Tools and permissions

The model selects from advertised tools. The runtime owns registration, validation, execution, and the results returned to the model.

One capability boundary

Configured permissions → ToolRegistry → ToolRouter
                                      → Model request
                                      → Validated call → Handler → Result

Each handler supplies its specification. The finalized router advertises and dispatches the same capabilities; a model-supplied name cannot enable an unregistered tool. Calls execute sequentially after response validation.

Most calls use JSON function arguments. apply_patch carries raw patch text. The router preserves their payload kinds and call IDs in retained history.

Permission modes

ModeAvailable local actions
DisabledNo local tools
Read-onlyFile inspection, plans, and available coordination services
FullRead-only actions plus patches and shell commands

Main and workers retain configured permissions. Role guidance directs how they coordinate. Child agents inherit effective permissions and model settings; Echo makes no model requests and executes no tools.

File tools enforce workspace path boundaries. Full mode executes unsandboxed host shell commands without per-call approval. A failed tool can leave effects already applied, so errors and prior results remain visible to later steps.

Coordination tools manage conversations and delivery. Hosted web search is executed by the provider inside the model request.

Implementation: tools/.