Skip to main content
Glama

shell_session_send

Send commands to a persistent shell session; secrets are redacted, dangerous commands blocked, merged output and exit code returned.

Instructions

Send a command to a persistent session. Output (merged stdout/stderr) is redacted before returning. Dangerous commands are blocked per security.dangerousCommands. Returns {output, exitCode}.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
commandYes
sessionIdYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.1

TDQS

A3.8/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations the description carries the full burden, and it does valuable work: it discloses that stdout/stderr are merged and redacted before return, that dangerous commands are blocked per security.dangerousCommands, and that the result shape is {output, exitCode}. It omits session lifecycle/timeout behavior and permission requirements, but the security-relevant traits are unusually well surfaced.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three compact sentences, front-loaded with the action and followed by security behavior and return shape. Every sentence carries information; nothing is filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description correctly summarizes the return value, and it covers the key behavioral caveats (redaction, blocking). The remaining gap is the relationship to sibling session tools (open/close/revoke) and what happens if the session is stale.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 0% with two required parameters, yet the description adds little: 'persistent session' loosely hints that sessionId identifies an existing session, and 'command' is self-evident from context. It provides no detail on command format, shell semantics, or how sessionId is obtained.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Send a command to a persistent session'), which clearly implies it operates on an already-open session rather than a one-shot exec. It stops short of naming the sibling it differs from (e.g. shell_exec or shell_session_open), so an agent must infer the distinction.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Usage is only implied: the required sessionId and the phrase 'persistent session' suggest a session must already exist, but the description never states the shell_session_open prerequisite or contrasts with shell_exec for stateless execution. No explicit when/when-not guidance is given.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.