3 ms·
Nobody talks about this but the security model is the thing that should disqualify most of these tools immediately. I spent a weekend auditing the network call
by kunalganglani 2mo ago
Nobody talks about this but the security model is the thing that should disqualify most of these tools immediately.
I spent a weekend auditing the network calls that three popular open-source coding agents make. Two of them send your file contents to external endpoints by default with zero sandboxing. No confirmation prompt, no allowlist, nothing. If you're running these on anything with proprietary code you're essentially uploading your source to a third party and hoping their privacy policy holds.
OpenCode is the worst offender here — the default config pulls from a remote provider URL and there's no way to even see what's being sent without packet inspection. You can lock it down but it requires manually editing YAML configs that aren't documented anywhere obvious. Aider at least respects .gitignore and keeps everything local unless you explicitly configure a remote endpoint.
The frustrating part is the actual coding capabilities are decent on several of these. Multi-file edits, git integration, context-aware suggestions — all solid. But none of that matters if the tool is silently exfiltrating your code. Audit the network layer before you evaluate anything else.