Shellaro Download

Security model

Shellaro holds access to your servers, so extensions are treated as untrusted code and everything is reviewed before it is installed. This page says what that protects against and where its limits are.

Isolation

What extensions never get

Passwords, passphrases, private keys or key paths, Credential Manager entries, API keys, tokens, Shellaro's settings and files, other extensions' storage, raw terminal input. There is no API for any of these.

Commands on your servers

terminal.execute and remote.exec go through Command Safety, the same engine as typed commands, with the extension named as the origin. remote.exec runs commands you do not see in a terminal, so the first command on each server asks you ("Always allow on <server>" or "Allow once"), showing the command. Consents are listed and revocable per extension.

This is still a trust decision: an extension with remote.exec that you allowed on a server can read files there with commands Command Safety considers harmless (such as cat). The review marks this permission High for that reason. Install such extensions only from publishers you trust.

The local cluster

local.cluster lets an extension ask Shellaro to create, start, stop or delete the local Kubernetes cluster. Creating and deleting always show Shellaro's confirmation. The k3s container runs privileged (Kubernetes needs it), on its own Docker network with no ports on the host; only the toolbox's SSH port is published, on 127.0.0.1.

Packages

Limits, honestly