Skip to main content
Glama
zademy
by zademy

Run code in a sandbox (executes the supplied code)

ctx_execute
Destructive

Run code in a sandbox to compute answers from large data, printing only results to keep raw bytes out of context.

Instructions

Run code in a sandboxed subprocess. Languages: javascript, shell, typescript, python, perl.

Think-in-Code — the core philosophy: the bytes your code processes never enter your conversation memory; only what you console.log() does. Reading a 700 KB log directly means 700 KB of your remaining reasoning capacity gets spent on raw bytes. Running code over that same log in this sandbox and printing a 3 KB summary leaves you with 697 KB of capacity for the actual work.

Concrete shape — analyze 47 source files without reading any of them: ctx_execute(language: "javascript", code: const fs = require('fs'); const files = fs.readdirSync('src').filter(f => f.endsWith('.ts')); files.forEach(f => { const lines = fs.readFileSync('src/'+f,'utf8').split('\\n').length; console.log(f + ': ' + lines + ' lines'); }); ) // 47 files analyzed, 15,314 LoC summarized — output ~3.6 KB instead of 47 Read() calls = ~700 KB.

WHEN:

  • You intend to derive an answer FROM data (filter, count, aggregate, parse, compare, transform) — do the derivation in code and print only the answer

  • Output shape or size cannot be predicted before execution (recursive finds, repo-wide greps, list endpoints, query results, log scans)

  • You would otherwise read raw output and then mentally compute — that compute belongs here, in code, where its inputs stay out of your conversation

  • You need to keep a long-running process alive (dev server, watcher, daemon) — pass background: true to detach on timeout instead of killing the process

  • The output may legitimately be large but you only want recall-by-topic later — pass an intent string; outputs over ~5KB are auto-indexed into the knowledge base and only the section titles + previews come back, retrievable via ctx_search

WHEN NOT:

  • Single observational command whose entire short output you intend to consume verbatim (whoami, pwd, git status on a clean tree) — Bash is simpler

  • File mutations (Edit/Write) or navigation (cd/ls) — Bash is the right surface

  • You already know the output is one short fixed line and you want to read it as-is

RETURNS: Only what your code prints. Wrap risky calls in try/catch — uncaught errors go to stderr and may leak more than intended. When intent is set and output exceeds the auto-index threshold, the response carries searchable section titles + previews instead of the raw stdout; use ctx_search(queries: [...]) to drill into specific sections.

EXAMPLE: ctx_execute(language: "javascript", code: "const out = require('child_process').execSync('npm test', {encoding:'utf8', stdio:['ignore','pipe','pipe']}); console.log(out.split('\n').filter(l => /(FAIL|✗|×|Error:|Tests +.*(failed|passed))/i.test(l)).slice(0, 60).join('\n'))") EXAMPLE: ctx_execute(language: "javascript", code: "const out = require('child_process').execSync('gh issue list --json number,title --limit 100', {encoding:'utf8'}); const hooks = JSON.parse(out).filter(i => /hook|routing/i.test(i.title)); console.log(${hooks.length} hook-related issues)")

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
cwdNoOptional working directory for shell commands. Non-shell languages still execute from their sandbox temp directory.
codeYesSource code to execute. Use console.log (JS/TS), print (Python/Ruby/Perl/R), echo (Shell), echo (PHP), fmt.Println (Go), IO.puts (Elixir), or Console.WriteLine (C#) to output a summary to context.
intentNoWhat you're looking for in the output. When provided and output is large (>5KB), indexes output into knowledge base and returns section titles + previews — not full content. Use ctx_search(queries: [...]) to retrieve specific sections. Example: 'failing tests', 'HTTP 500 errors'. TIP: Use specific technical terms, not just concepts. Check 'Searchable terms' in the response for available vocabulary.
languageYesRuntime language
timeoutMsNoMax execution time in MILLISECONDS — timeoutMs: 120000 is two minutes, timeoutMs: 120 is 0.12 seconds. When omitted, the host's own RPC timeout governs where it has one; on hosts that do not bound a call (Pi, Antigravity CLI) a generous server-side default applies instead. Pass an explicit value for long-running builds (Gradle/Maven/SBT), or background: true to detach.
backgroundNoKeep process running after timeout (for servers/daemons). Returns partial output without killing the process. IMPORTANT: Do NOT add setTimeout/self-close timers in background scripts — the process must stay alive until the timeout detaches it. For server+fetch patterns, prefer putting both server and fetch in ONE ctx_execute call instead of using background.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv2.0.0

TDQS

A4.4/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With annotations already declaring destructive/openWorld, the description still adds real behavioral context: the stdout-only memory model, the stderr leak risk of uncaught errors, timeout semantics, background detach behavior, and the >5KB auto-indexing path. Annotations are not contradicted — destructiveHint:true is consistent with arbitrary code execution.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Well front-loaded and organized with WHEN / WHEN NOT / RETURNS headers, but overladen with a multi-paragraph "Think-in-Code" philosophy essay and two long inline code examples that repeat guidance already given in prose. The same routing decisions could be conveyed in roughly half the space.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a code-execution tool with no output schema, the description covers everything an agent needs: what runs, how output reaches context, error behavior, background/timeout handling, and the intent-based retrieval path. Nothing essential is left to inference.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the baseline is 3; the description earns above that by adding semantics the schema does not — that `background: true` detaches rather than kills, that `intent` routes large output into ctx_search retrieval, and that `timeoutMs` matters for long builds.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

Opens with a specific verb+resource ("Run code in a sandboxed subprocess") and enumerates the supported languages, so the core purpose is unambiguous. It does not, however, differentiate itself from the closely related sibling tools ctx_execute_file and ctx_batch_execute, which is the main clarity gap for an agent choosing among execution surfaces.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Contains explicit WHEN and WHEN NOT sections with concrete conditions, and names a competing alternative (Bash) with the trigger that selects it (single short observational command, file mutation, navigation). This is about as explicit a routing guide as a tool description can carry.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.