An Agent can read files, modify a workspace, and run terminal commands. Choose a permission policy before running, and give automated tasks explicit workspace, model, timeout, and step boundaries.An active plan does not change the permission policy for the execution phase. Auto or Full access can still be combined with Plan Mode when you want to review scope first.Do not put keys in a repository, Use separate data directories on remote hosts, shared machines, and CI runners so accounts do not share sessions, logs, or provider configuration.
Permission modes
TUI
Use
Alt+M to switch Ask, Auto, and Full access in the TUI. Run /permission status to inspect the current mode.Headless
Headless uses CLI policy names:smart corresponds to TUI Auto. Headless does not support ask because it has no human approval surface; use the TUI or ACP when a person must approve an action.Plan Mode is separate
Plan Mode controls whether the agent plans before execution. Permission mode controls how tool actions are approved:Recommended safety baseline
Interactive development
- Use Ask or Auto by default.
- Check paths and commands before deletion, bulk writes, or external requests.
- Run
mcode init .in an unfamiliar repository and review itsAGENTS.md. - Use
/status,/doctor, and/contextto inspect account, configuration, and context state. - Inspect the diff and run relevant tests before accepting the result.
CI and batch jobs
- Set an explicit
--cwd; do not depend on the caller’s current directory. - Set
--timeoutand--max-stepsto bound execution. - Use
--permission fulloroffonly in an isolated workspace. - Use
--output-format jsonorstream-json; do not infer status from human-readable text. - Check both the process exit code and the JSON
status. - Preserve stdout and stderr separately so diagnostics cannot corrupt machine output.
Protect credentials
Provider API keys are read from environment variables:AGENTS.md, prompts, screenshots, or CI logs. Login callback URLs can contain temporary credentials and must not be shared or committed. mcode provider list shows only managed-login or masked-key status.Workspace and data directory
The default data root is~/.minimax; use MINIMAX_DATA_DIR to select another directory:Protocol boundaries
- ACP stdout is reserved for protocol messages; logs go to stderr.
mcode execfails on pending questionnaires or permission requests instead of bypassing interaction.- Browser and Computer Use are desktop-host capabilities and are not automatically available in the CLI.