Skip to main content
opensre ask is OpenSRE’s headless, one-shot CLI command. It runs one agent turn, prints the response, and exits instead of opening the interactive shell. It uses the LLM provider from opensre onboard and any tools configured with opensre integrations setup.

Live activity

When both output streams are attached to a terminal, ask starts with a Thinking… spinner with elapsed time. It switches to the active diagnostic tool (or a neutral tool count for a batch) when tools are invoked. The final answer remains on standard output without echoing raw tool transcripts. Piped and --json runs do not emit progress, so their output remains machine-readable. Pass - as the prompt to read all of standard input:

Tool approvals

Read-only tools run automatically. Tools that mutate state, contact an external service, explicitly require approval, or do not declare their side effects are denied by default. Authorize only the tools needed for this invocation by repeating --allowed-tool:
An unknown tool name is rejected before the agent starts. The authorization is not saved and applies only to that process. The root --yes (-y) option does not authorize agent tools. --dangerously-bypass-approvals authorizes every approval-gated tool for that invocation. Use it only in a trusted environment where the prompt and connected integrations are controlled:
Do not combine the bypass flag with --allowed-tool. Neither option bypasses the operating-system permissions or sandboxing that applies to OpenSRE.

JSON output and exit codes

Put the global --json option before ask for machine-readable output:
The command writes one JSON object with status, response, denied_tools, and error. The error value is either null or an object with message and suggestion.