Shell
Execute shell commands from your agent. Supports timeouts, output truncation, and an optional command allowlist for safety.Quick Start
Config
string
Shell to use (default: platform default, e.g.
/bin/sh).number
default:"30000"
Command timeout in milliseconds.
number
default:"10000"
Max output characters to return. Long output is truncated from the start.
string
Working directory for commands.
string[]
Allowlist of command prefixes. If set, only commands starting with one of these are permitted.
Tools
Security
The Shell toolkit includes built-in protections against command injection:- Metacharacter rejection: Commands containing shell metacharacters (
;,|,&,`,$,(,),{,},\,<,>, newlines) are automatically rejected before execution — even if they pass the allowlist check. - Allowlist enforcement: When
allowedCommandsis set, only commands starting with an allowed prefix are permitted.