Skip to main content
Archived

This project has been archived by its maintainers, and is no longer receiving any updates.

autourgos-cap-shell

Framework: Autourgos Python License: Apache 2.0 Author Contributor Contributor

Argv-only command execution for an Autourgos agent — one tool, run_command, that never touches a shell. Implements autourgos_core.Capability, gated by autourgos-policy's CommandPolicy and bounded by its ExecutionSandbox.

from autourgos_cap_shell import ShellCapability

shell = ShellCapability()
print(shell.run_command(["python", "--version"]))
# Python 3.12.1
# [exit code: 0]

Features

  • Argv-only: subprocess.run(argv, shell=False) — there is no shell string to inject into, ever
  • No raw shell-string execution path at all, matching autourgos_policy.CommandPolicy's own documented Phase 4 expectation
  • cwd-jail and environment scrubbing reused, not reimplemented: calls ExecutionSandbox.prepare_context() before every command
  • CommandPolicy still applies: a Resource(kind="command", ...) target lets the gate reject shell-operator/injection syntax embedded in any single argv element before the callable runs
  • Fully typed (py.typed), zero required dependency beyond autourgos-core/autourgos-policy

Table of Contents


Install

pip install autourgos-cap-shell

Requires autourgos-core>=0.2.0 and autourgos-policy>=0.3.1.


Tool

Tool Risk Resource
run_command(argv, cwd=None) WRITE command — " ".join(argv), checked by CommandPolicy

argv is a list of strings, executed directly. cwd, if given, is validated against the sandbox's allowed_cwd_roots. With no cwd, commands run in the calling process's own working directory.


Usage

Direct calls

from autourgos_cap_shell import ShellCapability

shell = ShellCapability()
output = shell.run_command(["python", "-c", "print('hello')"])
print(output)
# hello
# [exit code: 0]

cwd and environment

run_command calls autourgos_policy.ExecutionSandbox.prepare_context(cwd=cwd) itself before invoking subprocess.run — reusing the sandbox's cwd-jail check and environment allowlist rather than reimplementing either.

from autourgos_cap_shell import ShellCapability
from autourgos_policy import ExecutionSandbox, SandboxConfig

shell = ShellCapability(
    sandbox=ExecutionSandbox(SandboxConfig(allowed_cwd_roots=("C:/work",)))
)
output = shell.run_command(["dir"], cwd="C:/work")

Through a PolicyGate

from autourgos_cap_shell import ShellCapability
from autourgos_core import Action, Resource, Risk
from autourgos_policy import PolicyConfig, PolicyExecutor, PolicyGate

shell = ShellCapability()
gate = PolicyGate(PolicyConfig(profile="assisted", allowed_resource_kinds=("command",)))
executor = PolicyExecutor(gate, confirmation_callback=lambda action, decision: True)

action = Action(
    tool="run_command",
    arguments={"argv": ["python", "--version"]},
    targets=[Resource("command", "python --version")],
    risk=Risk.WRITE,
)
outcome = await executor.execute(action, shell.run_command)
assert outcome.executed

With autourgos-kernel

from autourgos_kernel import Engine, Run
from autourgos_policy import PolicyConfig, PolicyExecutor, PolicyGate

engine = Engine(llm=my_llm, capabilities=[shell])
result = await engine.run(
    Run(goal="check the python version"),
    policy_executor=PolicyExecutor(PolicyGate(PolicyConfig(profile="assisted"))),
)

Why Argv-Only

autourgos_policy.CommandPolicy's own docstring says it: "the Phase 4 shell capability will prefer argv execution without a shell." A raw shell string has to be parsed correctly for cmd.exe, PowerShell, and POSIX shells before injection syntax can be reliably rejected — that's not a problem CommandPolicy (a conservative regex denylist, not a shell parser) tries to solve. run_command sidesteps it entirely: subprocess.run(argv, shell=False) has no shell to inject into.

Not in this release:

  • Raw shell-string execution.
  • A persistent shell session (state carried between calls, e.g. cd sticking across commands).

API Reference

ShellCapability(sandbox: ExecutionSandbox | None = None)

Method Returns Description
.tools() list[ToolBinding] The one run_command binding
.describe(call) Action Rejects a call with no argv, an empty argv, or a non-string element
.run_command(argv, cwd=None) str stdout, [stderr] block if any, and [exit code: N]

License

Apache License 2.0, Copyright (c) 2026 Jitin Kumar Sengar

Metadata

Release files for autourgos-cap-shell 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for autourgos-cap-shell 0.1.1
File Size Uploaded
autourgos_cap_shell-0.1.1.tar.gz 18.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for autourgos-cap-shell 0.1.1
File Interpreter ABI Platform
autourgos_cap_shell-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 33.1 kB

Release files / autourgos_cap_shell-0.1.1.tar.gz

Download URL autourgos_cap_shell-0.1.1.tar.gz
Size 18.7 kB
Tags Source
SHA-256 checksum
How to use checksums
16707c65c16021dbb81642676505d533bdb870cfedb117b13d6995f45415ce91
BLAKE2b-256 checksum
How to use checksums
d853044c7f1282f7f19ff2478d0d1226572f6ef74189599ecabcbb9eef11e0d5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.9

Release files / autourgos_cap_shell-0.1.1-py3-none-any.whl

Download URL autourgos_cap_shell-0.1.1-py3-none-any.whl
Size 14.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
4a7887b24ea7eac73b613c1b07c8f942d2cd9ace38d2d57b5ac795f0691c492e
BLAKE2b-256 checksum
How to use checksums
dd55160d04703025e7bf8161bb4eefb220bea94c9b73a65a631b88a0a42c2a4b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.9

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page