docker/exec
Run one command in a running container and return stdout, stderr, and exit code. Ideal for one-off tasks; no TTY or stdin.
Instructions
Runs ONE command inside a running container and returns its stdout, stderr and exit code: no TTY, no stdin, no follow. The highest-risk docker tool: arbitrary code, as the image's user (often root) unless user is set, with its own containers: grant list. Always runs as root at the Docker socket: no privileged argument, refused unless the grant has allowed: true. command is an argv array, not a shell line: ["sh", "-c", "ls /app"] for a shell. A non-zero exit code is not a tool error; read exit_code. timeout (seconds, default 30, capped at 300) is bounded by the worker limit, which is 30 s unless the operator sets timeout_seconds for docker/exec in daemon.yaml: then the answer is timed out after N seconds and the command keeps running in the container. Output is capped at 1 MiB. Text shows Exit code: N and the output; output_format: json returns container, id, command, exit_code, running, stdout, stderr. To read logs use docker/logs, to manage the container docker/manage.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| user | No | Run as this user inside the container (name or uid[:gid]); default is the image's user | |
| command | Yes | argv array, e.g. ["sh", "-c", "ls /app"] | |
| timeout | No | Seconds to wait (default 30, values above 300 are capped at 300); the worker limit (30 s unless raised in daemon.yaml) ends the call first | |
| container | Yes | Container name, full ID or ID prefix | |
| working_dir | No | Working directory inside the container | |
| output_format | No | json returns container, id, command, exit_code, running, stdout, stderr; default is text |