This project has been archived by its maintainers, and is no longer receiving any updates.
autourgos-cap-shell
Argv-only command execution for an Autourgos agent — one tool, run_command,
that never touches a shell. Implements autourgos_core.Capability, gated by autourgos-policy's
CommandPolicy and bounded by its ExecutionSandbox.
from autourgos_cap_shell import ShellCapability
shell = ShellCapability()
print(shell.run_command(["python", "--version"]))
# Python 3.12.1
# [exit code: 0]
Features
- Argv-only:
subprocess.run(argv, shell=False)— there is no shell string to inject into, ever - No raw shell-string execution path at all, matching
autourgos_policy.CommandPolicy's own documented Phase 4 expectation - cwd-jail and environment scrubbing reused, not reimplemented: calls
ExecutionSandbox.prepare_context()before every command CommandPolicystill applies: aResource(kind="command", ...)target lets the gate reject shell-operator/injection syntax embedded in any single argv element before the callable runs- Fully typed (
py.typed), zero required dependency beyondautourgos-core/autourgos-policy
Table of Contents
Install
pip install autourgos-cap-shell
Requires autourgos-core>=0.2.0 and autourgos-policy>=0.3.1.
Tool
| Tool | Risk | Resource |
|---|---|---|
run_command(argv, cwd=None) |
WRITE |
command — " ".join(argv), checked by CommandPolicy |
argv is a list of strings, executed directly. cwd, if given, is validated against the sandbox's
allowed_cwd_roots. With no cwd, commands run in the calling process's own working directory.
Usage
Direct calls
from autourgos_cap_shell import ShellCapability
shell = ShellCapability()
output = shell.run_command(["python", "-c", "print('hello')"])
print(output)
# hello
# [exit code: 0]
cwd and environment
run_command calls autourgos_policy.ExecutionSandbox.prepare_context(cwd=cwd) itself before invoking
subprocess.run — reusing the sandbox's cwd-jail check and environment allowlist rather than reimplementing
either.
from autourgos_cap_shell import ShellCapability
from autourgos_policy import ExecutionSandbox, SandboxConfig
shell = ShellCapability(
sandbox=ExecutionSandbox(SandboxConfig(allowed_cwd_roots=("C:/work",)))
)
output = shell.run_command(["dir"], cwd="C:/work")
Through a PolicyGate
from autourgos_cap_shell import ShellCapability
from autourgos_core import Action, Resource, Risk
from autourgos_policy import PolicyConfig, PolicyExecutor, PolicyGate
shell = ShellCapability()
gate = PolicyGate(PolicyConfig(profile="assisted", allowed_resource_kinds=("command",)))
executor = PolicyExecutor(gate, confirmation_callback=lambda action, decision: True)
action = Action(
tool="run_command",
arguments={"argv": ["python", "--version"]},
targets=[Resource("command", "python --version")],
risk=Risk.WRITE,
)
outcome = await executor.execute(action, shell.run_command)
assert outcome.executed
With autourgos-kernel
from autourgos_kernel import Engine, Run
from autourgos_policy import PolicyConfig, PolicyExecutor, PolicyGate
engine = Engine(llm=my_llm, capabilities=[shell])
result = await engine.run(
Run(goal="check the python version"),
policy_executor=PolicyExecutor(PolicyGate(PolicyConfig(profile="assisted"))),
)
Why Argv-Only
autourgos_policy.CommandPolicy's own docstring says it: "the Phase 4 shell capability will prefer argv
execution without a shell." A raw shell string has to be parsed correctly for cmd.exe, PowerShell, and
POSIX shells before injection syntax can be reliably rejected — that's not a problem CommandPolicy (a
conservative regex denylist, not a shell parser) tries to solve. run_command sidesteps it entirely:
subprocess.run(argv, shell=False) has no shell to inject into.
Not in this release:
- Raw shell-string execution.
- A persistent shell session (state carried between calls, e.g.
cdsticking across commands).
API Reference
ShellCapability(sandbox: ExecutionSandbox | None = None)
| Method | Returns | Description |
|---|---|---|
.tools() |
list[ToolBinding] |
The one run_command binding |
.describe(call) |
Action |
Rejects a call with no argv, an empty argv, or a non-string element |
.run_command(argv, cwd=None) |
str |
stdout, [stderr] block if any, and [exit code: N] |
License
Apache License 2.0, Copyright (c) 2026 Jitin Kumar Sengar
Metadata
Release files for autourgos-cap-shell 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| autourgos_cap_shell-0.1.1.tar.gz | 18.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| autourgos_cap_shell-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 33.1 kB
Release files / autourgos_cap_shell-0.1.1.tar.gz
| Download URL | autourgos_cap_shell-0.1.1.tar.gz |
|---|---|
| Size | 18.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
16707c65c16021dbb81642676505d533bdb870cfedb117b13d6995f45415ce91
|
|
BLAKE2b-256 checksum How to use checksums |
d853044c7f1282f7f19ff2478d0d1226572f6ef74189599ecabcbb9eef11e0d5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.11.9
|
Release files / autourgos_cap_shell-0.1.1-py3-none-any.whl
| Download URL | autourgos_cap_shell-0.1.1-py3-none-any.whl |
|---|---|
| Size | 14.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
4a7887b24ea7eac73b613c1b07c8f942d2cd9ace38d2d57b5ac795f0691c492e
|
|
BLAKE2b-256 checksum How to use checksums |
dd55160d04703025e7bf8161bb4eefb220bea94c9b73a65a631b88a0a42c2a4b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.11.9
|