You trust your AI agent with your repo. Do you trust it with your SSH keys, your ~/.aws, your dotfiles? Most people running Claude Code, Codex, or OpenCode don’t think about it until it’s too late — and by then the agent has already read everything it could reach.
Greywall (Apache 2.0, Go) is a container-free, deny-by-default sandbox built specifically for AI coding agents on Linux and macOS. No Docker, no VMs — kernel-enforced isolation via Bubblewrap namespaces, Landlock, Seccomp BPF, eBPF monitoring, and a TUN-based network capture.
Here’s the scenario: You have OpenCode running as your ACP agent. IntelliJ IDEA connects via one plugin. AgentBridge connects via another. Both work fine individually. Run them at the same time? One breaks.
This isn’t a bug in your IDE plugin. It’s not a bug in AgentBridge. It’s an architectural property of how OpenCode’s ACP transport works.
OpenCode’s opencode acp command uses stdio transport — JSON-RPC 2.0 messages flow over a single stdin/stdout pipe. The relevant code in packages/opencode/src/cli/cmd/acp.ts creates one WritableStream for stdout and one ReadableStream for stdin. These are wrapped by ndJsonStream from the @agentclientprotocol/sdk for newline-delimited JSON framing.
CodeNomad is the prettiest OpenCode cockpit I’ve seen — ★2,427 on GitHub, MIT, TypeScript, Electron + Tauri desktop apps with a standalone server mode. Multi-instance workspaces, voice input, sidecars, theming, the works.
But I don’t use it. I looked at it, I ran it on the dev box, and I moved on. Here’s why — and what I looked at instead.
If you use OpenCode and want a GUI, CodeNomad is the right answer. It’s polished, active (Nov 2025, still pushing), and the server mode means you can expose it remotely. But it’s single-provider by design — OpenCode only. If you ever want to run Claude Code and OpenCode side by side, or have human review gates between agent work, CodeNomad isn’t built for that.