TurenOS is Turen Labs' batteries-included Desktop workbench for security engineers. It starts from the excellent OpenCode agent foundation and is being shaped into a focused environment for code review, application security, investigation, and remediation.
Important
TurenOS is under active development. Security-specific capabilities continue to evolve, so review the documented trust boundaries before using them in sensitive environments.
TurenOS should make a useful security workflow available without spending the first hour wiring tools together:
- repository and dependency reconnaissance;
- Batou-powered code and application security analysis;
- secret, SAST, dependency, and supply-chain checks behind one agent workflow;
- evidence-preserving findings with file, line, command, and artifact provenance;
- review and remediation loops that can prove a fix rather than merely suggest one;
- explicit execution policies, isolated runners, audit logs, and safe defaults for risky tools.
The first milestone is a stable, continuously mergeable TurenOS distribution. Security capabilities should be added as modular batteries rather than buried in an unmaintainable fork.
- model-agnostic TurenOS Desktop client with a bundled local agent server;
- local Claude Code provider (
claude-code/fable,sonnet,opus, andhaiku) using an existingclaude auth loginsubscription instead of an Anthropic API key; - deep links (
forge://), config (forge.json), and data paths (.forge) — retained as load-bearing compatibility identifiers for existing installs; - MCP, LSP, permission, session, and tool infrastructure inherited from OpenCode;
- signed TurenOS Desktop builds for macOS, Linux, and Windows;
- a bundled native runtime used by Desktop locally and in managed WSL environments;
- cross-platform release packaging and upstream compatibility tracking.
TurenOS is not a sandbox. Agents can execute commands and modify files with your user privileges. Read SECURITY.md before using it on untrusted repositories.
Engineering documentation lives in docs/. Start with:
- Claude Code provider — using a local
claude auth loginsubscription instead of an API key. - Architecture — package boundaries, runtime topology, and durable data flows.
- Systems and subsystems — responsibilities, ownership, and failure behavior across TurenOS.
- Branding and compatibility — why some
forgeidentifiers remain stable. - Secure storage — how credentials are encrypted.
- Memory — durable project memory.
- Automations — durable in-app workflows with interval/cron schedules,
per-step
when/onFailureconditions, and local file-change/session-end event triggers. - Token efficiency — measured context cost against Claude Code and Codex.
TurenOS pins Bun 1.4.2.
bun install --frozen-lockfile
bun devSee CONTRIBUTING.md for the pinned-runner fallback, build commands, and checks.
packages/forge— bundled TurenOS agent runtime, server, tools, and native sidecar build.packages/core— shared Effect services and domain logic.packages/app— web and desktop renderer.packages/desktop— TurenOS Electron host and packaging.packages/ui— shared UI system and TurenOS identity.packages/sdkandpackages/sdk-next— client SDKs.
All TurenOS-owned workspace packages use the @turenlabs/* scope. Upstream provider IDs and durable migration keys remain unchanged where compatibility requires them. See branding and compatibility before changing a forge identifier.
TurenOS is an independently maintained hard fork of OpenCode. The projects diverged after OpenCode commit 3a1c6df9e24672f0761a6ced18e1315d89334baf on July 17, 2026. Changes after that fork point are TurenOS-specific unless otherwise attributed; this repository does not represent later OpenCode releases.
OpenCode and TurenOS are distributed under the MIT License. See LICENSE and NOTICE for attribution.
