Built-ins

Shell Built-In

Built-in Shell tools, persistent Workspace Sandbox, and host approval

Shell Built-In

Shell is a built-in Workspace capability from @downcity/city, not a Plugin. Shell owns its SandboxProvider, the persistent Sandbox created for its Workspace, and all Shell Sessions created inside it. City does not know which execution backend the Workspace uses.

import { Agent } from "@downcity/agent";
import { City, Shell, Workspace } from "@downcity/city";
import { MicrosandboxProvider } from "@downcity/sandbox-microsandbox";

const workspace = new Workspace({
  id: "project",
  path: "/path/to/project",
  shell: new Shell({
    sandbox_provider: new MicrosandboxProvider(),
  }),
});
const city = new City({
  workspaces: [workspace],
});
const agent = new Agent({ id: "repo-helper" });
city.agents.add(agent);

The model receives shell_exec and shell_session. Both default to target: "sandbox", where the project is mounted at /workspace. Use target: "host" with a clear reason only when full host access is required; the request must pass approval.

The same Workspace shares Sandbox HOME and installed tools across Chat Sessions. Different Workspaces have separate writable environments. A shell_id identifies a Shell Session and is never interchangeable with a Chat session_id.

Closing City or Workspace stops compute without deleting the persistent Sandbox filesystem. There are no host path allowlists or intermediate execution modes.

See Shell and Sandbox for lifecycle, environment, and approval details.

Table of Contents