sh
sh- Group
- Shell
- Turned on by
- Its own switch on the Tools page of Conversation settings.
- Approval
- Reviewed: writes and open-ended actions ask for approval unless the security level or an earlier “Always allow” covers them.
- Profile key
tool.sh.description
Runs a command line in sh in the conversation's workspace and returns its output.
It runs as plain sh -c, which reads no startup files, so commands get none of the aliases or functions from your shell setup.
When it asks you
Always allow is never offered. The card shows the full command, marked [Background] for a background run. A recursive delete of the filesystem root, your home folder, a system folder such as /etc, or a path built from a variable or command substitution asks at every level, Full access included.
Good to know
- A command still running at its timeout moves to the background and keeps running, whether the main agent, a subagent or a workflow step ran it, even with 8 background tasks already running. A subagent's or workflow step's background commands report to it, and any still running when it gives its final reply are stopped. Background commands end when Mework quits or crashes.
- Each workspace, on any machine, remembers the directory its last successful command ended in, and the next command in that workspace starts there. A command that ends outside the workspace sends the next one back to the workspace root, and its result says so. Background commands start in the remembered directory but never change it.
Parameters
| Parameter | Type | Details |
|---|---|---|
command requiredCommand | string | The POSIX sh command line. |
descriptionDescription | string | One short sentence, in active voice, saying what this command does. Name the action itself; do not hedge with words such as "complex" or "risky". For ordinary commands (git, npm, everyday CLI tools) keep it to five to ten words: - ls → "List files in current directory" - git status → "Show working tree status" - npm install → "Install project dependencies" For commands that are hard to read at a glance (pipelines, unusual flags, find/xargs) add just enough context to make the effect clear: - find . -name "*.tmp" -exec rm {} ; → "Delete every .tmp file under the current directory" - git reset --hard origin/main → "Discard local changes and match remote main" - curl -s url | jq '.data[]' → "Fetch JSON from a URL and print its data entries" |
run_in_backgroundRun in background | boolean | Run the command as a background task instead of blocking this call. The receipt carries its shell:<id> address. |
timeoutTimeout (ms) | number | Optional timeout in milliseconds (default 120000, max 600000). On expiry the command is moved to the background rather than stopped, and the receipt carries its shell:<id> address. |