Skip to content

[feature] Preview and edit a shell result before sharing it with the model #281

Description

@AetherAI3

Problem

/shell-result currently turns the latest 8 KiB command capture directly into a model prompt. The README tells users to review output first, but the command provides no preview/editor for the exact bounded capture that will be sent.

Evidence: src/commands/console_input.ts and src/commands/chat.ts. The existing explicit-share boundary is useful; make it easier to use.

Proposed outcome

Stage the exact proposed shell attachment in a local preview with command, captured cwd, exit status, and truncation information. Let the user remove/edit lines, then choose Send or Cancel. Keep a clearly named explicit send form for scripts rather than introducing interactive prompts into pipes.

Constraints and alternatives

Do not automatically attach shell output to future prompts or saved chat. Preserve untrusted-data framing after editing. Reuse the existing redaction facilities as an aid, without presenting a filter as a guarantee. Cancelling the preview makes zero inference requests.

Bind the staged attachment to a command/session identity so a newly completed command cannot replace the capture the user reviewed. Selecting a range or editing text must preserve honest provenance about omissions.

Acceptance

  • The preview shows exactly the bytes/text destined for the next prompt, including bounded-output omission markers.
  • Edits/removals survive into the sent attachment; cancelled and empty selections remain local.
  • A newer result arriving while previewing cannot change the approved attachment.
  • Fixture tokens and environment values can be removed; output is sanitized for terminal controls while copyable text remains useful.
  • TTY, non-TTY, failed commands, Unicode, and truncated large logs are covered. No raw shell capture enters ordinary history or a support export through this flow.

Priority: P1. Focused follow-up to completed #244/#245/#247. Source reviewed at ca4180d (0.4.0 candidate). This ticket is an implementation spec; live service qualification remains separate.

Activity

  1. AetherAI3 commented on Oct 6, 2026

    @AetherAI3
    OwnerAuthor

    Closed by PR #308, merged as 881cd5c.

    Evidence at exact PR head 1d8373d: Linux CI completed Build and test with 3,368 tests, 3,357 passed, 11 skipped, 0 failed. The new preview/edit/send/cancel, immutable command binding, Unicode/sanitization, truncation, nonzero exit, TTY and line-mode, and no-history fixtures passed. Local Windows console/bounded-output tests passed 20/20; documentation and type checks passed.

    The staged preview is the exact sanitized attachment sent on approval. Edits/removals persist, a newer command cannot replace the reviewed result, and cancel or an empty selection makes no model request. /shell-result send is the explicit one-step path for pipes/JSON. The shell capture stays out of ordinary input history and support-bundle content.

    The PR records the non-code CI limits honestly: artifact storage quota blocked uploads, the pinned ATSv2 repository was unavailable, the published 0.4.0 operator packet failed the release-truth gate, and the Windows self-hosted runner was offline. CodeQL Analyze succeeded before its evidence-upload failure.

  2. AetherAI3 commented on Oct 6, 2026

    @AetherAI3
    OwnerAuthor

    Follow-up acceptance verification after #308 merged found remaining reproducible privacy/binding gaps at its exact tested head 1d8373d36f87cd9bed51432b857afc7272311d53; details are recorded in #308 (comment) . An additional harmless TTY fixture confirms that a submission-blocked shell attachment is restored into the ordinary composer, and pressing Enter then saves that attachment into ordinary history despite making zero model calls. No real credentials or external model were used.

    The current closed state came from #308's merge; it should not be treated as proof that every acceptance criterion passed. #309 is being reconciled into a targeted follow-up on the merged implementation, retaining the line-editor controls while fixing these boundaries and adding enabled-history, exact-wire, queued-binding and failure-path regressions. #284 remains sequenced after this reconciliation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions