Overview
The interactive shell saves every line you type to a history file so up-arrow recall and/history work across sessions. Each new prompt reloads the file
when another running shell has changed it, so concurrent sessions share recent
commands without a restart. Separately, it records each LLM prompt/response turn
for local debugging and /resume. Incident prompts can include sensitive
identifiers and tokens, so the shell:
- Redacts known token shapes before each entry is written to disk
- Supports disabling persistence entirely (memory-only mode)
- Caps how many entries are kept (oldest pruned)
- Offers
/history clearto wipe the file on demand
~/.opensre/interactive_history. See
Prompt and response logging for the separate LLM
turn log and remote product-analytics forwarding.
Defaults
Redaction patterns
The built-in patterns target token shapes that are distinctive enough to keep false positives on natural-language incident text low. Each match becomes a labeled placeholder.
Redaction applies only to persistent history. The line you typed is still
passed to OpenSRE’s normal pipeline as you typed it.
Slash commands
Configuration
Settings resolve from (highest wins):- Environment variables
- The
interactive.historyblock in~/.opensre/config.yml - Built-in defaults
Environment variables
Config file
Prompt and response logging
Separately from typed-command history, OpenSRE records each agent turn — the submitted prompt and final response — in the interactive shell,opensre ask, gateway chat, and scheduled or embedded agent runs. Failures and
cancellations retain the prompt and available error details. Each continuation
is recorded separately. This log is richer than command history (it includes model
output, not just what you typed) and is used for two purposes:
- Local debugging /
/resume: appended as JSON Lines to~/.opensre/prompt_log.jsonl, and folded into the session file so/resumecan restore conversation context. Gateway logs use the organization and user conversation directory rather than the host-wide default. An explicitOPENSRE_PROMPT_LOG_PATHoverrides that location. - Product analytics: forwarded through the first-party OpenSRE app endpoint
as an
$ai_generationevent (model, provider, latency, token counts, and the prompt/response text) so usage and quality can be tracked. Failed turns carry structured error properties ($ai_is_error,$ai_error,error_kind). Turns handled entirely by terminal tools or slash commands report$ai_model/$ai_providerasno_conversational_agent; when a conversational reply was intended but the LLM provider failed (missing API key, model access, quota, auth), the event reports the attempted model (orunknown) plus anai_error_kindbucket (not_configured,quota,auth, orprovider_error).
Defaults
Environment variables
The separate operations log at
~/.opensre/operations_log.jsonl records agent
and scheduler lifecycle breadcrumbs such as loop start, iteration outcome, loop
creation, and delivery status. It does not store prompt or response bodies.
Remote forwarding for this event also honors the global telemetry opt-outs: set
OPENSRE_NO_TELEMETRY=1, OPENSRE_ANALYTICS_DISABLED=1, or DO_NOT_TRACK=1
to stop all product analytics (including $ai_generation) without touching the
local JSONL file. See
Environment variables.
Config file
Threat model
The history file is plain text on local disk at~/.opensre/interactive_history, with the user’s default file permissions.
Built-in redaction targets common token shapes only — it is not a substitute for
proper secret handling. Treat the file as confidential and be aware:
- A determined attacker with read access to your home directory can still read entries written before redaction was enabled.
- Redaction cannot detect tokens that look like normal text (for example a natural-language password). Do not paste secrets you would not put in a system log.
- Custom redaction patterns are not supported in v1. To redact internal token
shapes, use
/history offfor that session and run/history clearafterwards.
OPENSRE_NO_TELEMETRY=1 (or OPENSRE_PROMPT_LOG_DISABLED=1 to also stop the
local file) rather than relying on redaction alone.
For a strong local posture: set OPENSRE_HISTORY_ENABLED=0 and
OPENSRE_NO_TELEMETRY=1. That stops command-history persistence and remote analytics.
Up-arrow recall across sessions is lost. /resume conversation context also
depends on session files and the prompt log — set
OPENSRE_PROMPT_LOG_DISABLED=1 (or clear session/prompt-log data) if you need
that path off too. Otherwise rely on the in-memory ring for the current process.