
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@serkanalgur/opencode-slim
Advanced tools
Smart context management plugin for OpenCode - semantic compression, cost-aware pruning, adaptive thresholds
Smart context management plugin for OpenCode. Optimizes token usage through semantic compression, cost-aware pruning, and adaptive thresholds.
opencode plugin @serkanalgur/opencode-slim@latest --global
This installs the plugin globally. The TUI features (panel, slash commands) are automatically loaded when OpenCode starts.
If the CLI command doesn't work, add to your ~/.config/opencode/opencode.json:
{
"plugins": ["@serkanalgur/opencode-slim"]
}
After installation, these slash commands are available in the TUI:
/panel — Opens the rich TUI panel with context usage, stats, and help/compress — Shows instructions for using the compress toolThe panel provides a real-time overview of your context usage, including:
The enhanced compress tool supports multiple modes:
// Auto mode (default) - intelligently selects what to compress
compress({ focus: "old exploration" })
// Range mode - compress specific message range
compress({ focus: "completed tasks", mode: "range", start: 0, end: 50 })
// Topic mode - compress messages matching a topic
compress({ focus: "database work", mode: "topic", topic: "database" })
Create ~/.config/opencode/slim.jsonc:
{
"enabled": true,
"compress": {
"enabled": true,
"permission": "allow",
"maxContextLimit": "80%",
"minContextLimit": "40%",
"nudgeFrequency": 5,
"protectUserMessages": false,
"protectedTools": ["task", "skill", "todowrite", "todoread"]
},
"strategies": {
"deduplication": {
"enabled": true,
"protectedTools": []
},
"purgeErrors": {
"enabled": true,
"turns": 4,
"protectedTools": []
}
},
"adaptive": {
"enabled": true,
"learningRate": 0.1,
"minCompressionRatio": 0.3
},
"costAware": {
"enabled": true,
"cacheBoostFactor": 0.5
},
"persistence": {
"enabled": true,
"directory": "~/.config/opencode/slim"
}
}
The panel provides a real-time overview of your context usage, including:
Unlike simple text truncation, slim analyzes the semantic content of messages and groups related tool calls together. This preserves context while removing redundancy.
Slim considers the cost of tokens when deciding what to compress. It prioritizes compressing expensive operations (like large file reads) while preserving cheap but important context.
The plugin learns from your compression patterns and adjusts thresholds over time. If you tend to need more context, it will compress less aggressively. If you're efficient, it will compress more.
State is saved to disk, so compression history and learning persist across restarts.
| Command | Description |
|---|---|
/panel | Open the Slim TUI panel with context usage, stats, and help |
/compress | Show instructions for using the compress tool |
Note: Compression is performed by the AI assistant using the compress tool. The slash command provides guidance on usage.
| Feature | slim | DCP |
|---|---|---|
| TUI Panel | ✅ | ✅ |
| Slash Commands | ✅ /panel /compress | ✅ /dcp /dcp-compress |
| Manual Compress | ✅ | ✅ |
| Semantic grouping | ✅ | ❌ |
| Cost awareness | ✅ | ❌ |
| Adaptive thresholds | ✅ | ❌ |
| Session persistence | ✅ | ❌ |
| Topic extraction | ✅ | ❌ |
| File count | ~10 | ~150 |
| License | MIT | AGPL-3.0 |
| Config complexity | Low | High |
MIT
FAQs
Smart context management plugin for OpenCode - semantic compression, cost-aware pruning, adaptive thresholds
We found that @serkanalgur/opencode-slim demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.