Skip to content
Research
Agent

TOOL_OUTPUT_PERSISTENCE

`_externalize` creates a unique sibling `.tool-output-*.tmp` with exclusive creation (`open(..., "x")`). Its mode is `0o666 & ~umask`, preserving ordinary file-creation permissions without reading or changing the process-wide umask. This matters when a mounted sandbox reads the

GuideBOOST
From plugin
deer-flow
83k2 skills2 agents
Install
$ npx -y skills add bytedance/deer-flow --agent claude-code

How it fires

How this agent gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.

Context preview

The summary Claude sees to decide when to auto-load this agent.

`_externalize` creates a unique sibling `.tool-output-*.tmp` with exclusive creation (`open(..., "x")`). Its mode is `0o666 & ~umask`, preserving ordinary file-creation permissions without reading or changing the process-wide umask. This matters when a mounted sandbox reads the

Agent definition

TOOL_OUTPUT_PERSISTENCE.md

Host tool-output publication

`_externalize` creates a unique sibling `.tool-output-*.tmp` with exclusive creation (`open(..., "x")`). Its mode is `0o666 & ~umask`, preserving ordinary file-creation permissions without reading or changing the process-wide umask. This matters when a mounted sandbox reads the output under a different UID. Restrictive operator umasks remain restrictive.

The writer closes its file before atomically replacing the deterministic final path. The last successful publisher wins. Ownership starts only after exclusive creation succeeds: a collision or creation failure must not remove another writer's pending file. An observed `OSError` cleans only this invocation's temp and leaves previously published content intact.

When blob storage is enabled, blob publication follows host publication. If the blob write fails, that message uses the safety-limited inline fallback and does not advertise the host path. It also must not unlink the deterministic final path: a concurrent publisher may already have replaced it and durably checkpointed that content. Remove published files only as part of inactive thread-data maintenance.

Unclean shutdown

SIGKILL, OOM termination, and host failure bypass exception cleanup and can leave unique temporary files. There is no automatic stale-temp sweeper. These internal files are excluded from workspace-change and delivery scans; `keep_recent_writes` elides model-visible messages and does not prune files.

Remove `.tool-output-*.tmp` leftovers during thread-data maintenance only when all Gateway processes writing the shared storage are stopped, or when deleting the corresponding inactive thread's data. Age alone cannot prove a writer is dead, especially across workers or shared mounts, so publication must not delete other writers' files based on a TTL.

Read more
Ships withdeer-flow

On February 28th, 2026, DeerFlow claimed the 🏆 #1 spot on GitHub Trending following the launch of version 2. Thanks a million to our incredible community — you made this happen!

Get the whole plugin

Other agents on deer-flow.