# Run commands in Git Bash, and the optional Windows boundary

In NeuralVault 2.0 the shell the assistant uses for commands is PowerShell, you can switch it to Git Bash, and you can turn on an optional boundary where Windows itself refuses writes outside your working folder; both are set in one small file, not on a Settings screen.

*https://perpetualtechnologies.co.uk/support/git-bash-and-the-windows-boundary — last checked 2026-10-11*

## Steps

1. Commands only run when a working folder is attached to the chat. See the guide on attaching a working folder. Every command still asks first.
2. By default commands run in PowerShell. To use Git Bash instead, create a file named .neuralvault-shell.json in your user folder (the file name starts with a dot) containing exactly {"shell": "git_bash"}.
3. Git Bash runs with the same checks, refusals and time limits as PowerShell. If Git Bash is chosen but bash.exe cannot be found, the app says so and uses PowerShell. You can set the NV_GIT_BASH environment variable to the full path of bash.exe.
4. To add the optional Windows boundary, put {"isolation": "windows"} in the same file. Both keys can sit in one file, but Git Bash and background commands are refused while the boundary is on, so use PowerShell with it.
5. With the boundary on, commands run under a write-restricted Windows token inside a job. Windows itself, not the command checker, refuses a write outside the working folders you attached and a private temp folder. The whole process tree is stopped when the run ends or times out, and the job is capped at 512 processes and 8 GiB of memory. NeuralVault adds a permission entry, for an identity that belongs only to NeuralVault, to each attached working folder.
6. It does not cover everything, and each result says so: reading files, the network, and the rule that keeps commands out of your vault are not confined by it.
7. If the boundary is switched on and cannot be set up, the command is refused with the reason and is never run without it. To turn it off, remove the line or set "isolation" to "off".

## How to tell it worked

For Git Bash, ask the assistant to run echo $BASH_VERSION: Git Bash prints a version and PowerShell prints an empty line. For the boundary, a command that writes a file outside your working folder fails with access denied.

## If it does not work

**You are looking for a Git Bash or isolation switch in Settings.**

There is none on this release. The file in your user folder is the only way to set them.

**Commands still run in PowerShell.**

Check the file name starts with a dot, sits in your user folder, is valid JSON, and says git_bash exactly (case does not matter). Anything else keeps PowerShell. Also check bash.exe exists.

**A command was refused with "shell isolation is switched on but could not be set up".**

The boundary is on but Windows would not build it, for example a working folder that is too broad. Fix the folder or remove the "isolation" line in .neuralvault-shell.json.

**You want to undo all of this.**

Delete .neuralvault-shell.json from your user folder. The shell goes back to PowerShell with no boundary. Reset and uninstall remove that file too.

## Related guides

- [Give the assistant a folder to work in](https://perpetualtechnologies.co.uk/support/attach-a-working-folder)
- [Approval cards: approve, decline or rewind a write](https://perpetualtechnologies.co.uk/support/approval-cards)
- [Permission modes: Plan, Manual and Default, and the safety guard](https://perpetualtechnologies.co.uk/support/permission-modes-and-the-safety-guard)

## Still stuck

Bug reports belong in the app, in Settings, About. Those carry no contact details, so they
get fixed rather than answered. To get a reply, email us instead: that route targets two
business days. https://perpetualtechnologies.co.uk/contact
