Description
When running an agent in ACP mode (docker agent serve acp ./agent.yaml) from an ACP-compatible client,
tool-approval prompts for the shell tool display only the word "Shell". The actual command that would be
executed is not visible anywhere in the prompt, so you're asked to approve (or reject) a command you can't
see.
The command does appear to be sent over the wire — it's present in the rawInput field of the permission
request's tool call update (e.g. {"cmd": "...", "cwd": ".", "timeout": 30}) — but the human-readable title is
just the tool's static annotation title ("Shell"), which is what my client renders in the dialog. The same
static title is used for the tool call updates in the transcript, so those also show only "Shell".
Expected Behavior
The approval prompt should convey what is actually being approved. For the shell tool, the prompt should
include the command (or a truncated preview), e.g. as the tool call title (Shell: docker ps -a / Run: rm -rf /tmp/scratch) in addition to rawInput. Ideally this generalizes: derive a descriptive title from the
meaningful arguments of well-known tools (command for shell, path for file operations, etc.).
Actual Behavior
The permission prompt shows only "Shell" with the options "Allow this action" / "Allow and remember my choice"
/ "Skip this action" and no command text. Seeing the command requires an ACP client that renders rawInput (raw
JSON) somewhere in its UI.
Steps to Reproduce
- Configure an agent with the shell tool and default interactive approval.
- Connect from an ACP client that spawns
docker agent serve acp ./agent.yaml.
- Ask the agent to run any shell command (e.g. "list the files in the current directory").
- Observe the approval prompt: only "Shell" is displayed — the command is not shown.
Versions
Docker Agent: v1.139.0
ACP clients:
- Zed 1.21.0
- Intellij Idea 2026.2
Screenshots

Description
When running an agent in ACP mode (
docker agent serve acp ./agent.yaml) from an ACP-compatible client,tool-approval prompts for the shell tool display only the word "Shell". The actual command that would be
executed is not visible anywhere in the prompt, so you're asked to approve (or reject) a command you can't
see.
The command does appear to be sent over the wire — it's present in the rawInput field of the permission
request's tool call update (e.g.
{"cmd": "...", "cwd": ".", "timeout": 30}) — but the human-readable title isjust the tool's static annotation title ("Shell"), which is what my client renders in the dialog. The same
static title is used for the tool call updates in the transcript, so those also show only "Shell".
Expected Behavior
The approval prompt should convey what is actually being approved. For the shell tool, the prompt should
include the command (or a truncated preview), e.g. as the tool call title (
Shell: docker ps -a / Run: rm -rf /tmp/scratch) in addition to rawInput. Ideally this generalizes: derive a descriptive title from themeaningful arguments of well-known tools (command for shell, path for file operations, etc.).
Actual Behavior
The permission prompt shows only "Shell" with the options "Allow this action" / "Allow and remember my choice"
/ "Skip this action" and no command text. Seeing the command requires an ACP client that renders rawInput (raw
JSON) somewhere in its UI.
Steps to Reproduce
docker agent serve acp ./agent.yaml.Versions
Docker Agent: v1.139.0
ACP clients:
Screenshots