- Found: 2026-10-06, Cowright Phase 1 research (Pitfall 11)
- Environment: GSD Core 1.16.0 (
--opencode --global), OpenCode 1.18.35, Linux
Summary
The OpenCode install writes "mcp": {"gsd": {"command": ["npx", "-y", "-p", "@opengsd/gsd-core", "gsd-mcp-server"]}}. Every OpenCode start, including every spawned opencode run worker, resolves
@opengsd/gsd-core to whatever npm latest is at that moment. The MCP server can therefore differ
from the installed version and needs the network on every start. It also widens the supply-chain
surface to every future publish.
Minimal repro
npx @opengsd/gsd-core@1.16.0 --opencode --global
- Read
mcp.gsd.command in ~/.config/opencode/opencode.jsonc: no version in the package spec.
Expected
The entry pins the installed version (@opengsd/gsd-core@1.16.0), or points at the installed tree's
own server script.
Actual
Unpinned package spec.
Suggested fix
Write @opengsd/gsd-core@<installed version> into the MCP entry, or run the server from the
installed tree with node.
Cowright workaround
scripts/apply.cjs pins the entry to @opengsd/gsd-core@1.16.0 after every install; check C10
verifies it is pinned and connected.
Evidence
docs/smoke/runs/2026-10-07/mechanical-final.json (C10)
--opencode --global), OpenCode 1.18.35, LinuxSummary
The OpenCode install writes
"mcp": {"gsd": {"command": ["npx", "-y", "-p", "@opengsd/gsd-core", "gsd-mcp-server"]}}. Every OpenCode start, including every spawnedopencode runworker, resolves@opengsd/gsd-coreto whatever npmlatestis at that moment. The MCP server can therefore differfrom the installed version and needs the network on every start. It also widens the supply-chain
surface to every future publish.
Minimal repro
npx @opengsd/gsd-core@1.16.0 --opencode --globalmcp.gsd.commandin~/.config/opencode/opencode.jsonc: no version in the package spec.Expected
The entry pins the installed version (
@opengsd/gsd-core@1.16.0), or points at the installed tree'sown server script.
Actual
Unpinned package spec.
Suggested fix
Write
@opengsd/gsd-core@<installed version>into the MCP entry, or run the server from theinstalled tree with
node.Cowright workaround
scripts/apply.cjspins the entry to@opengsd/gsd-core@1.16.0after every install; check C10verifies it is pinned and connected.
Evidence
docs/smoke/runs/2026-10-07/mechanical-final.json(C10)