This project is not covered by Drupal’s security advisory policy.

Shellwright is the safe way to let an AI agent look at a Drupal site. Instead of handing an agent SSH and Drush, you give it Shellwright: a bounded, read-only audit that returns one machine-readable report. It can run against production because nothing in it writes to the site.

Shellwright is not an agent and not a chat UI. It bundles no LLM. Your agent stays generic (Claude Code, an MCP client, OpenClaw, a plain CI job) and Shellwright is the Drupal-side tool it calls. A wright is a maker, as in shipwright; Shellwright works your site through a controlled shell, and it will never be an actual shell.

What the audit reports
Eight read-only checks run through a tagged-service registry and fold into a single JSON report with a stable schema:

security_updates: installed projects with known-insecure releases (from the core Update Manager cache, no network calls of its own)
module_updates: non-security updates, revoked and unsupported releases
cron_health: whether cron has run recently
requirements: non-OK entries from the core Status report
deprecated_api: deprecated or obsolete extensions, and those not yet declaring support for the next core major
filesystem_writability: files and directories writable, settings.php and the site directory hardened
queue_health: cron queues whose backlog suggests they are not draining
orphaned_config: config whose declared dependencies (module, theme, or config object) are missing
One report, four ways to reach it

Drush: drush shellwright:audit (alias ash), with --format=json for agents
HTTP: GET /shellwright/api/audit, gated by permission or a bearer token
Admin page: /admin/reports/shellwright
MCP: the shellwright_mcp submodule exposes shellwright-audit and shellwright-list-checks as tools via the mcp module
Least privilege by default

Enabling the module installs a Shellwright auditor role holding only the access shellwright audit permission. Machines never need a Drupal user: mint a token with drush shellwright:token-add, and the token is scoped to the read-only audit. Only SHA-256 hashes are stored.

Fleet and CI
Reports are self-identifying (site name, UUID, environment, schema version), so they compose. A standalone aggregator collects audits from many sites over Drush aliases or token-authenticated HTTP and rolls them up to JSON, a summary table, or an HTML report, with a CI-friendly exit code. A CI example is included.

Guarded writes, kept separate
Write capability lives in the shellwright_ops submodule, disabled by default and CLI only. Every operation has a dry-run plan, requires explicit confirmation and a named environment (production is default-deny), and destructive operations need a further opt-in. Config changes route through config sync, never straight into the active store. Write capability will never be folded into the audit. There is no HTTP or MCP write path.

Extending it
Implement AuditCheckInterface and tag the service shellwright_audit_check. The runner discovers it, isolates failures, and merges its findings into the report. Checks must not write to the site.

Agent skills
Ships a skills pack that tells an agent how to call the audit, read the report, present findings, and the rule that it must never act on a remediation without explicit confirmation and a named environment.

Requirements
Drupal ^10.3 || ^11
Core update module (optional, enables the update checks)
mcp module (optional, for the MCP submodule)
Status

Beta. All transports and the MCP integration are verified on Drupal 11. Feedback and additional checks are welcome in the issue queue.

Links
Home: https://shellwright.com

Project information

  • By dinis on , updated
  • shield alertThis project is not covered by the security advisory policy.
    Use at your own risk! It may have publicly disclosed vulnerabilities.

Releases