Built-in Tools
Authoritative for the daemon - every tool listed here is real and callable exactly as shown, not a guess at what might exist.
Discovery and primitives (context_builder)
| Tool | Notes |
|---|---|
search_tools | query = search; category = list domain tools; no args = list domains |
get_tool | Full schema for one FQN |
execute_tool | name + params object |
run_parallel | Prefer tasks: [{tool, args}] |
background_run | Launch / status / wait / cancel / list; notify_when, wait_for; watch + command + interval (+ optional until); signal, stdin |
wait | Block up to timeout_seconds (default 30, max 600) but return EARLY on any meaningful event - a sub-agent finishing or erroring, a background task reaching a terminal state, or a mid-turn user message. Use it after firing off async work instead of polling background_run/agent status in a loop. Optional reason (a short English phrase) is shown to the user next to a live countdown. |
Injection of these depends on the agent having tools (offered
alongside background_run); wait needs nothing beyond that. Injection
of the discovery set also depends on runtime.tool_injection and
catalog size (see Tools).
Conditionally injected
| Tool | Gate |
|---|---|
ask_user | Ask-user enabled |
call_app | Call-app enabled |
use_skill | Skills enabled |
memory.* | Memory enabled |
agent + kv | Agent spawn enabled |
kv: write key+value, read key, delete: true, list: true.
Use search_tools modes to browse by category, and
background_run(watch=true, ...) for a watch loop.
Session cron: scheduler.schedule
Declare tools.modules.scheduler. Params: schedule (5-field cron),
message, optional context, reply, reports. See
scheduler.
Memory
set_goal, remember, task_create, task_update.
Agent spawn
One tool agent with modes (spawn / batch / wait / status / list /
cancel). Coordinator only. See
agent_spawn.
File tools (filesystem)
read, write, edit, multi_edit, glob, grep, delete.
Primary path param is path (file_path accepted as alias).
tools.modules.workspace: in YAML is unconditionally rewritten to
tools.modules.filesystem: at compile time - there is no way to
write workspace: in an app.yaml and get anything other than
filesystem. There is a separate, real module with id workspace
(git-backed status/diff/commit for the session workdir), but every
one of its tools is internal-only - it backs the client's own
diff/approve UI, not something an app grants to an agent via YAML.
Preview
preview (inspect, snapshot), previewshot (screenshot).
Chat UI display labels
The LLM always calls the real FQN (as bash__run,
web__search, ...) - there's no callable short-name variant. The
chat client separately renders a short label in the tool-call
bubble, computed client-side and never sent by the daemon:
| FQN | Chat UI label |
|---|---|
bash.run (also takes a pty bool) | Bash |
web.search / web.fetch | Search / Fetch |
lsp.diagnostics | Diagnostics |
Database: connect, query, disconnect. HTTP: request,
download, upload.