Tool Specification: mshtools-shell
Overview
Bash command execution in non-persistent environment providing system-level access to Debian GNU/Linux 12 (bookworm) container. Enables file operations, package management, and binary execution.
JSON Schema
{
"type": "object",
"properties": {
"command": {
"type": "string",
"description": "Shell command to execute (single command or chained with &&, ;, ||, |)"
}
},
"required": ["command"]
}
Streaming Mechanism
- Transport: HTTP API to shell execution service
- Execution Model: Fresh shell session per invocation (non-persistent)
- State Behavior: No state preservation between calls (variables, directory changes reset)
- Output: STDOUT/STDERR combined, truncated at 10000 characters
- Timeout: Automatic timeout after reasonable duration to prevent hanging
Integration Architecture
Container Context
- Base Image: Debian GNU/Linux 12 (bookworm)
- User Context: Non-root execution with limited /proc access
- Network Namespace: Isolated (blocked external connectivity)
- PID Namespace: Isolated process tree
Execution Flow
- Command Validation: Security screening for dangerous operations
- Session Creation: Spawn fresh bash shell in container
- Execution: Run command with timeout enforcement
- Output Capture: Capture STDOUT/STDERR streams
- Session Termination: Shell process terminated after execution
- Result Return: Text output returned to model
File System Access
/ # Root filesystem (read-only system)
/app/ # Application files (read-only)
/app/.kimi/skills/ # Skill binaries and documentation
/mnt/kimi/upload/ # User uploads (read-only)
/mnt/kimi/output/ # Output directory (read-write)
/mnt/okcomputer/ # OK Computer workspace (read-write)
/tmp/ # Temporary files (volatile)
Available Binaries
- System: ls, find, grep, cat, mkdir, rm, cp, mv, ps, top, df, free
- Package Management: apt, pip, npm (where available)
- Network: curl, wget (blocked at network layer)
- Text Processing: awk, sed, sort, uniq, wc, jq
- Archive: tar, zip, unzip
- Custom: KimiXlsx (77MB), tectonic (57MB), .NET validators
Security Model
Capabilities Dropped
- ptrace (no process debugging)
- mount (no filesystem mounting)
- Raw socket access restricted
Restricted Paths
/root (no access)
/home/* (no access)
/var/log (no access)
/proc (limited view)
Execution Constraints
- Non-interactive: No TTY, no stdin interaction
- No Background Jobs: Commands must complete synchronously
- Resource Limits: CPU/memory quotas enforced via cgroups
Usage Patterns
File Operations
ls -la /mnt/kimi/upload/
cp file.txt /mnt/kimi/output/
rm -rf /tmp/temp_dir/
Command Chaining
cd /path && ls -la # AND - fail fast
command1 ; command2 # Sequential regardless
command1 || command2 # Conditional (if first fails)
command1 | command2 # Pipe output
Path Handling
- Always quote paths with spaces:
"/path with spaces/"
- Prefer absolute paths:
/mnt/kimi/output/file.txt
- Working directory: Unpredictable, use cd at start of chain
Limitations
- Network Blocked: External curl/wget fail at container level
- No State: Variables don't persist:
export VAR=value lost next call
- No Daemons: Cannot start background services
- Read-Only System: Cannot modify /app/, /bin/, /etc/ (except /tmp, /mnt/kimi/output)
1---2name: tool-specification-mshtools-shell3description: Bash command execution in non-persistent environment providing system-level access to Debian GNU/Linux 12 (bookworm) container. Enables file operations, package management, and binary execution.4---5# Tool Specification: mshtools-shell67## Overview8Bash command execution in non-persistent environment providing system-level access to Debian GNU/Linux 12 (bookworm) container. Enables file operations, package management, and binary execution.910## JSON Schema11```json12{13 "type": "object",14 "properties": {15 "command": {16 "type": "string",17 "description": "Shell command to execute (single command or chained with &&, ;, ||, |)"18 }19 },20 "required": ["command"]21}22```2324## Streaming Mechanism25- **Transport**: HTTP API to shell execution service26- **Execution Model**: Fresh shell session per invocation (non-persistent)27- **State Behavior**: No state preservation between calls (variables, directory changes reset)28- **Output**: STDOUT/STDERR combined, truncated at 10000 characters29- **Timeout**: Automatic timeout after reasonable duration to prevent hanging3031## Integration Architecture3233### Container Context34- **Base Image**: Debian GNU/Linux 12 (bookworm)35- **User Context**: Non-root execution with limited /proc access36- **Network Namespace**: Isolated (blocked external connectivity)37- **PID Namespace**: Isolated process tree3839### Execution Flow401. **Command Validation**: Security screening for dangerous operations412. **Session Creation**: Spawn fresh bash shell in container423. **Execution**: Run command with timeout enforcement434. **Output Capture**: Capture STDOUT/STDERR streams445. **Session Termination**: Shell process terminated after execution456. **Result Return**: Text output returned to model4647### File System Access48```49/ # Root filesystem (read-only system)50/app/ # Application files (read-only)51/app/.kimi/skills/ # Skill binaries and documentation52/mnt/kimi/upload/ # User uploads (read-only)53/mnt/kimi/output/ # Output directory (read-write)54/mnt/okcomputer/ # OK Computer workspace (read-write)55/tmp/ # Temporary files (volatile)56```5758### Available Binaries59- **System**: ls, find, grep, cat, mkdir, rm, cp, mv, ps, top, df, free60- **Package Management**: apt, pip, npm (where available)61- **Network**: curl, wget (blocked at network layer)62- **Text Processing**: awk, sed, sort, uniq, wc, jq63- **Archive**: tar, zip, unzip64- **Custom**: KimiXlsx (77MB), tectonic (57MB), .NET validators6566## Security Model6768### Capabilities Dropped69- ptrace (no process debugging)70- mount (no filesystem mounting)71- Raw socket access restricted7273### Restricted Paths74- `/root` (no access)75- `/home/*` (no access)76- `/var/log` (no access)77- `/proc` (limited view)7879### Execution Constraints80- **Non-interactive**: No TTY, no stdin interaction81- **No Background Jobs**: Commands must complete synchronously82- **Resource Limits**: CPU/memory quotas enforced via cgroups8384## Usage Patterns8586### File Operations87```bash88ls -la /mnt/kimi/upload/89cp file.txt /mnt/kimi/output/90rm -rf /tmp/temp_dir/91```9293### Command Chaining94```bash95cd /path && ls -la # AND - fail fast96command1 ; command2 # Sequential regardless97command1 || command2 # Conditional (if first fails)98command1 | command2 # Pipe output99```100101### Path Handling102- **Always quote paths with spaces**: `"/path with spaces/"`103- **Prefer absolute paths**: `/mnt/kimi/output/file.txt`104- **Working directory**: Unpredictable, use cd at start of chain105106## Limitations107- **Network Blocked**: External curl/wget fail at container level108- **No State**: Variables don't persist: `export VAR=value` lost next call109- **No Daemons**: Cannot start background services110- **Read-Only System**: Cannot modify /app/, /bin/, /etc/ (except /tmp, /mnt/kimi/output)