magi-code 0.95.2

Repository-aware CLI coding agent for terminal work
Documentation
# Tools and safety

Magi-code uses tools to inspect repositories, edit files, run commands, research public pages, inspect images, and delegate work.

## Built-in tools

Common capabilities include:

- reading known files
- searching paths, text, and source structure
- creating and editing files
- running non-interactive shell commands
- viewing local images through a configured vision model
- searching and opening public web pages
- delegating independent work to subagents

Use `/settings` → Tools to enable or disable tools for Global or Project scope (`Ctrl-G`). Successful saves apply to future actions in the current session; enabling Code Mode requires restart.

## Review shell activity

Shell commands appear in Mission Control with an explanation of why they are being run. You can also run a command directly by starting a prompt with `!`:

```text
!git status
```

Shell guardrails inspect commands and bound execution, but they are not an operating-system sandbox. Magi-code runs with your account's filesystem and process permissions. Use a container or virtual machine for untrusted repositories.

## Batch tool calls with Code Mode

Code Mode lets the agent run a short JavaScript script that calls existing tools in one batch, such as reading many files, filtering search results, or applying repeated edits. It is on by default. Disable it under `/settings` → Tools → Code Mode, save, and restart.

Every inner call keeps normal approvals, hooks, cancellation, and session records. Nested calls appear in the Activity Tree. The transcript card shows intent, live progress, call counts, elapsed time, and changed files. Its model-response token count is an estimate, not billed usage.

Code Mode is not a transaction: completed edits and commands remain applied after a later failure or cancellation. See [Code Mode](../features/code-mode.md) for limits and recovery.

## Track files touched by shell commands

With Jev enabled, **Track Bash file activity** under `/settings` → Internal Tooling adds files that Bash commands likely read, wrote, or edited to Session Files. Restart after enabling. Simple literal reads are recognized locally; other commands are classified by Jev in bounded background work.

These entries are inferences. They never count as confirmed edits and never allow `hash_edit` without a fresh read. See [Jev and internal tooling](../features/jev-and-internal-tooling.md).

## Control path access

Tools normally work from the launch directory. Settings can permit or deny absolute paths for individual tools. Keep absolute-path access disabled when a task should remain inside one workspace.

## Images

The `view_image` tool sends a local image to the vision model configured in settings. It never falls back to the active chat model.

```json
{
  "capabilities": {
    "tools": {
      "view_image": {
        "vision_model": "openai-codex/gpt-5.5"
      }
    }
  }
}
```

Kitty and Ghostty can also show local image previews in the transcript. Displaying a preview does not call a provider. Unsupported terminals keep text-only cards.

## Web research

With an active Codex provider, public search uses Codex OAuth. Other providers require `EXA_API_KEY` for search. Opening a public URL does not require that key.

Never place search credentials in settings or prompts.

## Protect sensitive data

Tool results can enter provider context and saved sessions. Avoid asking magi-code to read secrets. Inspect session exports and review-comment expansions before sharing them.

Magi-code applies path checks, output bounds, environment filtering, and redaction in supported surfaces. These controls reduce exposure; they do not prove that arbitrary repository content is safe.

## Advanced reference

See [Tools and safety model](../features/tools-and-safety.md), [Security notes](../features/security.md), and [Local transcript images](../features/terminal-images.md) for exact policies and limits.