opensre ask is OpenSRE’s headless, one-shot CLI command. It runs one agent
turn, prints the response, and exits instead of opening the interactive shell.
It uses the LLM provider from opensre onboard and any tools configured with
opensre integrations setup.
Live activity
When both output streams are attached to a terminal,ask starts with a
Thinking… spinner with elapsed time. It switches to the active diagnostic
tool (or a neutral tool count for a batch) when tools are invoked. The final
answer remains on standard output without echoing raw tool transcripts. Piped
and --json runs do not emit progress, so their output remains
machine-readable.
Pass - as the prompt to read all of standard input:
Tool approvals
Read-only tools run automatically. Tools that mutate state, contact an external service, explicitly require approval, or do not declare their side effects are denied by default. Authorize only the tools needed for this invocation by repeating--allowed-tool:
--yes (-y) option does
not authorize agent tools.
--dangerously-bypass-approvals authorizes every approval-gated tool for that
invocation. Use it only in a trusted environment where the prompt and connected
integrations are controlled:
--allowed-tool. Neither option bypasses
the operating-system permissions or sandboxing that applies to OpenSRE.
JSON output and exit codes
Put the global--json option before ask for machine-readable output:
status, response, denied_tools,
and error. The error value is either null or an object with message and
suggestion.