Imported from fabioc-aloha/Alex_ACT_ONE (
skills/terminal-command-safety/SKILL.md). Install upstream withnpx skills add fabioc-aloha/Alex_ACT_ONE --skill terminal-command-safety. Copyright stays with the author.
Terminal Command Safety
The always-on instruction retains the Backtick Hazard and its temp-file rule. Use this skill after that floor is satisfied when execution needs a procedure for output capture, hang prevention, or host behavior.
Output Capture Failures
Terminal output can be silently lost or truncated.
- Redirect to file, then read:
cmd 2>&1 | Out-File $env:TEMP\out.txt - Pipe pagers through
Out-String - Sentinel:
; echo "EXIT_CODE:$LASTEXITCODE" - Limit volume:
Select-Object -First,-Tail,Format-Table - Avoid alt-buffer programs (
less,vim,man) — use non-interactive equivalents - If empty: retry with
get_terminal_output, then redirect to file, then check stderr
Terminal Hanging
- Use
mode=asyncfor commands over 15 seconds, including servers, builds, and test suites. VS Code 1.121+ may auto-promote a quiet synchronous command to the background; this remains the required agent intent and covers older hosts. - Never run interactive commands. Pre-answer with flags such as
--yesor--no-edit. - Set network timeouts such as
--max-timeor--prefer-offline. - Avoid heredoc blocks because they can desynchronize the terminal parser.
- Run one command at a time. Do not chain unrelated commands.
- Stop a stuck command with
send_to_terminaland Ctrl+C, or start a fresh terminal.
VS Code Platform Changes
Recent VS Code agentic-execution improvements reduce the need for some manual patterns above. The file-redirect fallback remains the safe default when full, unfiltered output matters.
| Surface | Behavior change | When the manual pattern still wins |
|---|---|---|
| 1.117 | Terminal output is auto-included after send_to_terminal; async-completion notifications fire automatically. |
Exact byte-for-byte diagnostic output is needed. |
| 1.118 | Agentic execution pre-filters terminal output. | Exact error strings, full test results, or encoding-sensitive output are needed. |
| 1.120-1.121 | chat.tools.compressOutput.enabled post-processes long output; one-shot async terminals auto-dispose. |
Raw lockfile diffs, install logs, or output that compression strips is needed. |
| 1.127 | macOS/Linux terminal commands are sandboxed by default. | Windows remains unchanged, so the resident Backtick Hazard still applies. |
Boundaries
- Do not weaken, duplicate, or bypass the resident Backtick Hazard floor.
- Do not send secrets through a terminal command or tool input.
- Do not treat a missing output line as proof that a command succeeded.
Anti-Patterns
| Anti-pattern | Correction |
|---|---|
| Relying on compressed output for a precise diagnosis | Redirect to a temporary file and inspect it. |
| Starting a long-running command synchronously | Use asynchronous execution when it must outlive the current response. |
| Retrying an interactive command unchanged | Find and provide its noninteractive flags. |
Would Revise If
Revisit by 2026-11-18 if the deferred procedure fails to load when a terminal command needs it, host behavior makes the version table inaccurate, or a terminal failure reaches the user because the resident Backtick Hazard alone was insufficient.