Skip to main content
opensre ask is OpenSRE’s headless, one-shot CLI command. It runs one agent turn, prints the response, and exits instead of opening the interactive shell. It uses the provider, integrations, and tools configured by opensre onboard.
Pass - as the prompt to read all of standard input:
For a structured alert investigation, use opensre investigate instead.

Tool approvals

Read-only tools run automatically. Tools that mutate state, contact an external service, explicitly require approval, or do not declare their side effects are denied by default. Authorize only the tools needed for this invocation by repeating --allowed-tool:
An unknown tool name is rejected before the agent starts. The authorization is not saved and applies only to that process. The root --yes (-y) option does not authorize agent tools. --dangerously-bypass-approvals authorizes every approval-gated tool for that invocation. Use it only in a trusted environment where the prompt and connected integrations are controlled:
Do not combine the bypass flag with --allowed-tool. Neither option bypasses the operating-system permissions or sandboxing that applies to OpenSRE.

JSON output and exit codes

Put the global --json option before ask for machine-readable output:
The command writes one JSON object with status, response, denied_tools, and error. The error value is either null or an object with message and suggestion.