GPTScript
Scripting language that lets LLMs interact with any system via natural language — run shell commands, call APIs, and chain tools.
GPTScript
GPTScript is a scripting framework that allows LLMs to seamlessly interact with your operating system, local tools, and remote APIs using a minimal natural-language-like syntax. Scripts are plain text files; the LLM decides which tools to call and in what order.
Key Features
- Natural-language scripts: write intent in plain English; GPTScript figures out the tool calls
- Built-in tools: file I/O, HTTP requests, code execution, and system shell — all available by default
- Context sharing: pass files, URLs, and previous outputs as context between script steps
- OpenAI + local models: works with any OpenAI-compatible API including local Ollama models
- Daemon & workspace mode: long-running assistants with persistent workspace for multi-turn interactions
- Composable: import and call other GPTScript files as sub-routines
Quick Start
# macOS / Linux
brew install gptscript-ai/tap/gptscript
# or
curl https://get.gptscript.ai/install.sh | sh
export OPENAI_API_KEY=your_key
# hello.gpt
cat > hello.gpt <<'EOF'
tools: sys.exec
List the 5 largest files in the current directory and explain what they might contain.
EOF
gptscript hello.gpt
npx ai-supply add gptscript-natural-language-automation
Curated mirror of the open-source GPTScript (Apache-2.0). Get it from the source.
Compromise signals — malicious or tampered code (leaked secrets, backdoors, a dropped executable) — reduce the score, and known dependency CVEs carry a bounded penalty (they warrant review but never QUARANTINE — update the dependency to clear). Other dangerous-by-capability traits are risk surface, expected for some capabilities. Every finding is mapped to its OWASP control below.
Findings mapped to the OWASP Top 10 for LLM Applications (2025) and the OWASP Machine Learning Security Top 10. Expand any flagged control for the exact findings — compromise reduces the score; expected/risk-surface do not, except a known CVE, which carries a small bounded penalty (high/critical → Review).
The same gate an agent runs before installing (POST /api/v1/trust/gptscript-natural-language-automation/check). Click a policy:
Consume GPTScript programmatically. Authenticate with an API key or session — see Authorize an agent.
# Agents: CHECK BEFORE YOU INSTALL (no auth) — score, grade, level, capability manifest
curl https://ai-supply.store/api/v1/trust/gptscript-natural-language-automation
# Gate against your org policy (returns { pass, violations })
curl -X POST https://ai-supply.store/api/v1/trust/gptscript-natural-language-automation/check \
-H "Content-Type: application/json" \
-d '{"minGrade":"B","denyPermissions":["shell"],"denyUnknownEgress":true}'
# CLI
npx ai-supply add gptscript-natural-language-automation
# REST (install → download)
curl -X POST https://ai-supply.store/api/v1/listings/gptscript-natural-language-automation/install \
-H "Authorization: Bearer $AIM_KEY"
# MCP tool
install_listing({ "slug": "gptscript-natural-language-automation" })OpenAPI spec →Curated mirror — latest upstream source. See the repository for tagged releases.