Skip to content

feat(opencode): add enforced learn mode - #19

Open
vmiloserdov wants to merge 6 commits into
mainfrom
vmiloser/learn-mode-enforcement-ui
Open

vmiloserdov wants to merge 6 commits into
mainfrom
vmiloser/learn-mode-enforcement-ui

Conversation

@vmiloserdov

@vmiloserdov vmiloserdov commented Sep 26, 2026 •

Copy link
Copy Markdown

Issue for this PR

Closes #15

Type of change

  • Bug fix
  • New feature
  • Refactor / code improvement
  • Documentation

What does this PR do?

User story

As a student completing a coding assignment, I want to use AI to understand the codebase while writing the assignment myself, so that I can strengthen my software engineering skills.

The existing Plan mode relies on a system prompt. That is useful guidance, but it cannot guarantee that a tool call will not modify the working tree. This PR adds Learn mode as an enforced read-only alternative for students who want explanations, code navigation, and research without allowing OpenCode to make changes for them.

Changes

  • Adds Learn as a primary agent, so it appears in the existing agent selector and participates in the normal mode-switching flow.
  • Gives Learn a focused prompt that frames it as a research and explanation mode.
  • Restricts Learn's tool registry to read, glob, grep, webfetch, and websearch. Write tools, task delegation, custom tools, plugin tools, and MCP tools are omitted before the model can call them.
  • Rejects both direct shell input and configured command expansion when the active agent is Learn. This protects the two session paths that can otherwise invoke a command outside the normal tool list.
  • Styles Learn consistently in the app and session UI.
  • Keeps the local .devcontainer setup out of version control via .gitignore; it is only for my local container workflow and is not part of this feature.

I did not use a "revert after the fact" strategy such as git reset --hard. A reset could discard the student's own uncommitted work. Learn instead prevents mutation-capable paths from being exposed or started.

How did you verify your code works?

Automated verification:

  • bun typecheck from packages/opencode
  • bun test test/agent/agent.test.ts test/tool/registry.test.ts test/session/prompt.test.ts from packages/opencode

The tests cover:

  • Learn being available as a primary agent with only the intended permissions.
  • The read-only registry containing exactly the five allowed tools.
  • A Learn session rejecting a direct shell write attempt before it runs.
  • A Learn session rejecting a configured command that would expand into a shell write attempt.

Manual verification:

  • Started OpenCode, selected Learn from the existing mode selector, and asked questions about repository code.
  • Asked Learn to create a file and to override its restrictions. It refused, and no file was created.
  • Entered shell mode with ! and attempted a command that writes a file. Learn rejected the command before execution.
  • Confirmed the working tree remained unchanged with git diff --exit-code and git status --short.
  • Switched back to Build mode and confirmed that normal editing remains available there.

Screenshots / recordings

The Learn option uses the existing mode selector and agent styling. I will attach a short terminal recording of the read-only prompt and shell checks before this draft is marked ready for review.

How it looks:
image

Rejecting edit prompt:
image

Rejects the shell commands that are run in Shell mode (! in the front of the prompt):
image

Accepting the allowed prompt:
image

Link to GDrive recording:
https://drive.google.com/file/d/1gg9rFkDplu-3DVvuWCNoM--lAjMTzpln/view?usp=drive_link

Checklist

  • I have tested my changes locally
  • I have not included unrelated changes in this PR

@vmiloserdov vmiloserdov changed the title Vmiloser/learn mode enforcement UI feat(opencode): add enforced learn mode Sep 26, 2026
@yswcyswc
yswcyswc marked this pull request as ready for review September 27, 2026 17:11

@yswcyswc yswcyswc left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The read-only protections look solid overall. I left one integration question about allowing read-only learning commands within Learn mode.

}
const agentName = cmd.agent ?? input.agent

if (input.agent === "learn" || agentName === "learn") {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should Learn mode block every slash command here, or only commands that can modify the repository? As written, this appears to prevent read-only learning commands such as /group and /newcomer from running while Learn mode is active. Since these features are intended to integrate with Learn mode, it may be useful to allow explicitly read-only commands while continuing to block shell expansions and mutation-capable commands.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great note. Yes, Learn mode will allow a specific list of commands, and I think this part should be reserved for another PR, when we move onto the next stage of the project, which is the integration of the Learn Mode.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Learn Mode: Read Only Mode

2 participants