
Research
/Security News
Fake imToken Chrome Extension Steals Seed Phrases via Phishing Redirects
Mixed-script homoglyphs and a lookalike domain mimic imToken’s import flow to capture mnemonics and private keys.
opencode-bonfire
Advanced tools
Pick up exactly where you left off. Bonfire maintains a living context document across AI coding sessions—read at start, updated at end.
Project install (recommended):
bunx opencode-bonfire install
Global install (available in all projects):
bunx opencode-bonfire install --global
| Component | Description |
|---|---|
| 9 Commands | /bonfire-start, /bonfire-end, /bonfire-spec, /bonfire-strategic, /bonfire-document, /bonfire-review, /bonfire-review-pr, /bonfire-archive, /bonfire-configure |
| 3 Agents | codebase-explorer, writer, work-reviewer |
| 2 Skills | bonfire-context, archive-bonfire-awareness |
| 1 Plugin | Archive suggestions + compaction context preservation |
| 1 Tool | bonfire for structured session data |
/bonfire-start # Start session, scaffold if needed
/bonfire-end # Update context, commit changes
/bonfire-spec <topic> # Create implementation spec
/bonfire-strategic <type> <topic> # Create RFC, PRD, or POC
/bonfire-document <topic> # Document a codebase topic
/bonfire-review # Find blindspots and gaps
/bonfire-review-pr <number> # Review a GitHub PR
/bonfire-archive # Archive completed work
/bonfire-configure # Change project settings (git, linear)
Bonfire creates a .bonfire/ directory in your project:
.bonfire/
├── index.md # Living context document
├── config.json # Project settings
├── archive/ # Completed work history
├── specs/ # Implementation specs
└── docs/ # Reference documentation
Start each session with /bonfire-start to read context. End with /bonfire-end to save progress.
bunx opencode-bonfire uninstall
# or
bunx opencode-bonfire uninstall --global
Note: Your .bonfire/ data is preserved during uninstall.
Bonfire uses the same .bonfire/ directory format as the Claude Code version. You can switch between platforms freely.
Bonfire animation by Jon Romero Ruiz.
FAQs
OpenCode forgets everything between sessions. Bonfire remembers.
We found that opencode-bonfire demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Mixed-script homoglyphs and a lookalike domain mimic imToken’s import flow to capture mnemonics and private keys.

Security News
Latio’s 2026 report recognizes Socket as a Supply Chain Innovator and highlights our work in 0-day malware detection, SCA, and auto-patching.

Company News
Join Socket for live demos, rooftop happy hours, and one-on-one meetings during BSidesSF and RSA 2026 in San Francisco.