27 tools, namespaced by domain.
Every tool is declared with JSON-schema parameters and returned as a
structured call. Names carry their domain — fs_*, search_*, dev_* — so the model always knows what it's reaching for.
Files
9 toolsRead, write, and reshape files — with parents created for you.
| Tool | What it does | Parameters |
|---|---|---|
| fs_ls | List a directory | dir |
| fs_read | Read a file (optional range) | path, offset, limit |
| fs_write | Create / overwrite a file | path, content |
| fs_append | Append to a file (creates it) | path, content |
| fs_mkdir | Create a directory (and parents) | path |
| fs_edit | Replace a unique string | path, old_string, new_string |
| fs_delete | Delete a file or directory | path |
| fs_move | Move / rename | from, to |
| fs_copy | Copy a file or directory | from, to |
Search
3 toolsFind code by content, by name, or as a whole tree.
| Tool | What it does | Parameters |
|---|---|---|
| search_grep | Recursive content search | pattern, dir, include |
| search_glob | Find files by name pattern | pattern, dir |
| search_tree | Directory tree to a depth | dir, depth |
Media
2 toolsPull text out of the images and documents in your repo.
| Tool | What it does | Parameters |
|---|---|---|
| ocr_image | Extract text from an image (tesseract) | path |
| extract_pdf | Extract the text of a PDF (pdftotext) | path |
Shell & dev
4 toolsOne sandboxed shell, then first-class git, build, and test tools.
| Tool | What it does | Parameters |
|---|---|---|
| shell_run | Sandboxed shell command | cmd, args[] |
| dev_git | Read-only git (status/diff/log/show/branch) | subcommand |
| dev_build | Compile the project | target |
| dev_test | Run the test suite | — |
Session
6 toolsPlan the work, remember across turns, and roll back any edit.
| Tool | What it does | Parameters |
|---|---|---|
| todo_write | Overwrite the task list | items |
| todo_read | Read the current task list | — |
| memory_save | Persist a key/value note | key, value |
| memory_read | Read a stored note | key |
| snapshots | List recent file snapshots | — |
| fs_restore | Restore a file from a snapshot | path |
Web & agent
3 toolsFetch, ask, and finish — the control plane of a turn.
| Tool | What it does | Parameters |
|---|---|---|
| web_fetch | Fetch a URL (host allowlist) | url |
| agent_ask | Ask the user and wait | question |
| agent_finish | End the turn with a summary | summary |
Powerful tools, held on a short leash.
- Confinement
Every path is resolved inside the project root. Escapes are refused, not sanitised.
- Write policy
none, confirm, or allow — with protected paths that never budge.
- Size caps
Tool output is truncated in bytes so a big repo cannot blow the context budget.
- Cleared env
shell_run runs without your API keys in the environment.
# tools are plain JSON-schema — a peek at one
{
"name": "fs_edit",
"description": "Replace a unique...",
"parameters": {
"path": "string",
"old_string": "string",
"new_string": "string"
}
}