Skip to main content

Running local commands safely

In the desktop application, the assistant can run commands and tests in your chat's workspace. How this works in the chat is explained in Local File Access. On this page you set when this may happen without asking and how isolated commands run.

Opening the command settings​

In a chat, open the Commands panel and choose Command settings for this folder. The settings apply per folder.

When may the assistant run a command?​

Choose one of these three modes:

  • Always ask: you approve every command.
  • Trusted commands automatically: commands you have saved start without asking. Other commands still ask for approval.
  • Automatically in sandbox: everything starts without asking, but in an isolated environment.

Saving trusted commands​

On a command, choose Always allow in this folder and then Exactly this command or Anything that starts with. Saved commands then start without asking. Commands with special characters (such as ; | > $) always ask for approval.

The saved rules are listed in the command settings under Always allowed in this folder. You can also remove them there.

Sandbox and network​

  • Use sandbox: commands can only write in this folder. This option is on by default on macOS and Linux.
  • Allow network: determines whether commands have internet access. This option is off by default. Without a sandbox, commands always have network access.

Every command card shows whether the sandbox and the network are on.

Windows

No sandbox is available on Windows yet.

Local servers and the built-in browser​

The assistant can also start a development server that keeps running, such as npm run dev for a small React project with Vite. The same rules apply as for other commands: you approve the exact command, or it starts through a saved rule or automatically in the sandbox. Instead of the time limit, the card says "Keeps running as a local server until you stop it."

The server keeps running after the assistant has answered. In the Commands panel, the card shows the status Server running with the buttons Open in browser and Stop. Up to 4 servers can run at the same time. Servers stop when you stop them or quit the app.

In the sandbox without network access, a server may only listen on this computer (localhost). To install packages, for example with npm install, turn on Allow network in Command settings for this folder.

You view the result in the built-in browser: the Browser button (the globe icon) on the right of the top bar. The panel opens beside the chat with back, forward, reload (stop while loading), an address bar and Open in your default browser.

  • The assistant opens the browser itself to show the result of a local server. This only works with local addresses, such as http://localhost:5173.
  • If you click a localhost link in an answer, it opens in the built-in browser. Other links open in your default browser.
  • You can also type any web address yourself.
  • The browser has its own separate session: you are not signed in to AI-Corporate there, websites get no permissions such as camera or microphone, and downloads are not possible.
  • While an app menu or dialog is open, the page is temporarily hidden.

Example:

In this folder, create a small React app with Vite that has a counter. Install the dependencies, start the dev server and show the result in the browser.

Settings for administrators​

Administrators can turn off local commands or automatic runs for everyone in the environment. They do this in the admin environment under Features (at environment level), in the Local commands (desktop app) card:

  • Allow local commands: when this is off, the assistant cannot run commands.
  • Allow automatic runs: when this is off, every command asks for approval.