Built-in tools
Use this page to check which tools an agent can call and which access each tool requires.
The built-in tools
The engine offers the built-in tools an agent declares in tools/extraTools, according to its
access; basic stays read-only. Workspaces and sandbox covers the
paths, the worktrees and the Docker sandbox.
| Tool | Who gets it | Does |
|---|---|---|
ws.tree, ws.read, ws.search | workspaceAccess read or write | read the node's root |
ws.write, ws.edit, ws.delete | deep + workspaceAccess: write | write files, confined; recorded per ticket |
ws.exec | deep + execute: true | runs a command in the sandbox |
ws.test | deep + execute: true, a project with ci | runs ci.test or ci.script in the sandbox |
git.log, git.diff | any access, a git workspace | read-only history and diff |
submit | every harness | submits the artifact the agent was asked to write; the engine validates it against the output Schema |
write_todos | deep | keeps the agent's todo list |
task | deep with subagents | hands one piece of work to a subagent |
See also
- Agent manifests for tool and access fields.
- Workspaces and sandbox for path and isolation rules.