Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Terminal agents: request only the missing execution scope

Last updated: 5 Oct 202611 min read
tutorial
AdvancedBy AITrove Editorial

A terminal agent may run in a sandbox that grants selected reads, writes, and network calls. A permission failure is evidence about the environment, not a signal to bypass it with another tool or path. Identify the exact operation, target, and reason it is needed; then request the narrow capability through the approved mechanism when the user's task calls for it. Keep independent work moving while the request is pending. A shell command that reads a protected file is still a protected read even if the ordinary file tool denied it. Prompts cannot turn an operating-system boundary into authorization.

Operational case

Manifest Gate's importer and tests are inside the writable checkout, so the agent can implement and validate the duplicate-slug fix locally. A later integration check needs a staging endpoint outside the sandbox network policy. The agent records the blocked endpoint and the purpose of the check, then completes local tests and a reviewable patch. It does not route through an unrelated browser session to evade the block. If access is not granted, the final report marks staging verification as incomplete without downgrading the local evidence.

Output
Allowed: edit importer and run local tests.
Blocked: staging endpoint request denied by network policy.
Request: access to the exact staging check, with purpose.
Meanwhile: finish local validation and diff review.
No access: report staging result as unverified.

Performance and operating cost

A denied operation can add waiting time, but repeated equivalent probes consume time without changing the permission state. Scope requests to the single missing resource rather than broad filesystem or network access. Recording the denial and local checks is O(1) per attempt plus the cost of those checks. A test omitted for environmental reasons must remain visible in the release packet.

Common Mistakes

  • Do not treat a sandbox denial as permission to try a side channel.
  • Do not ask for broad access when one endpoint or path is enough.
  • Do not silently label an unrun integration check as passed.

Connected lessons

prompt engineering
terminal agents
Storage details