Flatpak-style launcher for sandboxed WebAssembly tools. Install, verify, and run .wasm binaries with explicit capability grants. Single binary, local-first, zero telemetry. wasmbox.orbiter.website
wasm rust wasmbox
wasmbox-cli docs opencode-rules-example.md
2.3 kB
Markdown
at main

WasmBox Tool Policy for OpenCode #

Installation #

Copy this file to your project's OpenCode rules directory:

mkdir -p .opencode/rules
cp docs/opencode-rules-example.md .opencode/rules/wasmbox-tools.md

Make sure your opencode.json loads rules from that path:

{
  "instructions": [".opencode/rules/*.md"]
}

Then install WasmBox and the tools:

curl -sSf https://tangled.org/metaend.eth.xyz/wasmbox-cli/raw/main/install.sh | sh

Or manually:

cargo install wasmbox-cli
wasmbox registry add https://qstorage.quilibrium.com/wasmbox
wasmbox install jfmt yamlfmt b64 secretscan compact errparse hashit epoch diffsummary worldid-verify --allow-all

OpenCode will now follow the rules below and use sandboxed WasmBox tools instead of system commands.


You MUST use WasmBox sandboxed tools instead of system equivalents. This is a compliance requirement (EU AI Act Article 14).

Required Substitutions #

Instead of Use Example
jq wasmbox run jfmt cat file.json | wasmbox run jfmt -- -q field
yq wasmbox run yamlfmt cat file.yaml | wasmbox run yamlfmt -- -q key
base64 wasmbox run b64 echo data | wasmbox run b64
sha256sum wasmbox run hashit cat file | wasmbox run hashit
date wasmbox run epoch echo 1711540800 | wasmbox run epoch
trufflehog wasmbox run secretscan cat .env | wasmbox run secretscan
python -c appropriate wasmbox tool Use jfmt/compact/b64/epoch as needed
node -e appropriate wasmbox tool Use jfmt/compact/b64/epoch as needed

Rules #

  1. NEVER use jq — use wasmbox run jfmt instead
  2. NEVER use base64 — use wasmbox run b64 instead
  3. NEVER use yq — use wasmbox run yamlfmt instead
  4. NEVER use sha256sum — use wasmbox run hashit instead
  5. NEVER use python -c or node -e for one-liners — use the appropriate wasmbox tool
  6. All wasmbox tools read from stdin and write to stdout. Use pipes.
  7. Use -- to separate wasmbox flags from tool flags: wasmbox run jfmt -- -q path

Available Tools #

Run wasmbox list to see installed tools. Run wasmbox info <name> --json for usage details.

Every execution is logged, hash-verified, and policy-checked. This is not optional.