ctx.workspace. Mirage’s MirageWorkspace capability supplies a Mirage session as that workspace, so file and shell tools, such as pydantic-ai-backend’s ConsoleCapability, read, write and run commands across every mount.
Install
openai, anthropic, …).
Usage
ConsoleCapability’s default ruleset asks before every write and command. Mirage already judges each call through the session’s mount modes and profile, so the example allows them in the console and leaves the policy to Mirage.
Exports
MirageWorkspace(ws, session_id="agent") acts as that session, so its profile judges every call. Commands run in Mirage’s shell, each in a clone of the session at its working directory, as a subshell does: a cd or an export in one command does not reach the next. Files go through the session’s op facade, and symlinks resolve through the namespace. The run’s WorkspaceRef names the session; a ref in message history that names any other session is declined.
The backend passes Pydantic AI’s workspace conformance suite, except the rules that need POSIX processes (mkfifo) or mode bits: Mirage’s permissions are the session profile, not chmod.
Examples
examples/python/agents/pydantic_ai/s3_agent.py, read-only S3 exploration.examples/python/agents/pydantic_ai/s3_pdf_agent.py, native PDF input from S3.examples/python/agents/pydantic_ai/slack_pdf_agent.py, native image and PDF reads from Slack.