Skip to main content
BashToolset is unreleased and is not included in PyPI 1.1.13. Use the verified source revision below to try it. Agent examples require model configuration; direct file reads do not need model credentials.

Overview

BashToolset is a read-only filesystem toolset providing ten familiar shell commands for reading, without starting a shell process or accepting command-line options. All tools are implemented using the Python standard library and safely read files and directories within the configured permission scope. Import path: from veadk.tools.builtin_tools.bash_toolset import BashToolset
BashToolset requires Linux or macOS. All tools are read-only — no writes, deletions, or command execution.

When to use

Use BashToolset when the agent needs to read files in the working directory, browse directory structures, search file contents, or compare file differences. Unlike the code sandbox, BashToolset executes within the local process without depending on a remote sandbox, making it suitable for scenarios that require fast, safe access to local files.
BashToolset provides application-level access control, not an OS-level sandbox. The host must control directory renames, hard links, and mounts inside the allowed roots to prevent permission bypass. Timeouts cancel the caller and cooperatively stop the read worker, but a blocked filesystem call cannot be forcibly interrupted by a Python thread.

Usage example

bash_toolset_agent.py

Parameters

Constructor parameters

Default exclusions are: .env, .env.*, .ssh, .aws, *.pem, *.key. Pass an empty list [] to explicitly clear all exclusions, making every file within the permission scope readable.
Permission checks apply to both the requested path and its resolved symlink target. Recursive operations skip symlinks, excluded entries, and special files (such as named pipes).

Return format

All tools return a dictionary with the following fields:

Tool reference

cat

Read the contents of a text file at the given path.

pwd

Returns the working directory of the toolset. Takes no parameters.

ls

List children of a directory without following symlinks.

find

Recursively find files or directories by filename glob without following symlinks.

grep

Search file contents for literal text and return matching lines with path and line number. Does not support regular expressions. Read the first lines of a text file.

tail

Read the last lines of a text file.

wc

Count newline characters, whitespace-separated words, and bytes in a file. Returns a JSON result.

stat

Return file or directory type, size, permissions, and modification time as a JSON result.

diff

Compare two text files using unified diff format. Each file is limited to 2000 lines.

Configuring multiple allowed directories

BashToolset supports multiple allowed root directories, enabling the agent to read files across directories:
bash_toolset_multi_root.py

Security notes

  • Permissions on BashToolset are fixed at creation time. Modifying the lists passed to the constructor after creation does not affect the toolset.
  • Application-level access control does not replace an OS-level sandbox. The host must control directory renames, hard links, and mounts inside the allowed roots.
  • Timeouts cancel the caller and cooperatively stop the read worker; a blocked filesystem call cannot be forcibly interrupted by a Python thread.

Local verification without a model

This example creates a text file in a temporary directory, reads and prints hello, then removes the temporary directory. The application prepares the file; the reading tool does not modify it.
Relative paths always resolve against working_directory, including with multiple allowed roots. Use an absolute path for another allowed directory. Custom exclude_patterns replace the defaults rather than merging with them. When error is present, nonempty output may be only a partial result.
Last modified on September 19, 2026