Otōto 2.8.4 Otōto 2.8.4 adds an `ototo update` command that verifies a downloaded package against its `.SHA256SUMS` and `.sig` files using Otōto's release key before running the package's `install.sh`, preserving existing settings, with a `--dry-run` flag for verification only. The release's `install.sh` now also configures Otōto in OpenCode alongside or instead of Claude Code, registering it in `~/.config/opencode/opencode.json` with a 30-minute (1800000 ms) per-call timeout and disabling OpenCode's own grep and glob unless `--keep-search` is passed. The update also fixes parsing of file lists sent as JSON strings such as `"[\"src/a.rs\"]"`, which are now read as the list rather than as a single nonexistent file. - ototo update . Put the package we send, with its .SHA256SUMS and .sig , in ~/Downloads and run ototo update : it checks them against Otōto's release key, then runs the package's install.sh , which keeps your settings. --dry-run only checks; a path picks another package. This one you still install with sh install.sh . - OpenCode. install.sh now sets Otōto up in OpenCode too, beside Claude Code or on its own. In ~/.config/opencode/opencode.json it registers Otōto with 30 minutes for each call OpenCode otherwise gives up on a tool after about a minute, and an ask can take longer , lists Otōto's instructions your own AGENTS.md is left as it is , and turns OpenCode's own grep and glob off --keep-search keeps them . A config with comments is left alone, and it prints what to add by hand. ototo doctor checks it; uninstall.sh takes it out. Set OpenCode up by hand before? Its mcp.ototo needs "timeout": 1800000 . - Fewer wasted reads. A list of files sent as a string of JSON " \"src/a.rs\" " is now read as that list, not as one file that is not there.