | Default project memory |
per-repo | One session per repository | Repos with multiple entry directories |
git-branch | Session changes with the current branch | Branch-specific workflows |
per-session | New session for each OpenCode session id | Short-lived isolated work |
chat-instance | Session follows the current chat instance | Highly ephemeral usage |
global | One session for everything | Shared memory across all work |
Controls which Honcho collection honcho_chat, honcho_create_conclusion, and targeted prompt recall use for the user. This is independent of agentObserveMe (whether the agent peer is modeled). Changing modes does not migrate existing conclusions — use /honcho:import to backfill local OpenCode transcripts so Honcho can derive into the new collection.
| Mode | Collection | Best for |
|---|---|---|
unified (default on new installs) | The user's self-collection (observer=user, observed=user) | Shared workspaces where multiple agents should recall each other's conclusions about the user |
directional (existing installs until set) | This AI peer's view of the user (observer=aiPeer, observed=user) | Isolated per-agent memory; previous OpenCode behavior |
New ~/.honcho/config.json files stamp observationMode: "unified". Configs that predate the field keep directional so an upgrade does not orphan already-derived memory. After updating, OpenCode prompts you to keep directional or switch to unified (/honcho:setup, /honcho:config, or the TUI launch dialog). If you switch, optionally run /honcho:import to reingest local OpenCode transcripts:
{
"hosts": {
"opencode": {
"observationMode": "unified"
}
}
}
The root agent peer is created with observeMe: false by default: Honcho models the user, not the assistant. Set agentObserveMe to true if you want a peer card / representation of the agent itself.
{
"hosts": {
"opencode": {
"agentObserveMe": true
}
}
}
| Command | Description |
|---|---|
/honcho:setup | First-time setup for cloud or local Honcho |
/honcho:status | Show effective Honcho status for the current OpenCode project, including live workspace and session names when available |
/honcho:settings | Show effective config values and config paths |
/honcho:config | Edit shared Honcho fields in ~/.honcho/config.json |
/honcho:import | Preview or import your local OpenCode session history into Honcho |
/honcho:import reads session history through the OpenCode SDK client that the plugin receives, maps sessions with the same sessionStrategy as live capture, and uploads user/assistant text with original timestamps.
~/.honcho/opencode-import-state.json).observationMode: "unified", import so past transcripts can be derived into the user self-collection instead of remaining only on the old directional pair.The plugin exposes these tools inside OpenCode:
| Tool | Description |
|---|---|
honcho_setup | Validate setup and persist shared credentials or endpoint settings |
honcho_status | Show effective runtime status |
honcho_get_config | Read effective and persisted settings |
honcho_set_config | Update a persisted shared setting |
honcho_search | Search Honcho session messages in the current session |
honcho_chat | Query Honcho for reasoning-backed context (observer follows observationMode) |
honcho_create_conclusion | Save a durable memory conclusion (same observer as honcho_chat) |
The plugin uses these OpenCode plugin capabilities:
eventchat.messagetool.execute.aftercommand.execute.beforeexperimental.chat.system.transformexperimental.session.compactingshell.envtoolexperimental.chat.system.transform always appends the Honcho memory instruction. With recallMode hybrid or context it also adds a stable memory snapshot (user profile, agent context, session summary), captured once on the first turn of a session.chat.message retrieves prompt-specific recall on user turns in hybrid and context mode, appending a synthetic memory part when it yields a new block. Unchanged blocks are deduplicated within the session. In tools mode nothing beyond the instruction is injected; the model reaches memory only through the honcho_* tools.tool.execute.after records shell commands, file edits, and delegated tasks to the session. Read-only and trivial calls are skipped. Shell arguments that may carry credentials are redacted, keeping only the executable name.honcho_setup, the packaged honcho-memory skill is copied to ~/.config/opencode/skills/honcho-memory, or $OPENCODE_CONFIG_DIR/skills/honcho-memory when set. An unchanged file is left untouched.For macOS/Linux local branch testing:
bun install
bun run build
opencode plugin "$PWD" --global --force
That command wires the current checkout into OpenCode with --force, which is the intended local branch-testing flow.
FAQs
Honcho memory integration for OpenCode
The npm package @honcho-ai/opencode-honcho receives a total of 53 weekly downloads. As such, @honcho-ai/opencode-honcho popularity was classified as not popular.
We found that @honcho-ai/opencode-honcho demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Research
/Security News
Malicious Chrome and Firefox extensions target Axiom Trade and Padre users, stealing session tokens and wallet data.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.