$npx skillfedfor your agent

bashkit

A sandboxed bash interpreter for AI agents

With conditionsPyPI SecurityReleased Aug 2026272.1K downloads / moMITPlatform wheel

Decision gist · record as of 2026-08-14

platform wheels — bashkit-0.16.0-cp39-abi3-macosx_10_12_x86_64.whl · bashkit-0.16.0-cp39-abi3-macosx_11_0_arm64.whl · bashkit-0.16.0-cp39-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
v0.16.0 · released 2026-08-07 · Python >=3.9

Yes, if you need in-process bash execution for AI agents or automation. The active maintenance, zero runtime dependencies, permissive MIT license, and no known vulnerabilities make it low-risk. Medium install friction (compiled wheels) is typical for Rust-backed packages and not a blocker. Verify performance and sandboxing guarantees match your threat model before deploying to production.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.9 or later; compiled wheels are provided for macOS (x86_64, arm64), Linux (x86_64, aarch64, musl), and Windows (x86_64).
  • Medium install friction due to compiled wheels (cp39-abi3 bindings across multiple platforms).
  • Active maintenance with a release 7 days ago and 236 repository stars.

License · maintenance · safety

MIT (permissive) — MIT license (permissive) means you can use, modify, and distribute bashkit freely in commercial or proprietary projects with minimal restrictions—only attribution is required.

last release 2026-08-07 (7 days) · last repo commit 2026-08-14 · 236 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 272,145 downloads/mo, #8,211 on PyPI

Verify before relying

from bashkit import Bash

bash = Bash()
result = bash.execute_sync("echo 'Hello, World!'")
print(result.stdout)  # Hello, World!
  • Performance characteristics and memory overhead compared to subprocess-based bash execution.
  • Completeness of the 164 built-in commands and edge cases in bash syntax compatibility.
  • Security audit status and threat model documentation for the sandboxing guarantees.
Same gist for agents: .md · .json

What it is and what it does

Bashkit embeds a bash interpreter directly into Python via Rust native bindings, letting you execute bash scripts and commands in-process without spawning subprocesses or containers. It maintains persistent state (variables, working directory, virtual filesystem) across calls and includes 164 built-in commands like grep, sed, awk, jq, curl, and find. The package is designed for AI agents and automation workflows where you need fast, controlled bash execution with a virtual filesystem layer.

The interpreter supports full bash syntax—pipelines, redirects, loops, functions, arrays—and offers both synchronous and asynchronous execution modes. You can mount real filesystem paths (read-only or writable), pre-populate virtual files, stream output via callbacks, and control network access through an explicit allowlist. Credentials can be injected transparently or via environment variable placeholders. It integrates with LangChain, PydanticAI, and Deep Agents for agent-based workflows.

Use it for

  • Run bash scripts inside AI agents without subprocess overhead or container orchestration.
  • Execute untrusted bash code in a sandboxed environment with controlled filesystem and network access.
  • Maintain bash interpreter state (variables, cwd, mounted files) across multiple Python function calls.
  • Stream live bash output during execution via callbacks for real-time monitoring or logging.
  • Inject secrets and credentials into bash scripts transparently without exposing them to the script itself.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you need in-process bash execution for AI agents or automation.

The active maintenance, zero runtime dependencies, permissive MIT license, and no known vulnerabilities make it low-risk. Medium install friction (compiled wheels) is typical for Rust-backed packages and not a blocker. Verify performance and sandboxing guarantees match your threat model before deploying to production.

Install

bashkit on PyPI

Before you install

Medium install friction due to compiled wheels (cp39-abi3 bindings across multiple platforms). Active maintenance with a release 7 days ago and 236 repository stars. Supports Python 3.9 through 3.14 with no runtime dependencies, making it straightforward to add once installed.

Requires Python 3.9 or later; compiled wheels are provided for macOS (x86_64, arm64), Linux (x86_64, aarch64, musl), and Windows (x86_64).

License in practice

MIT license (permissive) means you can use, modify, and distribute bashkit freely in commercial or proprietary projects with minimal restrictions—only attribution is required.

Quickstart

from bashkit import Bash

bash = Bash()
result = bash.execute_sync("echo 'Hello, World!'")
print(result.stdout)  # Hello, World!

Verify before relying

  • Performance characteristics and memory overhead compared to subprocess-based bash execution.
  • Completeness of the 164 built-in commands and edge cases in bash syntax compatibility.
  • Security audit status and threat model documentation for the sandboxing guarantees.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.9
Install frictionMedium. Platform-specific wheel
Runtime dependenciesNone
MaintenanceActively maintained 7 days since the last release
Last repo commit
First released
Downloads272,145 / month, #8,211 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 4 - BetaIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.9Programming Language :: RustTopic :: SecurityTopic :: Software Development :: Interpreters

Evidence: bashkit-0.16.0-cp39-abi3-macosx_10_12_x86_64.whl; bashkit-0.16.0-cp39-abi3-macosx_11_0_arm64.whl; bashkit-0.16.0-cp39-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl; bashkit-0.16.0-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl; bashkit-0.16.0-cp39-abi3-musllinux_1_1_aarch64.whl; bashkit-0.16.0-cp39-abi3-musllinux_1_1_x86_64.whl; bashkit-0.16.0-cp39-abi3-pyemscripten_2025_0_wasm32.whl; bashkit-0.16.0-cp39-abi3-win_amd64.whl

Tags

Capabilities
sandboxed bash interpreter pythonin-process bash executionbash sandbox for ai agentsvirtual filesystem bashbash scripting without subprocess
Topics
bash-sandboxai-agentsrust-bindings
PyPI keywords
bashsandboxaiagentshellinterpreter

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “sandboxed bash interpreter python”

  • bashkitBashkit is a sandboxed bash interpreter for Python that runs bash…
  • langchain-azure-dynamic-sessionsProvides LangChain integration tools to execute Python code and bash…
  • starlark-pyo3Exposes the Starlark interpreter (a Python-like language) to Python…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also starlark-pyo3 · bash · pydantic-monty-runtime · contree-sdk · executor · quickjs-rs · hyperlight-sandbox · deepagents-code · swe-rex · spur