Stops Claude reading a file over 1,000 lines whole (with Read, cat or Get-Content) and gives it an outline tool (definitions with line numbers) so it reads…

Make the $20 Claude Pro plan last longer in Claude Code.
Twenty-two small mods that show you exactly where your usage goes and cut the waste. One mod makes a model call: prompt-polish, once each time you press Improve, and never on its own. The others make none. None adds anything to the system prompt (read-cap adds one tool, which Claude Code lists by name only until Claude first uses it; write-guard adds one line to a tool result at most once per conversation; compact-keeper adds a note of at most 4,000 characters after a compaction): every figure on screen is one Claude Code already reports, or a time the mod measured.
| Mod | What it does | Where |
|---|---|---|
| tool-diet | Loads tools you have not used lately on demand instead of with every request | Everywhere |
| skill-diet | Lists skills you have not used lately in this project by name only, without their descriptions | Everywhere |
| agent-diet | Runs Explore subagents on Haiku instead of your main model | Everywhere |
| context-xray | /xray opens the exact breakdown of what fills your context window | Everywhere |
| pro-hud | Live meters above the prompt for your 5-hour session, your week and the context window, plus a per-turn receipt of tokens in, cached and out | Claude desktop app |
| output-diet | Trims long shell output, search results and subagent reports before Claude reads them, keeping the head, the tail and the error lines; the untrimmed text is saved to a file Claude can open without a permission prompt | Everywhere |
| reread-guard | Skips Claude re-reading a file it already read when the file has not changed, with Read or a plain cat, sed -n, head, tail or Get-Content; a deliberate retry still goes through | Everywhere |
| write-guard | Steers Claude to Edit instead of rewriting an existing file in full with Write; a deliberate rewrite still goes through | Everywhere |
| loop-guard | Holds back a shell command that already failed twice in a row, so Claude changes approach | Everywhere |
| cmd-diet | Adds quiet flags to noisy shell commands before they run, so Claude reads short output from the start; errors, failures and warnings stay in full | Everywhere |
| gh-account | Runs each git push, pull, fetch, clone and gh command as the logged-in GitHub account that can see the repository, without switching the active account | Everywhere |
| cache-clock | Counts down until the prompt cache expires; once it has, shows exactly how many tokens your next message will re-send uncached | Everywhere |
| read-cap | Stops Claude reading a file over 1,000 lines whole (with Read, cat or Get-Content) and gives it an outline tool, so it reads only the lines it needs; a retry still reads the whole file | Everywhere |
| session-receipt | /receipt opens a pane with the exact tokens every turn of the session spent, and the costliest turns | Everywhere |
| peek | Typing status while background tasks run opens a pane with each one's exact elapsed time and last output lines, instead of sending the prompt to Claude | Everywhere |
| budget-guard | Holds a prompt back once your 5-hour or weekly usage reaches your limit (90% by default); sending it again goes through | Everywhere |
| turn-budget | When one turn uses more than +5 session points, writes a handoff and continues in a fresh session by itself; /handoff any time | Everywhere |
| compact-keeper | After a compaction, adds a note of exact facts from before it: your latest prompt in full, the todo list, the last failed command, files edited | Everywhere |
| collision-guard | Asks before Claude edits a file another chat on this machine changed in the last 30 minutes | Everywhere |
| answer-pane | Explain, plan and ELI5 pages drawn natively in a side pane; plans have decision buttons and Respond fills the prompt box | Desktop app (no diagrams in the terminal) |
| prompt-polish | An Improve button beside Send (above the prompt in the terminal) rewrites your draft with Opus at low effort and puts it back in the box; Undo restores it. One model call per press | Everywhere |
| kit-updates | Tells you when an installed mod from this kit has a newer version or a new mod joins the kit; /kit-update installs updates and new mods | Everywhere |

In Claude Code:
/plugin marketplace add VedantAndhale/claude-pro-kit
/plugin install tool-diet@claude-pro-kit
/plugin install skill-diet@claude-pro-kit
/plugin install agent-diet@claude-pro-kit
/plugin install context-xray@claude-pro-kit
/plugin install pro-hud@claude-pro-kit
/plugin install output-diet@claude-pro-kit
/plugin install reread-guard@claude-pro-kit
/plugin install write-guard@claude-pro-kit
/plugin install loop-guard@claude-pro-kit
/plugin install cmd-diet@claude-pro-kit
/plugin install gh-account@claude-pro-kit
/plugin install cache-clock@claude-pro-kit
/plugin install read-cap@claude-pro-kit
/plugin install session-receipt@claude-pro-kit
/plugin install peek@claude-pro-kit
/plugin install budget-guard@claude-pro-kit
/plugin install turn-budget@claude-pro-kit
/plugin install compact-keeper@claude-pro-kit
/plugin install collision-guard@claude-pro-kit
/plugin install answer-pane@claude-pro-kit
/plugin install prompt-polish@claude-pro-kit
/plugin install kit-updates@claude-pro-kit
Updates are off by default for marketplaces you add yourself. With kit-updates installed you are told when a fix ships and /kit-update installs it, from the desktop app or the terminal. Without it, turn on auto-update once: in a terminal, run claude, then /plugin → Marketplaces → claude-pro-kit → Enable auto-update; the desktop app has no toggle for it.
Install any one on its own; they do not depend on each other. Mods are not sandboxed, so read the code before installing: each mod is a single file under plugins/<name>/hooks/.
Every tool listed in front sends its whole description and schema with every request. A deferred tool is listed by name only, and Claude loads it through ToolSearch when it needs it; Claude Code already does this for most MCP tools. tool-diet does it for the rest of the tools you are not using: anything outside the core set (Bash, PowerShell, Read, Edit, Write, Glob, Grep, Agent, Skill, ToolSearch, TodoWrite, AskUserQuestion) that you have not used in your last five sessions.
Measured with one prompt, "Reply with just OK.", in a fresh session, as the API reported each request:
| Prompt tokens per request | |
|---|---|
| Without tool-diet | 43,859 |
| With tool-diet | 27,905 |
| Change | −15,954 (−36%) |
On that setup, the largest tool moved was Artifact, whose description alone is 19,870 characters. What moves depends on your tools and your habits; /xray shows yours.
/tool-diet lists what is on demand this session, grouped by where each tool comes from; /tool-diet keep <tool> always loads one, unkeep undoes it, and /tool-diet off|on switches it. Answers are toasts, so they add nothing to the conversation. The status line keeps the count: 38 tools on demand.
Every request carries the skill listing: each installed skill's name and its whole description. With a few plugins installed that is dozens of skills, most of which a given project never uses (video skills in a backend repo, document skills in a game). skill-diet keeps the skills you used lately in this project listed in full and lists the rest on one line by name only. The Skill tool still loads any of them, and typing /name still works.
Measured with one prompt, "Reply with just OK.", in a fresh session with 45 skills installed and the other mods on, as the API reported the request:
| Prompt tokens per request | |
|---|---|
| Without skill-diet | 27,423 |
| With skill-diet | 19,197 |
| Change | −8,226 (−30%) |
In the same setup, asked to fill in a PDF form, Claude found anthropic-skills:pdf from its name alone and loaded it with the Skill tool. What moves depends on your skills; /xray shows yours.
/name or called by Claude through the Skill tool./skill-diet shows what is listed by name only this session and how many characters left the listing; /skill-diet keep <skill> always lists one in full, unkeep undoes it, and /skill-diet off|on switches it. Answers are toasts, so they add nothing to the conversation. The status line keeps the count, in the form <n> skills by name only, <n> characters off./xray shows the skills line before and after, in tokens.A subagent runs on your main model unless its definition or Claude's Agent call names another. Explore only searches and reads, yet in the author's own 85 subagent transcripts, every one of the 2,043 Explore requests ran on Opus or Sonnet, reading 147,298,992 input tokens. agent-diet starts the agent types you list (Explore by default) on Haiku.
/agent-diet shows the setting and how many subagents it moved this session; /agent-diet model haiku|sonnet|opus picks the model, /agent-diet add|remove <agent type> changes the list, and /agent-diet off|on switches it. Answers are toasts, so they add nothing to the conversation. The status line keeps the count, in the form 2 subagents on haiku.Measured with claude -p --model sonnet --output-format json on a task that sends one Explore subagent to find a file, three runs each in alternating order. Every run found the file. Figures are the cost and tokens Claude Code reported per model:
| Run | Without: cost | Without: Sonnet tokens in | With: cost | With: Sonnet tokens in | With: Haiku tokens in |
|---|---|---|---|---|---|
| 1 | $0.05692 | 68,395 | $0.03724 | 40,213 | 27,848 |
| 2 | $0.05577 | 68,111 | $0.03764 | 39,593 | 27,872 |
| 3 | $0.05441 | 68,123 | $0.03736 | 40,184 | 42,770 |
| Average | $0.05570 | $0.03741 |

/xray opens a pane with the exact breakdown /context computes: what is sent with every request (system prompt, tools, MCP tools, memory files, skills, messages), what is loaded on demand, which MCP tools load every time, and each memory file's size. It measures when the pane opens and when you press Refresh (or r), never in the background, because the exact count sends one token-count request per tool and memory file.
Opens by itself when the context crosses 60% and again at 80%, with a toast pointing at /compact and /handoff. /xray auto off keeps it to /xray only.
The recording at the top of this page is the band. In text:
Session ━━━━━━━━━━━━━━────── 69% resets in 32m
Week ━━━━━━━━━━━━━━━───── 74% resets in 4d 17h
Context ━━━━━━━━──────────── 44% 436,034 tokens
This turn 1m 35s · 1 tool · 0 files edited · 436,034 in · 431,260 cached · 580 out
On a wide window the three meters sit side by side on one row; on a narrow one each figure on the turn line wraps whole rather than being cut off.
/compact when it climbs.· session 20%, and finished tool calls draw as one line: status dot, tool, target, time./hud shows what is on; /hud all on|off, or /hud band|spinner|cards on|off. The answer is a toast, so toggling adds nothing to the conversation. It draws in the desktop app only and leaves the terminal as it is. Rows other mods put above the prompt still draw beneath the band.
Weekly toasts at 50%, 75% and 90% of the week, once each, because the weekly limit drains quietly across many sessions.
When a Bash or PowerShell result runs past 120 lines or 8,000 characters, Claude reads:
[output-diet: 82/500 lines shown; all 500 in ~/.claude/projects/<project>/<session>/tool-results/output-diet-<call>.txt]
<first 30 lines>
… [lines 31–450 omitted; error/warning lines from them:]
250│ ERROR: build failed in src/app.ts
300│ Warning: deprecated API
…
<last 50 lines>
3 trimmed · 41,200 chars saved.tool-results folder, beside the transcript, where Claude Code keeps the outputs it saves itself, so Claude can open it without a permission prompt. When that folder cannot be found, it goes under ~/.claude/output-diet/ (or CLAUDE_CONFIG_DIR).Grep result past the same limits keeps its first 100 lines, with a note to narrow the search: [output-diet: first 100/252 lines shown; narrow the search, or read all in …]. In the author's 1,048 past Grep results, 26 went past the limits, and keeping the first 100 lines would have cut 104,052 characters. Glob is left alone: none of 128 went past.When Claude asks to Read the same range of the same file again in the same conversation, and the file's size and modification time have not changed, the read is skipped and Claude is told to use the copy it has. Any edit, a different range, or a subagent (which has its own context) reads freely. Claude Code can clear old tool results from context, so retrying the identical read straight after a skip always goes through. The record resets on /compact and /clear.
What Claude is told in place of the repeat read, kept to one line because the model reads it:
api.ts unchanged since you read it; use that copy. If it's gone from context, retry the same Read.
Shell reads too. Claude often reads a file with the shell instead of Read: in the author's transcripts, 318 sed -n runs went past the guard. A shell command that only prints one file is now treated the same way: cat FILE, sed -n 'A,Bp' FILE, head -n N / tail -n N, and in PowerShell Get-Content, gc, cat or type (with -TotalCount, -Head, -First, -Tail, -Last or -Raw). The same range of the same unchanged file is skipped once, and retrying the same command goes through. A whole cat after a whole Read that showed every line counts as a repeat. A pipe, a chain, a variable, a glob or any other flag runs untouched. A shell read never counts as a Read, since Edit needs a real one first.
The status line counts them: 2 re-reads skipped.
Write sends the whole file as Claude's output, the most expensive kind of token; Edit sends only the lines that change. Claude sometimes rewrites a file it has already read in full to change a few lines. In the author's own 272 session transcripts, 141 writes rewrote a file Claude had already read or written (999,273 characters), and 112 of them followed an earlier rewrite in the same session. Of the 512,847 characters in the rewrites whose previous version was in the transcript, 171,325 had changed.
A hook runs after Claude has written the content, so write-guard cannot save the rewrite it sees; it stops the ones after it:
You rewrote all of api.ts. For changes to an existing file use Edit: it sends only the changed lines.api.ts exists; change it with Edit, not a full Write. If a full rewrite is intended, retry the same Write. Retrying the same Write goes through./clear starts over.1 full rewrite held back.Each retry of a failing command re-sends the whole conversation, and the same command usually fails the same way. In the author's 272 session transcripts, 10 commands failed 3 or more times, 38 runs between them.
Once the exact same Bash or PowerShell command has failed twice in a row, the next try is held back once, and Claude is told:
This exact command failed 2 times in a row. Change the approach instead of rerunning it. If a rerun is intended, retry the same command.
/clear starts over.1 failing retry held back.output-diet trims long output after a command has run; cmd-diet keeps the noise from being printed at all. Before a Bash or PowerShell command runs, a known noisy command gets its own quiet flags, which drop progress lines and keep errors, test failures and warnings:
| Command | Runs as | Output, measured |
|---|---|---|
git status | git status --short --branch | 415 to 58 characters |
pytest | pytest -q | 1,063 to 495 characters, failure details unchanged |
cargo build / test / check / clippy / run | cargo build -q | 197 to 0 characters on success, warnings unchanged |
npm install / ci | npm install --no-audit --no-fund | 62 to 18 characters |
curl (Bash only) | curl -sS | 1,049 to 577 characters, the progress meter removed |
mvn | mvn -B -ntp | not measured: drops download progress |
wget (Bash only) | wget -nv | not measured: one line per file |
docker pull | docker pull -q | not measured: drops layer progress |
In a live headless run (git status && python -m pytest on 41 test files, one failing), the request cost 41,535 tokens without cmd-diet and 40,571 with it, by the API's usage, and both runs named the failing test and its reason correctly. The shorter output stays in context, so every later request in the session sends less too.
&&, || or ; chain is handled on its own. A step that pipes, redirects or substitutes (| grep, > file, $(...)) is left alone, since something else reads its output; 2>&1 is fine.git status --porcelain, pytest -v, curl -fsSL, npm install --silent) is left alone, and a flag already present is not added twice.3 commands quieted.With two GitHub accounts logged in to gh, a push to a repository the other account owns fails, and Claude spends turns on gh auth status and gh auth switch. Before a Bash or PowerShell command runs, gh-account matches each git push, pull, fetch, clone, ls-remote and gh step to the repository's owner, and the owner to a logged-in account. When that account is not gh's active one, that step alone runs with its token:
GH_TOKEN="$(gh auth token --user ACCOUNT)" git push
The token itself never appears in the command or its output, and the active account is not switched. For git it also asks gh for the credential.
-R owner/repo, a gh api repos/<owner>/... path, or the folder's remotes. With no remote named, every remote must point at the same owner.gh auth status, and organizations from gh api user/orgs. What it learns is kept across sessions.gh auth and other gh commands that reach no repository, a command that already sets GH_TOKEN, a token from the environment, git over ssh, hosts other than github.com, and subshells or substitutions./gh-account shows which account each owner uses, and /gh-account forget clears it. Answers are toasts. The status line counts them: 2 commands sent as <account>.Claude's prompt cache keeps your conversation for a fixed time after each request. Reply within it and the context is read from cache; reply after it and the whole context is sent again at full price. That message pays the cache-write price (1.25 times the input price for a 5-minute cache, 2 times for a 1-hour one) on every token instead of the cache-read price (0.1 times): 12.5 to 20 times more for the same context, and nothing on screen says so.
cache-clock puts the countdown in the status line, restarted by every response from the main conversation:
cache warm · 3m left
cache cold · next message re-sends 61,204 tokens
When the cache runs out, a toast says so once (after the lifetime is known, see below). The token figure is the previous response
hooks/register.ts 223 lines1import type { Register } from 'claude-code'
2
3// A Read with no line range on a long text file is refused once, with the
4// file's exact line count, and Claude is pointed at the outline tool and a
5// ranged Read instead. Retrying the same Read goes through, so nothing is ever
6// out of reach. The outline is built here from the file on disk: no model call.
7// A plain shell `cat FILE` or `Get-Content FILE` of such a file is held the same
8// way; a ranged print (`sed -n`, `head`, `tail`) and anything else pass.
9
10const MAX_LINES = 1000
11const MAX_ENTRIES = 300
12const MAX_BYTES = 4 * 1024 * 1024
13
14// Reads Claude Code turns into something other than text lines.
15const NOT_TEXT = /\.(png|jpe?g|gif|webp|bmp|ico|pdf|ipynb)$/i
16
17const baseName = (path: string) => path.split(/[\\/]/).pop() ?? path
18const count = (n: number) => n.toLocaleString('en-US')
19
20export const lineCount = (text: string) => (text.length === 0 ? 0 : text.split('\n').length - (text.endsWith('\n') ? 1 : 0))
21
22const KEYWORD = /^(if|for|while|switch|catch|return|else|do|try|with|elif|except|match|when)\b/
23
24const DEFINITIONS: RegExp[] = [
25 // Markdown headings
26 /^#{1,6}\s+\S/,
27 // JavaScript and TypeScript declarations
28 /^\s*(export\s+)?(default\s+)?(declare\s+)?(abstract\s+)?(async\s+)?(function\*?|class|interface|type|enum|namespace)\s+[\w$]/,
29 /^(export\s+)?(const|let|var)\s+[\w$]+/,
30 // Python
31 /^\s*(async\s+)?(def|class)\s+\w/,
32 // Go
33 /^(func|type)\s+[\w(]/,
34 // Rust
35 /^\s*(pub(\([\w:]+\))?\s+)?(async\s+)?(unsafe\s+)?(fn|struct|enum|trait|impl|mod|macro_rules!)\s*[\w<]/,
36 // Java, C#, Kotlin, Swift, PHP: a modifier-led declaration
37 /^\s*((public|private|protected|internal|static|final|abstract|sealed|override|open|data|suspend)\s+)+[\w<>[\],.?\s]*[\w>]\s*[\w$]+\s*[({<]/,
38 /^\s*(class|interface|struct|enum|record|object|fun|func|protocol|extension|trait)\s+\w/,
39 // Methods in a class body: name(...) { or name(...): Type {
40 /^\s+(static\s+|async\s+|get\s+|set\s+|override\s+)*[A-Za-z_$][\w$]*\s*(<[^>]*>)?\([^)]*\)\s*(:\s*[^={;]+)?\{\s*$/,
41]
42
43export const outline = (text: string) => {
44 const lines = text.split('\n')
45 const entries: string[] = []
46 for (let i = 0; i < lines.length && entries.length < MAX_ENTRIES; i++) {
47 const line = lines[i].replace(/\r$/, '')
48 const trimmed = line.trim()
49 if (trimmed.length === 0 || KEYWORD.test(trimmed)) continue
50 if (DEFINITIONS.some(re => re.test(line))) {
51 entries.push(`${i + 1}: ${trimmed.length > 120 ? `${trimmed.slice(0, 119)}…` : trimmed}`)
52 }
53 }
54 return { entries, isCut: entries.length === MAX_ENTRIES }
55}
56
57export const describeOutline = (path: string, text: string) => {
58 const { entries, isCut } = outline(text)
59 const head = `${baseName(path)}: ${count(lineCount(text))} lines`
60 if (entries.length === 0) return `${head}; no definitions found. Read a range with offset and limit.`
61 return [head, ...entries, ...(isCut ? [`(first ${MAX_ENTRIES} definitions shown)`] : [])].join('\n')
62}
63
64export const refusal = (path: string, lines: number, tool: string, retry = 'Read') =>
65 `${baseName(path)} has ${count(lines)} lines. Call ${tool} to see its definitions with line numbers, ` +
66 `then Read only the range you need (offset, limit). Retry the same ${retry} to read it whole anyway.`
67
68// Characters a word may hold outside quotes; anything else (a pipe, redirect,
69// chain, variable, glob, escape, `~`) could make the shell do more than read.
70const BASH_PLAIN = /[\p{L}\p{N}_.\-/:+,@%=]/u
71const PWSH_PLAIN = /[\p{L}\p{N}_.\-/:\\]/u
72
73// Splits a command into words with their quotes removed; undefined when any
74// part is not plain.
75export function words(command: string, shell: string): string[] | undefined {
76 const out: string[] = []
77 const text = command.trim()
78 let cur: string | undefined
79 let quote: string | undefined
80 for (let i = 0; i < text.length; i++) {
81 const c = text[i]
82 if (quote !== undefined) {
83 // PowerShell also closes a string on a typographic quote.
84 if (shell !== 'Bash' && /[\u2018-\u201e]/.test(c)) return undefined
85 if (c === quote) {
86 // PowerShell spells a quote inside quotes by doubling it.
87 if (shell !== 'Bash' && text[i + 1] === quote) return undefined
88 quote = undefined
89 } else if (quote === '"' && /[$`]/.test(c)) return undefined
90 else if (quote === '"' && shell === 'Bash' && /[\\!]/.test(c)) return undefined
91 else cur += c
92 continue
93 }
94 if (c === "'" || c === '"') {
95 quote = c
96 cur ??= ''
97 continue
98 }
99 if (c === ' ' || c === '\t') {
100 if (cur !== undefined) out.push(cur)
101 cur = undefined
102 continue
103 }
104 if (!(shell === 'Bash' ? BASH_PLAIN : PWSH_PLAIN).test(c)) return undefined
105 cur = (cur ?? '') + c
106 }
107 if (quote !== undefined) return undefined
108 if (cur !== undefined) out.push(cur)
109 return out
110}
111
112// The file a plain `cat FILE` or `Get-Content FILE` prints whole; undefined
113// for a range (`sed -n`, `head`, `-Tail`) or anything it does not understand.
114export function wholeRead(command: string, shell: string): string | undefined {
115 const all = words(command, shell)
116 if (all === undefined || all.length < 2) return undefined
117 const [name, ...args] = all
118 if (shell === 'Bash') return name === 'cat' && args.length === 1 && !args[0].startsWith('-') ? args[0] : undefined
119
120 if (!['get-content', 'gc', 'cat', 'type'].includes(name.toLowerCase())) return undefined
121 let path: string | undefined
122 for (let i = 0; i < args.length; i++) {
123 const arg = args[i].toLowerCase()
124 if (arg === '-raw') continue
125 if ((arg === '-path' || arg === '-literalpath') && path === undefined && args[i + 1] !== undefined) {
126 path = args[++i]
127 continue
128 }
129 if (arg.startsWith('-') || path !== undefined) return undefined
130 path = args[i]
131 }
132 return path === undefined || path.startsWith('-') ? undefined : path
133}
134
135// The path a shell resolves, given its working directory; undefined when it
136// cannot be placed with certainty (Git Bash's own `/tmp`, `\x`, `D:x`).
137export function absolute(path: string, cwd: string): string | undefined {
138 const isWindows = /^[A-Za-z]:[\\/]/.test(cwd)
139 // Git Bash spells D:\x as /d/x.
140 const drive = isWindows ? path.match(/^\/([A-Za-z])(\/.*)?$/) : null
141 if (drive !== null) return `${drive[1]}:${drive[2] ?? '/'}`
142 if (/^[A-Za-z]:[\\/]/.test(path)) return isWindows ? path : undefined
143 if (path.startsWith('/')) return isWindows ? undefined : path
144 if (path.startsWith('\\') || /^[A-Za-z]:/.test(path)) return undefined
145 return `${cwd.replace(/[\\/]+$/, '')}/${path}`
146}
147
148export const register: Register = on => {
149 const refusedOnce = new Set<string>()
150 let outlineTool = 'mcp__read-cap__outline'
151 let refusals = 0
152
153 on('session.start', async ($, e, next) => {
154 const { tool } = await $.tool.register({
155 name: 'outline',
156 description:
157 "Lists a text file's definitions (functions, classes, types, headings) with line numbers, so you can Read only the lines you need. Use it before reading a long file.",
158 inputSchema: {
159 type: 'object',
160 properties: { file_path: { type: 'string', description: 'Absolute path of the file' } },
161 required: ['file_path'],
162 },
163 })
164 outlineTool = tool
165 return next(e)
166 })
167
168 on('tool.call', { tool: 'mcp__read-cap__outline' }, async ($, e) => {
169 const path = (e as { file_path?: unknown }).file_path
170 if (typeof path !== 'string') return { deny: 'outline needs file_path.' }
171 const text = await $.fs.read(path).catch((err: unknown) => err)
172 if (typeof text !== 'string') return { deny: `outline could not read ${baseName(path)}: ${String(text)}` }
173 return { result: describeOutline(path, text) }
174 })
175
176 // The line count of a long text file read whole, once per loop and file;
177 // undefined lets the read through. A Read and a shell read share the hold.
178 type Fs = { stat: () => Promise<{ kind: string; size: number }>; read: () => Promise<unknown> }
179 const longFile = async (fs: Fs, path: string, agentId: string | undefined) => {
180 if (NOT_TEXT.test(path)) return undefined
181 const stat = await fs.stat().catch(() => undefined)
182 if (!stat || stat.kind !== 'file' || stat.size > MAX_BYTES) return undefined
183
184 const key = `${agentId ?? 'main'}|${path.replace(/\\/g, '/').toLowerCase()}`
185 if (refusedOnce.delete(key)) return undefined
186
187 const text = await fs.read().catch(() => undefined)
188 const lines = typeof text === 'string' ? lineCount(text) : 0
189 if (lines <= MAX_LINES) return undefined
190
191 refusedOnce.add(key)
192 refusals += 1
193 return lines
194 }
195
196 const capped = () => `${refusals} whole-file ${refusals === 1 ? 'read' : 'reads'} capped`
197
198 on('tool.call', { tool: 'Read' }, async ($, e, next) => {
199 if (e.limit !== undefined || e.offset !== undefined || e.pages !== undefined) return next(e)
200 const fs = { stat: () => $.fs.stat(e.file_path), read: () => $.fs.read(e.file_path) }
201 const lines = await longFile(fs, e.file_path, e.agentId)
202 if (lines === undefined) return next(e)
203
204 $.ui.status(capped())
205 return { deny: refusal(e.file_path, lines, outlineTool) }
206 })
207
208 // `cat FILE` or `Get-Content FILE` of a long file; a ranged print passes.
209 on('tool.call', async ($, e, next) => {
210 if ((e.tool !== 'Bash' && e.tool !== 'PowerShell') || typeof e.command !== 'string') return next(e)
211 const typed = wholeRead(e.command, e.tool)
212 const cwd = typed === undefined ? undefined : await $.session.cwd().catch(() => undefined)
213 const path = typed === undefined || cwd === undefined ? undefined : absolute(typed, cwd)
214 if (path === undefined) return next(e)
215 const fs = { stat: () => $.fs.stat(path), read: () => $.fs.read(path) }
216 const lines = await longFile(fs, path, e.agentId)
217 if (lines === undefined) return next(e)
218
219 $.ui.status(capped())
220 return { deny: refusal(path, lines, outlineTool, 'command') }
221 })
222}
223