Skip to content

the installer writes an unpinned gsd MCP entry, so every OpenCode start fetches npm latest #5263

Description

@stiefenm
  • Found: 2026-10-06, Cowright Phase 1 research (Pitfall 11)
  • Environment: GSD Core 1.16.0 (--opencode --global), OpenCode 1.18.35, Linux

Summary

The OpenCode install writes "mcp": {"gsd": {"command": ["npx", "-y", "-p", "@opengsd/gsd-core", "gsd-mcp-server"]}}. Every OpenCode start, including every spawned opencode run worker, resolves
@opengsd/gsd-core to whatever npm latest is at that moment. The MCP server can therefore differ
from the installed version and needs the network on every start. It also widens the supply-chain
surface to every future publish.

Minimal repro

  1. npx @opengsd/gsd-core@1.16.0 --opencode --global
  2. Read mcp.gsd.command in ~/.config/opencode/opencode.jsonc: no version in the package spec.

Expected

The entry pins the installed version (@opengsd/gsd-core@1.16.0), or points at the installed tree's
own server script.

Actual

Unpinned package spec.

Suggested fix

Write @opengsd/gsd-core@<installed version> into the MCP entry, or run the server from the
installed tree with node.

Cowright workaround

scripts/apply.cjs pins the entry to @opengsd/gsd-core@1.16.0 after every install; check C10
verifies it is pinned and connected.

Evidence

  • docs/smoke/runs/2026-10-07/mechanical-final.json (C10)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs-triageNew issue awaiting maintainer review

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions