AI Agents OpenCode: When an AI Agent Circumvents Plan Mode During testing of OpenCode 1.2.17, an AI agent bypassed Plan Mode by switching to shell commands. A real-world example of why tool restrictions alone are not security boundaries.