Skip to main content
Glama

Run a command in WSL

wsl_exec
Destructive

Run shell commands inside a configured WSL distro and return stdout, stderr and the exit code; reuse a named session to keep the working directory between calls.

Instructions

Run a shell command in the configured WSL distro (as the configured user, in a login bash) and return stdout, stderr and the exit code. Pass 'session' to reuse a session, which remembers its working directory; omit it for a one-off call. A non-zero exit code is reported as normal output, not as a tool error — read the exit code and stderr to judge the outcome. Almost everything is permitted: package installs, service restarts, sudo, interpreters. Refused outright: catastrophic operations (wiping the filesystem root, formatting a disk, powering off or shutting down the distro), and — unless the profile opens them — Windows interop executables and writes under /mnt//. stdin is closed. A job that must outlive the call needs all three descriptors detached: nohup cmd > log 2>&1 < /dev/null &

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
cwdNoAbsolute directory to run in, with no shell metacharacters. With a session, the session also moves there.
commandYesShell command, exactly as it would be typed in a terminal. Chaining with ';', '&&', '||' and pipes is allowed; each part is screened separately.
sessionNoSession id from wsl_connect. Keeps the working directory across calls.
timeoutMsNoLowers the command timeout for this call; it cannot exceed the profile's own limit. wsl.exe is killed when it elapses; the process inside the distro may survive.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.0.2

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already flag destructiveHint and openWorldHint, but the description adds far more than they convey: non-zero exit codes are normal output rather than tool errors, stdin is closed, the allow/deny policy (catastrophic ops, interop executables, /mnt writes) is spelled out, and detached jobs require all three descriptors. This is exactly the kind of context an agent needs to interpret results and avoid misuse.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the core action and return values, then layered with session semantics, error semantics, permission policy and detachment recipe. Each sentence carries non-obvious behavioral information, though the density is high enough that it reads as a reference block rather than a tight summary.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

No output schema exists, so the description carries the return-value burden and does: stdout, stderr, exit code, plus how to interpret non-zero exits. Combined with the permission boundaries and detachment guidance, an agent has everything needed to call and interpret this tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline is 3, but the description adds genuine meaning: 'session' is framed as reusable state that 'remembers its working directory' versus a one-off call, complementing the schema's pointer to wsl_connect. The timeout-interaction detail (wsl.exe killed, in-distro process may survive) is also useful even though the schema mentions it.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Run a shell command in the configured WSL distro') with precise scope: configured distro, configured user, login bash, returns stdout/stderr/exit code. This is clearly distinguishable from siblings like wsl_read_file or wsl_upload, which are narrower file operations.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly says when to pass 'session' (to reuse a working directory) versus omit it for a one-off call, and gives the exact recipe for a job that must outlive the call. It does not name sibling alternatives for related operations, but the conditional guidance on sessions and detachment is strong.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.