Describe what you need. Get a production-ready script. Execute locally in a persistent runspace. Script output, credentials, and runspace state stay on your machine — only what you actively send reaches the AI.
ShellPilot brings AI-assisted scripting into a workflow administrators can actually use: a real Windows UI, local execution, persistent PowerShell state, and clear control over what reaches the AI.
Many AI tools start from the command line. ShellPilot starts from the administrator's workflow. You can describe a task, review the generated PowerShell, execute it locally, inspect the output, paste screenshots or errors when needed, and continue working in the same session.
The goal is not to force every admin into an autonomous agent model. ShellPilot keeps the useful parts of AI assistance while preserving the parts administrators already rely on: visible output, explicit execution, copy-and-paste, documentation, local credentials, and a persistent runspace.
Cloud AI works immediately through the managed proxy. Local AI can be used where the customer already has or wants its own model infrastructure. Either way, the product stays UI-first and operationally simple: copy the executable, activate it, and work.
Built from real infrastructure delivery experience: mixed environments, change pressure, screenshots, logs, credentials, documentation, local execution, and administrators who need control before automation.
Every tool generates PowerShell. The difference is what happens after.
* ShellPilot runs with the permissions of the current user. Elevated operations require admin rights as expected.
Application control policies (AppLocker, WDAC) are respected — ShellPilot does not bypass security controls.
ShellPilot was built to fill gaps that existing tools leave open — persistent sessions, local execution, data privacy by default. PowerShell is the language. How you use it is your decision, not your vendor's. The AI recommends the best approach for your environment, not the one that sells more cloud subscriptions.
Not another AI chatbot with a terminal. A purpose-built execution environment engineered for IT infrastructure operations.
Embedded PowerShell 7 SDK with full session persistence. Variables, connections, and module state survive across every script execution. Connect-AzAccount once, use it for your entire session.
EMBEDDED PS7 SDKSecurity-critical operations run in a native C++ module. Cryptographic keys, device authentication, and credential handling are isolated from managed code.
ECDSA P-256 / DPAPIClient and proxy mutually verify each other using ECDSA signatures before any data exchange. Intercepted traffic cannot impersonate either endpoint.
MUTUAL AUTHENTICATIONDevice fingerprints generated from hardware characteristics. Licenses cannot be copied between machines or shared across unauthorized devices.
DEVICE FINGERPRINTPaste screenshots directly into the chat. AI analyzes error messages, log outputs, and configuration dialogs to generate targeted solutions.
IMAGE RECOGNITIONMulti-layer defense against runaway scripts. Interactive processes, infinite loops, and unexpected behaviors are caught and terminated without affecting your session.
DEFENSE IN DEPTHBuilt-in PowerShell 7 SDK and .NET 10 runtime. No installation, no dependencies, no admin rights required.
Tell ShellPilot what you need in plain language. Paste errors, logs, screenshots, requirements. It understands context.
AI generates production-ready PowerShell with error handling. Edit inline if needed. Multiple solutions presented when appropriate.
One click. Runs locally in your persistent runspace. Results stay on your machine. No data transmitted. Period.
Every layer verified. Every connection authenticated. Every output stays local. Designed for regulated industries.
No chat history stored. No scripts saved. No output cached. Close the application — everything is gone. Nothing is written to disk unless you explicitly export.
Scripts execute in an embedded PS7 runspace. Output, variables, credentials never leave your machine.
Client verifies the proxy. Proxy verifies the client. ECDSA challenge-response prevents MITM attacks.
Every AI request runs through the authenticated proxy path with device-bound session credentials. Captured traffic alone cannot be replayed against another device or reused outside the active session.
Get-Credential and Read-Host -AsSecureString handled natively. Passwords encrypted in memory. Never logged, never sent to AI.
Full ScriptBlock Logging compatibility. Windows Event Log integration. Audit every script execution.
Hardware-based device fingerprints. Activation tied to physical machines. Sessions cannot be cloned or transferred.
Budget, rate limits, device count all enforced server-side. Client-side tampering cannot bypass restrictions.
Extended Validation certificate. Immediate SmartScreen trust on all Windows systems. No download warnings.
Only your text prompt leaves your machine. Scripts, output, credentials, and session data never do.
What you see in the chat is the full conversation, including every script output. What the AI receives is a separate, automatically managed context — usually shorter, trimmed to fit the model's window. Only your prompts and the outputs you actively send via Send to AI enter it.
Solid arrow: your prompt — crosses automatically.
Dashed arrow: a specific script output — crosses only when you click Send to AI on that result.
Reply: the generated script, returned to the chat.
The client verifies the proxy. The proxy verifies the device. Both directions, every call — not just at login. The verification logic lives in the Native C++ Core and protects only the integrity of the connection.
Enterprise SSL inspection sees your prompt, the generated script, and a short-lived session token bound to this specific device. None of those lets an attacker impersonate the proxy or reproduce the backend. A captured token without the matching device is inert.
The Secure Proxy strips your identity before forwarding the request. Your email, subscription, and company are not part of what Google sees — only an anonymous device hash and your prompt.
Prompts, scripts, chat history, and script outputs are not persisted on the proxy or anywhere else. The proxy holds only what it needs to operate: your email, subscription state, and the device hash.
If PowerShell can do it, ShellPilot does it faster. Describe, execute, document — in one tool.
Bulk changes, permission audits, group nesting analysis, stale accounts, tiering assessments.
Azure resources, Entra ID, license management, compliance policies. Connect once, run everything.
HTML reports, Excel exports, audit trails, compliance docs — generated from live data in seconds.
Clone VMs, manage snapshots, move storage, check replication. No more Hyper-V Manager clicking.
Permissions, quotas, forwarding rules, message tracking, archive policies.
DNS records, DHCP scopes, firewall rules, connectivity tests. Network admin as code.
Compare GPOs, find conflicts, analyze inheritance, export settings.
Monitoring agents, scheduled tasks, job orchestration. Build an entire toolbox over time.
SQL queries, REST APIs, file operations, registry, services — ShellPilot does it faster.
Run your own LLM on-premises. AI inference stays on your network. The application still contacts the ShellPilot Azure proxy for subscription verification on launch and refreshes its licence token hourly when online.
Local LLM means inference stays inside your infrastructure. Designed for strict data-sovereignty requirements in banking, government, and healthcare environments.
Cloud outage? Your infrastructure management keeps running. ShellPilot operates independently when AI connectivity is interrupted.
The client refreshes its licence token hourly when online. If the proxy is briefly unreachable, an already-running Local AI session continues for up to 24 hours since the last successful refresh. AI inference itself runs on your hardware throughout.
Local models have inherent limitations (smaller context window). Optimized for standard scripting and automation tasks.
All plans include the full application with embedded PowerShell 7 + .NET 10. Cancel anytime.
All prices in USD, net (excluding applicable taxes). Billed monthly. Cancel anytime.
Annual billing on invoice available for business customers — see checkout.
* Local AI Integration available on Pro and Pro Plus
Want to test ShellPilot in your environment? Request a Demo →