> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nika.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# exec

> Contract, placement, related fields and source examples for this Nika YAML field.

[Language reference](/reference/language/overview) / `exec`

## Meaning and placement

### → permits

false = no shells · true = any (blocklist-gated) · array = allowed program names.

| Property        | Declaration                           |
| --------------- | ------------------------------------- |
| Requirement     | Optional in this object               |
| Schema location | `/properties/permits/properties/exec` |

**In the same object:** [env](/reference/language/words/env) · [fs](/reference/language/words/fs) · [net](/reference/language/words/net) · [tools](/reference/language/words/tools)

[Schema source (use the pointer above)](https://github.com/supernovae-st/nika-spec/blob/c5ebbb7b862b68bc6cf7235efba61173b844afc6/schemas/workflow.schema.json)

### task

The schema declares this field at the location below.

| Property        | Declaration                   |
| --------------- | ----------------------------- |
| Requirement     | Optional in this object       |
| Schema location | `/$defs/task/properties/exec` |
| \$ref           | "#/\$defs/exec"               |

**In the same object:** [after](/reference/language/words/after) · [agent](/reference/language/words/agent) · [extract](/reference/language/words/extract) · [for\_each](/reference/language/words/for_each) · [group](/reference/language/words/group) · [infer](/reference/language/words/infer) · [invoke](/reference/language/words/invoke) · [lift](/reference/language/words/lift) · [on\_error](/reference/language/words/on_error) · [retry](/reference/language/words/retry) · [returns](/reference/language/words/returns) · [timeout](/reference/language/words/timeout) · [when](/reference/language/words/when) · [with](/reference/language/words/with)

[Schema source (use the pointer above)](https://github.com/supernovae-st/nika-spec/blob/c5ebbb7b862b68bc6cf7235efba61173b844afc6/schemas/workflow.schema.json)

## In a source template

Excerpt from `templates/docker-report.nika.yaml`, source lines 36–45. This is a fragment, not a runnable workflow.

```yaml illustration theme={"system"}
model: mock/echo

permits:                            # the blast radius · default-deny once present
  exec:
    - "docker"                      # SLOT: the ONE program the reads may launch
  tools:
    - "nika:write"
  fs:
    write:
      - "./docker-health.md"        # SLOT: where the report lands (must match `keep`)
```

### Templates containing this field

| Template                               | Source                                                                                                                                       |
| -------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- |
| `templates/docker-report.nika.yaml`    | [Line 39](https://github.com/supernovae-st/nika-spec/blob/c5ebbb7b862b68bc6cf7235efba61173b844afc6/templates/docker-report.nika.yaml#L39)    |
| `templates/human-gated-ship.nika.yaml` | [Line 61](https://github.com/supernovae-st/nika-spec/blob/c5ebbb7b862b68bc6cf7235efba61173b844afc6/templates/human-gated-ship.nika.yaml#L61) |

These are literal key occurrences in the source files, not an execution or conformance claim. [How to instantiate a template](/guides/templates).

## Contract and implementation

This page projects the named specification revision. Check [released engine status](/reference/status) and [the validation workflow](/guides/agent-authoring) before running a file. An optional field is not evidence that every engine supports every value.

Canonical identity: `language:word:exec`. Spec revision: [`c5ebbb7b862b`](https://github.com/supernovae-st/nika-spec/tree/c5ebbb7b862b68bc6cf7235efba61173b844afc6).

[How documentation stays connected](/reference/knowledge-system).
