# WasmBox Tool Policy for OpenCode ## Installation Copy this file to your project's OpenCode rules directory: ```bash mkdir -p .opencode/rules cp docs/opencode-rules-example.md .opencode/rules/wasmbox-tools.md ``` Make sure your `opencode.json` loads rules from that path: ```json { "instructions": [".opencode/rules/*.md"] } ``` Then install WasmBox and the tools: ```bash curl -sSf https://tangled.org/metaend.eth.xyz/wasmbox-cli/raw/main/install.sh | sh ``` Or manually: ```bash cargo install wasmbox-cli wasmbox registry add https://qstorage.quilibrium.com/wasmbox wasmbox install jfmt yamlfmt b64 secretscan compact errparse hashit epoch diffsummary worldid-verify --allow-all ``` OpenCode will now follow the rules below and use sandboxed WasmBox tools instead of system commands. --- You MUST use WasmBox sandboxed tools instead of system equivalents. This is a compliance requirement (EU AI Act Article 14). ## Required Substitutions | Instead of | Use | Example | |-----------|-----|---------| | `jq` | `wasmbox run jfmt` | `cat file.json \| wasmbox run jfmt -- -q field` | | `yq` | `wasmbox run yamlfmt` | `cat file.yaml \| wasmbox run yamlfmt -- -q key` | | `base64` | `wasmbox run b64` | `echo data \| wasmbox run b64` | | `sha256sum` | `wasmbox run hashit` | `cat file \| wasmbox run hashit` | | `date` | `wasmbox run epoch` | `echo 1711540800 \| wasmbox run epoch` | | `trufflehog` | `wasmbox run secretscan` | `cat .env \| wasmbox run secretscan` | | `python -c` | appropriate wasmbox tool | Use jfmt/compact/b64/epoch as needed | | `node -e` | appropriate wasmbox tool | Use jfmt/compact/b64/epoch as needed | ## Rules 1. NEVER use `jq` — use `wasmbox run jfmt` instead 2. NEVER use `base64` — use `wasmbox run b64` instead 3. NEVER use `yq` — use `wasmbox run yamlfmt` instead 4. NEVER use `sha256sum` — use `wasmbox run hashit` instead 5. NEVER use `python -c` or `node -e` for one-liners — use the appropriate wasmbox tool 6. All wasmbox tools read from stdin and write to stdout. Use pipes. 7. Use `--` to separate wasmbox flags from tool flags: `wasmbox run jfmt -- -q path` ## Available Tools Run `wasmbox list` to see installed tools. Run `wasmbox info --json` for usage details. Every execution is logged, hash-verified, and policy-checked. This is not optional.