Writing, 30 Sept 2026, 5 min read

Sable: a Linux shell that asks before it runs anything

Sable is an open-source AI shell for Linux servers. Type plain English, see every command before it runs, and approve anything risky from your phone.

You know your server. You don’t remember the exact find invocation, the right journalctl flag, or which docker prune keeps your volumes. So you leave the terminal, search, and paste back a command you haven’t fully read, onto production. I built Sable, an open-source AI shell for Linux servers, so that step goes away without giving up control.

The problem

Say disk usage on a server hits 92% at night. The fix is usually three or four commands: find what grew, check it is safe to delete, delete it, confirm the space came back. None of it is hard. All of it is easy to get slightly wrong, and a slightly wrong rm on a production box is a bad night.

AI chat tools can write those commands, but they live in a browser tab. You copy, you paste, and nothing checks what you pasted. Autonomous agents go the other way: they run commands for you, often without showing them first. I wanted something in between: an assistant that lives in the shell, does the typing, and never runs anything I haven’t seen.

What it does

Sable replaces /bin/bash as your login shell. Type bash and it runs as bash. Type plain English and Sable works out the commands, shows them, and runs the job.

  • Every command is previewed. You see and can edit each command before it runs.
  • Risky commands wait for you. Eleven destructive patterns need a typed YES. Three, like rm -rf / and a fork bomb, never run at all.
  • Your phone is the approve button. When a scheduled job needs approval, Sable sends a push notification. Tapping Approve works once and then expires.
  • It keeps working while you’re away. You can say “every night at 2am, back up postgres”, or watch a disk, a log or a service and get told when something changes.
  • It learns the machine. Work you repeat becomes a reusable skill that you approve, ranked by how often it succeeds.
  • Nothing is hidden. A sidebar shows live model cost and running agents, and every action goes to an audit log.

It runs local models through Ollama by default, or OpenAI and Anthropic directly, with no gateway in between. scp, rsync and git push never touch the model.

How it works

Every line you type goes through a router first. Shell commands go straight to bash. Plain English goes to an orchestrator agent, which plans the work and proposes commands one at a time.

flowchart LR
    Y["You type a line"] --> R{"Router"}
    R -->|"bash"| B["Runs in bash"]
    R -->|"plain English"| O["Orchestrator agent"]
    O --> P{"Policy gate"}
    P -->|"allow"| V["Preview, then run"]
    P -->|"confirm"| C["Waits for YES or phone approval"]
    P -->|"deny"| D["Never runs"]
    O -->|"long job"| S["Sub-agent in a bubblewrap sandbox"]
    V --> A[("Audit log")]
    C --> A

Each proposed command passes through a policy gate before it runs:

you type      "free up space on /var"
router        plain English, send to the orchestrator
orchestrator  proposes: du -sh /var/log/* | sort -h
policy        read-only, allowed; shown as a preview
you           press enter
orchestrator  proposes: journalctl --vacuum-size=200M
policy        changes state, needs confirmation
you           confirm

Long jobs go to sub-agents. Each one runs in its own tmux window, inside a bubblewrap sandbox where the workspace is writable and the rest of the host is read-only, with memory and process limits. You keep your prompt while it works.

Before any command that changes files, Sable snapshots the paths it will touch, so /undo can put them back byte for byte. For plans with several changing steps, it can rehearse the whole plan on a copy first and show you the diff.

Sable also speaks MCP (Model Context Protocol). You can plug in MCP servers as tools, or let an MCP client such as Claude Code drive the server through sable --mcp-serve, behind the same policy and audit log.

Try it

On an Ubuntu 22.04+ or Debian server with Python 3.11+ and tmux:

git clone https://github.com/Parthkomalwad/sable ~/sable
cd ~/sable && bash install.sh

Log out and back in, and a setup wizard picks the model backend. bash uninstall.sh puts /bin/bash back. On Windows or macOS, scripts/playground.sh starts a Docker playground instead.

Sable replaces your login shell, which is a serious thing to replace. Read SECURITY.md first, and keep a second root session open the first time you install it.

What broke along the way

Every phase of Sable ends with a gate: a script that drives the real shell against a real model, with every run recorded. The gates found bugs that unit tests didn’t.

The model kept asking the same thing. When I cancelled a proposed command, the model proposed the same command again, three times in one gate transcript. Now two cancels in a row end the goal, and running anything resets the count.

A retry skipped the safety gate. When a step in a plan failed and was retried, the retry called the command runner directly. It skipped the policy check, and the audit log only recorded the failed first attempt. Retries now go through the gate and are logged as their own run.

The daily budget read zero after midnight. Spend events were stored in UTC, but “today” was matched on the local date. In India, east of UTC, the daily budget saw no spend for hours after midnight. It now counts from local midnight.

A keyboard shortcut did nothing. Ctrl+B was meant to send the next line straight to bash. The key binding set a variable in its own module while the shell read a different one, so it did nothing, and with text typed it crashed. Small bug, but it taught me to test the shell through its real interface, not just its functions.

What’s next

Version 1.0 shipped in September 2026 with MCP, memory, plugins and multi-host commands. Next on my list:

  • Running full goals on other hosts, not only single commands
  • More tasks in the built-in eval suite, which runs 25 real server tasks with no API key needed

The code is on GitHub, MIT licensed, and the full documentation covers installation, the safety model, every command and the architecture. See my other work, or send questions to pkomalwad@gmail.com.

#agents#linux#open-source#mcp

Comments

All writing RSS Reply by email