Shell Exec

Run a sandboxed shell command with timeout and allowlist

KeyArgo Updated 118 repo stars

File contents

Shell Exec

Run a sandboxed shell command with timeout and allowlist

Authority band

This tool runs under L2 authority in the Custodian kernel. Autonomous up to the per-action and session caps; escalates above threshold.

Inputs

Parameter Type Required Description
(see execute.py for full schema)

Configuration

No additional configuration required — uses credentials already wired to Custodian.

Usage

custodian tools run shell-exec --param value

Custodian governance

Every call to this tool passes through the Custodian kernel authority check before executing. The kernel verifies the current authority band, checks spending caps where applicable, logs the action to the OCSF audit trail, and escalates to a human operator if the action exceeds the declared band.

Adding this tool to any Hermes agent session requires no code changes — declare custodian-band: L2 in the SKILL.md frontmatter and the kernel wraps it automatically.

KeyArgo/custodian-kernel/tree/main/custodian/bundled_skills/files/shell-exec commit 30a8fea237

Frequently asked questions

npx skillmds@latest add keyargo/shell-exec