opensre ask is OpenSRE’s headless, one-shot CLI command. It runs one agent
turn, prints the response, and exits instead of opening the interactive shell.
It uses the provider, integrations, and tools configured by opensre onboard.
- as the prompt to read all of standard input:
opensre investigate instead.
Tool approvals
Read-only tools run automatically. Tools that mutate state, contact an external service, explicitly require approval, or do not declare their side effects are denied by default. Authorize only the tools needed for this invocation by repeating--allowed-tool:
--yes (-y) option does
not authorize agent tools.
--dangerously-bypass-approvals authorizes every approval-gated tool for that
invocation. Use it only in a trusted environment where the prompt and connected
integrations are controlled:
--allowed-tool. Neither option bypasses
the operating-system permissions or sandboxing that applies to OpenSRE.
JSON output and exit codes
Put the global--json option before ask for machine-readable output:
status, response, denied_tools,
and error. The error value is either null or an object with message and
suggestion.