# Tools and safety
Magi-code uses tools to inspect repositories, edit files, run commands, research public pages, inspect images, and delegate work.
## Built-in tools
Common capabilities include:
- reading known files
- searching paths, text, and source structure
- creating and editing files
- running non-interactive shell commands
- viewing local images through a configured vision model
- searching and opening public web pages
- delegating independent work to subagents
Use `/settings` → Tools to enable or disable tools for Global or Project scope (`Ctrl-G`). Successful saves apply to future actions in the current session; enabling Code Mode requires restart.
## Review shell activity
Shell commands appear in Mission Control with an explanation of why they are being run. You can also run a command directly by starting a prompt with `!`:
```text
!git status
```
Shell guardrails inspect commands and bound execution, but they are not an operating-system sandbox. Magi-code runs with your account's filesystem and process permissions. Use a container or virtual machine for untrusted repositories.
## Batch tool calls with Code Mode
Code Mode lets the agent run a short JavaScript script that calls existing tools in one batch, such as reading many files, filtering search results, or applying repeated edits. It is on by default. Disable it under `/settings` → Tools → Code Mode, save, and restart.
Every inner call keeps normal approvals, hooks, cancellation, and session records. Nested calls appear in the Activity Tree. The transcript card shows intent, live progress, call counts, elapsed time, and changed files. Its model-response token count is an estimate, not billed usage.
Code Mode is not a transaction: completed edits and commands remain applied after a later failure or cancellation. See [Code Mode](../features/code-mode.md) for limits and recovery.
## Track files touched by shell commands
With Jev enabled, **Track Bash file activity** under `/settings` → Internal Tooling adds files that Bash commands likely read, wrote, or edited to Session Files. Restart after enabling. Simple literal reads are recognized locally; other commands are classified by Jev in bounded background work.
These entries are inferences. They never count as confirmed edits and never allow `hash_edit` without a fresh read. See [Jev and internal tooling](../features/jev-and-internal-tooling.md).
## Control path access
Tools normally work from the launch directory. Settings can permit or deny absolute paths for individual tools. Keep absolute-path access disabled when a task should remain inside one workspace.
## Images
The `view_image` tool sends a local image to the vision model configured in settings. It never falls back to the active chat model.
```json
{
"capabilities": {
"tools": {
"view_image": {
"vision_model": "openai-codex/gpt-5.5"
}
}
}
}
```
Kitty and Ghostty can also show local image previews in the transcript. Displaying a preview does not call a provider. Unsupported terminals keep text-only cards.
## Web research
With an active Codex provider, public search uses Codex OAuth. Other providers require `EXA_API_KEY` for search. Opening a public URL does not require that key.
Never place search credentials in settings or prompts.
## Protect sensitive data
Tool results can enter provider context and saved sessions. Avoid asking magi-code to read secrets. Inspect session exports and review-comment expansions before sharing them.
Magi-code applies path checks, output bounds, environment filtering, and redaction in supported surfaces. These controls reduce exposure; they do not prove that arbitrary repository content is safe.
## Advanced reference
See [Tools and safety model](../features/tools-and-safety.md), [Security notes](../features/security.md), and [Local transcript images](../features/terminal-images.md) for exact policies and limits.