
Company News
AWS Security Hub Adds Socket for Supply Chain Security
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.
@witness-ai/opencode
Advanced tools
MCP memory / second brain for Claude Code & OpenCode — captures your coding sessions and distills how your knowledge and habits evolve over time, queryable by your agent.
OpenCode plugin for witness. It reconciles OpenCode's local session database on startup and when a session goes idle, and starts witness distillation only through the CLI's laptop-friendly auto-start gate.
| Operating system | Architecture | Installed binary package |
|---|---|---|
| macOS | Apple Silicon (darwin/arm64) | @witness-ai/opencode-darwin-arm64 |
| Linux | x86-64 (linux/x64) | @witness-ai/opencode-linux-x64 |
These are the only platforms supported by the npm distribution. macOS Intel, Linux ARM, and Windows are not supported. The CLI exits with a clear supported-platform message on those systems.
Add the npm plugin to your OpenCode config. OpenCode installs the package automatically with Bun on startup, and the plugin auto-registers mcp.witness if you have not already defined one:
{
"$schema": "https://opencode.ai/config.json",
"plugin": ["@witness-ai/opencode"]
}
To test a prerelease, pin the plugin entry to the beta version instead of the unversioned package name:
{
"$schema": "https://opencode.ai/config.json",
"plugin": ["@witness-ai/opencode@beta"]
}
Optional: install it globally if you also want a witness CLI on your shell PATH:
npm install -g @witness-ai/opencode
Optional: run the CLI ad hoc without a global install:
npm exec --yes --package=@witness-ai/opencode -- witness doctor
The main package includes the plugin, CLI wrapper, and prompts. npm installs one optional platform package containing the matching witness binary; it does not download binaries for other operating systems or architectures. The first embedding-model download is about 470MB into the witness data directory (assets/e5-small). npm install only installs the packages; the OpenCode plugin starts the model download when OpenCode next starts. Keep OpenCode running until the first download finishes. If OpenCode stops early, the plugin stops its downloader and retries later with bounded backoff. Set WITNESS_BIN to override the platform package binary.
After the download completes, verify the model, OpenCode runner, archive, and queue:
npm exec --yes --package=@witness-ai/opencode@beta -- witness doctor
npm exec --yes --package=@witness-ai/opencode@beta -- witness distill status
Upgrade note: Older witness releases could leave an OpenCode session whose agent or title is
witness-distillwhen distillation was interrupted. Current releases no longer create or filter those sessions in OpenCode's user database. Before the first import after upgrading, remove any leftoverwitness-distillsessions with OpenCode's supported session-management tools so they are not captured as normal archive data.
By default the model is downloaded from Hugging Face. A custom WITNESS_MODEL_BASE_URL must serve the same paths (onnx/model.onnx and tokenizer.json) and also set WITNESS_MODEL_SHA256 plus WITNESS_TOKENIZER_SHA256.
Automatic distillation is batched by default: sessions are reconciled on startup and idle, while model work starts at most once every 10 minutes, drains the current queue, then exits so the embed model is not resident. Edit witness config.toml if you want manual-only behavior:
auto_distill = false
If you want to force a different binary, set WITNESS_BIN before starting OpenCode:
export WITNESS_BIN=/absolute/path/to/witness
If you already have your own mcp.witness entry, the plugin leaves it alone. The npm CLI deliberately does not support witness install / witness uninstall; those are source-checkout workflows, not the npm one.
FAQs
MCP memory / second brain for Claude Code & OpenCode — captures your coding sessions and distills how your knowledge and habits evolve over time, queryable by your agent.
We found that @witness-ai/opencode demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.