Skip to content
v1.0.0

Execute, observe, and cancel trusted non-interactive /bin/bash processes on Linux and macOS with per-action approval in Ask/Full.

What this package declares

The file a client reads when it loads this plugin, exactly as this revision carries it.

plugin.json
{
  "$schema": "https://agent-plugins.org/schemas/1.0.0/plugin.schema.json",
  "name": "exec",
  "version": "1.0.0",
  "description": "Execute, observe, and cancel trusted non-interactive /bin/bash processes on Linux and macOS with per-action approval in Ask/Full.",
  "extensions": {
    "ai.abot.runtime": {
      "version": 1,
      "entrypoint": "./src/index.cjs",
      "catalogGroups": ["exec"],
      "settings": {
        "defaults": {
          "timeoutMs": 600000,
          "yieldAfterMs": 15000,
          "idleTimeoutMs": 120000,
          "outputRetentionMs": 604800000
        }
      },
      "capabilities": {
        "exec": {
          "catalogGroups": ["read", "write", "exec"],
          "description": "Execute one trusted non-interactive /bin/bash command on Linux or macOS. Use an explicit existing directory: `.` and relative paths start at the agent-work root, `workspace/...` selects the workspace, and absolute host paths are accepted. Commands run with the runtime OS user permissions without parsing their contents for path or sensitivity restrictions. Ask/Full require approval of the exact action; FULL+ executes without that prompt. A command still running after the foreground window yields a process ID and cursor that exec_wait can resume without restarting it.",
          "routingCapability": "filesystem_inspection",
          "developmentRoles": ["inspect", "establish", "mutate", "verify", "auxiliary"],
          "eventPresentation": {
            "metadata": {
              "command": {
                "param": "command",
                "kind": "string",
                "maxLength": 8192,
                "preserveWhitespace": true
              },
              "cwd": {
                "param": "cwd",
                "kind": "string",
                "maxLength": 4096,
                "preserveWhitespace": true
              }
            }
          },
          "skills": ["exec_skill"],
          "operations": {
            "execute_command": {
              "summary": "Execute one trusted non-interactive /bin/bash command in an explicit existing directory. This sensitive operation requires exact-action approval in Ask/Full and runs automatically in FULL+. The OS user permissions still apply; the selected folder is not a sandbox.",
              "outputChannels": {"text": "metadata", "data": "metadata"},
              "input": {
                "type": "object",
                "additionalProperties": false,
                "properties": {
                  "command": {
                    "type": "string",
                    "minLength": 1,
                    "maxLength": 8192
                  },
                  "cwd": { "type": "string", "minLength": 1, "maxLength": 4096 }
                },
                "required": ["command", "cwd"]
              },
              "effect": "mixed",
              "approval": "always"
            }
          }
        },
        "exec_wait": {
          "catalogGroups": ["read", "exec"],
          "description": "Continue observing the exact running shell process returned by exec. Use only the process ID and next cursor from the latest exec or exec_wait result. This does not start the command again.",
          "routingCapability": "filesystem_inspection",
          "developmentRoles": ["inspect", "verify", "auxiliary"],
          "eventPresentation": {
            "metadata": {
              "processId": { "param": "process_id", "kind": "string" },
              "cursor": { "param": "cursor", "kind": "number" }
            }
          },
          "skills": ["exec_process_skill"],
          "operations": {
            "wait_for_process": {
              "summary": "Wait for the next bounded observation from one running exec process without restarting it.",
              "outputChannels": {"text": "metadata", "data": "metadata"},
              "input": {
                "type": "object",
                "additionalProperties": false,
                "properties": {
                  "process_id": {
                    "type": "string",
                    "minLength": 1,
                    "maxLength": 128
                  },
                  "cursor": {
                    "type": "integer",
                    "minimum": 1,
                    "maximum": 1000000
                  }
                },
                "required": ["process_id", "cursor"]
              },
              "effect": "read_only",
              "approval": "always"
            }
          }
        },
        "exec_cancel": {
          "catalogGroups": ["write", "exec"],
          "description": "Cancel one running shell process previously returned by exec. Use only when the current task no longer needs that process or the user asks to stop it.",
          "routingCapability": "filesystem_inspection",
          "developmentRoles": ["auxiliary"],
          "eventPresentation": {
            "metadata": {
              "processId": { "param": "process_id", "kind": "string" }
            }
          },
          "skills": ["exec_process_skill"],
          "operations": {
            "cancel_process": {
              "summary": "Stop one active exec process and report its final state.",
              "outputChannels": {"text": "metadata", "data": "metadata"},
              "input": {
                "type": "object",
                "additionalProperties": false,
                "properties": {
                  "process_id": {
                    "type": "string",
                    "minLength": 1,
                    "maxLength": 128
                  }
                },
                "required": ["process_id"]
              },
              "effect": "mixed",
              "approval": "always"
            }
          }
        }
      }
    }
  }
}

Client extensions

Data this package carries for particular clients. The directory lists the clients named and never reads what is addressed to them.

  • ai.abot.runtime