Docs
Guides for running bashkit.
Short, focused articles for the bashkit CLI, security model, and embedded runtimes. For the Rust API, see therustdoc.
Getting started
- Get startedChoose your target — Rust, Python, Node, browser, or Pyodide — and run a first script.
- RustEmbed the sandbox in a Rust app: install, first script, examples.
- PythonEmbed the sandbox in Python: pip install, first script, examples.
- C APIEmbed Bashkit through its versioned native ABI and opaque handles.
- Node, Bun & DenoEmbed the sandbox in server-side JavaScript: npm i, first script, examples.
- Browser (WASM)Run the sandbox in the browser or at the edge — with a live terminal to try.
- Pyodide & JupyterLiteRun the sandbox in Python-in-the-browser via the Emscripten wheel.
- CLIRun scripts with bashkit-cli: flags, exit codes, opt-in runtimes.
LLM tools
- LLM toolsExpose Bashkit as a sandboxed tool for agent frameworks.
- Script analysisInspect a script before running it to drive permission prompts and audit logs.
- Scripted tool orchestrationCompose many tools into one bash-scriptable tool the LLM calls once.
- Migrating to bashkit-scripted-toolMove ScriptedTool, ToolDef, and ToolRegistry code to the new crate.
Concepts
- Sandbox configuration & limitsResource limits, filesystem backends, identity, and the network allowlist.
- Virtual filesystemThe in-memory VFS, its layering stack, and host-mount opt-ins.
- In-process terminalDrive an interactive shell and vi on an in-memory terminal, and read the screen as text.
- SecuritySandbox boundaries, threat model, and what scripts cannot do.
Networking
Runtimes
- Python builtinEmbedded Monty Python runtime, VFS bridging, limits, and caveats.
- CPython builtinReal CPython 3.14 in a WebAssembly sandbox: full stdlib, CLI, limits.
- TypeScript builtinEmbedded ZapCode TypeScript runtime shared with bash in-memory.
- SQLite builtinEmbedded Turso SQLite runtime, backends, output modes, and limits.
- SSH supportSandboxed ssh, scp, and sftp builtins with host allowlists.
- GitSandboxed git on the virtual filesystem with a configurable identity.
Reference
- CompatibilityBash and builtin feature coverage, security exclusions, and known gaps.
- jq builtinSupported jq flags, filters, variables, exit codes, and compatibility notes.
- yq builtinjq-style YAML and JSON processing, conversion, and safe in-place updates.
- Structured datajq/yq transforms and narrower CSV, JSON, and TOML helpers.
Extending
- Custom builtinsImplement Rust commands that run inside the Bashkit shell.
- Custom builtins (JavaScript)Register JS callbacks as persistent bash builtins from Node, Deno, or Bun.
- Clap builtinsUse clap parser structs to build typed custom commands.
- HooksObserve, modify, or cancel execution, builtin, lifecycle, and HTTP events.
- Live mountsAttach, detach, and hot-swap filesystems on a running interpreter.