Plugin

Shell

How Workspace Shell executes sandbox and host commands

Shell

Shell is a Workspace capability, not a Plugin. It owns its Sandbox Provider, the isolated Workspace Sandbox, and reusable Shell Sessions.

What it does

  • Executes commands in the Workspace Sandbox by default
  • Keeps installed tools and HOME state across Chat Sessions
  • Captures stdout, stderr, and exit codes
  • Supports timeouts and cancellation

Safety

Shell has only two targets: sandbox and host. Sandbox execution is the default and cannot see arbitrary host paths. Host execution requires an explicit reason and host approval; Sandbox failures never fall back to the host.

Use cases

  • Running build scripts
  • File system operations
  • Querying system state
  • Executing project-specific tools

Continue with: