Skip to main content
Pydantic AI gives every run a workspace: the environment its tools reach through ctx.workspace. Mirage’s MirageWorkspace capability supplies a Mirage session as that workspace, so file and shell tools, such as pydantic-ai-backend’s ConsoleCapability, read, write and run commands across every mount.

Install

The extra brings Pydantic AI and the console tools without a model provider; add the provider your agent uses (openai, anthropic, …).

Usage

ConsoleCapability’s default ruleset asks before every write and command. Mirage already judges each call through the session’s mount modes and profile, so the example allows them in the console and leaves the policy to Mirage.

Exports

MirageWorkspace(ws, session_id="agent") acts as that session, so its profile judges every call. Commands run in Mirage’s shell, each in a clone of the session at its working directory, as a subshell does: a cd or an export in one command does not reach the next. Files go through the session’s op facade, and symlinks resolve through the namespace. The run’s WorkspaceRef names the session; a ref in message history that names any other session is declined. The backend passes Pydantic AI’s workspace conformance suite, except the rules that need POSIX processes (mkfifo) or mode bits: Mirage’s permissions are the session profile, not chmod.

Examples