# Command Proposal

> Every agent CLI runs inside a sandbox, and when that sandbox refuses a command the agent used to have only one way out: print the line in its answer and ask you to run it somewhere else, then paste the output back.

- Area: Desktop app
- Plans: All plans
- Last checked against the product: 2026-09-26
- Web page: https://agentsroom.dev/docs/command-proposal

## What it does

Every agent CLI runs inside a sandbox, and when that sandbox refuses a command the agent used to have only one way out: print the line in its answer and ask you to run it somewhere else, then paste the output back. A command proposal replaces that dead end with a decision. The agent calls a tool, the line appears as a card in that agent's own panel with the reason it cannot run it itself, and one click runs it in a real terminal tab that AgentsRoom owns, so the agent can read the output on its own. Nothing runs until you say so, and nothing is remembered: you authorise one execution of one line.

## Where to find it

- The card appears in the terminal panel of the agent that proposed the command, titled **Run this command?** with the subtitle **This agent is waiting for your answer**. It never takes over the screen.
- You are told the usual way an agent needs you: the red dot on its tab and in the sidebar, the **Needs input** inbox, the dock badge and a push notification on your phone.
- The terminal the command runs in opens in the Dev Commands strip at the bottom of the room, next to the agent's own tab.

## How to use it

1. Open the agent that is waiting. The card shows the command line, the working directory as `<folder> · <project>`, and the agent's own explanation of why its sandbox refused it.
2. Read the line. The card also says: **The agent's own sandbox refused this command. Play runs it in a terminal tab next to this agent, which then reads the output itself.**
3. Click **Play** to run it. A terminal tab opens, labelled with the command line itself, carrying the avatar of the agent that proposed it (**Command started by <name>**, **Go to this agent**). The agent is handed the tab's id and reads the output itself.
4. Or click **Reject**. The optional field **Why not? (optional, sent to the agent)** goes back to the agent with the refusal, so it can propose something else instead of guessing.
5. Answer nothing and the card expires (the footnote counts down, **Expires in ...**). Nothing runs, and the agent is told nobody answered, not that you refused.

## Settings

None. There is deliberately no "always allow" option: each proposal is a different shell line, so a permanent yes would be a blank cheque on your shell.

## Agent tools (MCP)

- `commands_propose`: ask you to run one shell line the agent cannot run itself. Takes `command` (required), `reason` (required, the sentence you read on the card) and `cwd` (optional, relative to the project root, default `.`). It executes nothing by itself and returns whether you approved, rejected (with your note) or did not answer.
- `commands_output`: how the agent reads what the approved command printed, using the `commandId` the proposal returned (80 lines by default, 300 maximum).
- `commands_create` and `commands_run` are the other path: they are for a command you want to keep and re-run, not for a one-off.

## Providers

All providers, no difference. The tool is served by the AgentsRoom MCP server, which is injected into every CLI, so an agent running on Codex, Antigravity or any other CLI can ask exactly like a Claude agent.

## Mobile

Present since 2026-09-26. The **Run this command?** card also appears on the phone, above the composer of the agent that asked, even in the conversation view: same command, same optional note, same countdown. **Play** runs it in a terminal tab on the computer, which the agent then reads; **Reject** hands your note back. The first answer wins, on either screen.

## Limits

- The card waits two minutes; after that the proposal expires and the agent is told nobody answered.
- A command containing a `{{secret:NAME}}` reference is refused before you ever see it: resolving the value would put it in the process list and in the terminal output, where an agent could read it back. Expose the secret as an environment variable and write the command against that variable instead.
- The command is never saved: it opens a throwaway tab, does not join your saved commands, and is not replayed when the app restarts.
- Duplicating that tab opens a blank shell, not a second run.
- If your plan's limit of parallel dev commands is already reached, the approval cannot open a terminal and the agent is asked to try again after you close a tab.
- If AgentsRoom cannot tell which agent is asking, the proposal is refused: there would be no panel to ask you in.

## Common questions

- **Why is an agent asking me instead of just running it?** Its own sandbox refused the command (a write outside the workspace, a network call, an elevated tool). The card is the only channel it has left.
- **Where does the output go?** Into the terminal tab that opens on Play, which the agent reads itself. You do not have to copy anything back.
- **Can I make it stop asking?** Not with a checkbox. Widen the CLI's own sandbox settings, or save the command yourself so the agent can start it with `commands_run`.
- **I clicked Reject, what does the agent do?** It is told not to run the line another way and not to propose it again, and it gets your note if you wrote one.

## Related

- [Dev Terminals](https://agentsroom.dev/docs/dev-terminals.md): the terminal strip the approved command runs in, and the saved commands an agent can start by itself.
- [Secret Manager](https://agentsroom.dev/docs/secret-manager.md): why `{{secret:NAME}}` cannot appear in a proposed command.
- [Needs Input Inbox](https://agentsroom.dev/docs/needs-input-inbox.md): where an agent waiting for this card shows up.
- [Agent Delegation](https://agentsroom.dev/docs/agent-delegation.md): the other tool that pauses on a human decision.
