返回 DeepSeek-Reasonix
tool_schemas.json
根目录 / internal / boot / testdata / golden / windows-powershell / tool_schemas.json
1 [
2 {
3 "Name": "ask",
4 "Description": "Ask the user one or more multiple-choice questions when you hit a decision that is genuinely theirs to make — one you can't resolve from the request, the code, or sensible defaults. The frontend shows the options for the user to pick; their choices are returned to you. Prefer this over asking in prose for any real fork (which approach, which library, scope). Don't use it for decisions with an obvious default — pick the sensible option and proceed. Permission presets do not answer these questions for the user. Each question has a short `header` (a tab label), the `question` text, 2-4 `options` (each a `label` and optional `description`; put any recommended option first), and `multiSelect` when more than one may apply.",
5 "ReadOnly": true,
6 "Schema": {
7 "properties": {
8 "decision_id": {
9 "description": "Required when reopening a previously accepted decision; cite the original decision_id.",
10 "type": "string"
11 },
12 "new_evidence": {
13 "description": "Required with decision_id when asking again after the user already accepted a consequence.",
14 "type": "string"
15 },
16 "questions": {
17 "description": "1-3 related questions to ask together. Same ambiguity is asked only once.",
18 "items": {
19 "properties": {
20 "header": {
21 "description": "Very short label for the question (a tab title), e.g. \"Library\".",
22 "type": "string"
23 },
24 "multiSelect": {
25 "description": "Allow selecting more than one option.",
26 "type": "boolean"
27 },
28 "options": {
29 "description": "The choices. Put any recommended option first.",
30 "items": {
31 "properties": {
32 "description": {
33 "description": "Optional one-line explanation of the choice.",
34 "type": "string"
35 },
36 "label": {
37 "description": "The choice text (concise).",
38 "type": "string"
39 }
40 },
41 "required": [
42 "label"
43 ],
44 "type": "object"
45 },
46 "maxItems": 4,
47 "minItems": 2,
48 "type": "array"
49 },
50 "question": {
51 "description": "The full question to ask.",
52 "type": "string"
53 }
54 },
55 "required": [
56 "header",
57 "options",
58 "question"
59 ],
60 "type": "object"
61 },
62 "maxItems": 3,
63 "minItems": 1,
64 "type": "array"
65 }
66 },
67 "required": [
68 "questions"
69 ],
70 "type": "object"
71 }
72 },
73 {
74 "Name": "compress",
75 "Description": "Compress a selected part of the current model-visible conversation without deleting visible history. Use only when the user explicitly asks for context compression. Choose `before` to summarize everything before the uniquely matched user turn while keeping that turn and later context, or `after` to summarize from that turn through the last completed turn while keeping the active turn. The anchor must be an exact, unique excerpt from a real user message; use a longer excerpt if the tool reports multiple matches.",
76 "ReadOnly": true,
77 "Schema": {
78 "additionalProperties": false,
79 "properties": {
80 "anchor": {
81 "description": "An exact, unique excerpt from one real user message in the current model-visible conversation.",
82 "maxLength": 512,
83 "minLength": 1,
84 "type": "string"
85 },
86 "direction": {
87 "description": "Which side of the anchor user turn to compress.",
88 "enum": [
89 "before",
90 "after"
91 ],
92 "type": "string"
93 },
94 "focus": {
95 "description": "Optional guidance about facts or decisions the summary must preserve.",
96 "maxLength": 2000,
97 "type": "string"
98 }
99 },
100 "required": [
101 "anchor",
102 "direction"
103 ],
104 "type": "object"
105 }
106 },
107 {
108 "Name": "create_goal",
109 "Description": "Create one persisted same-session goal when the current direct human request is a long-running objective that should continue across autonomous rounds. You may infer that intent without requiring the user to name goal mode. Do not use this for routine single-turn work.",
110 "ReadOnly": false,
111 "Schema": {
112 "additionalProperties": false,
113 "properties": {
114 "max_goal_rounds": {
115 "anyOf": [
116 {
117 "minimum": 1,
118 "type": "integer"
119 },
120 {
121 "type": "null"
122 }
123 ],
124 "description": "Optional positive automatic-round limit; omit or null for unlimited."
125 },
126 "objective": {
127 "minLength": 1,
128 "type": "string"
129 }
130 },
131 "required": [
132 "objective"
133 ],
134 "type": "object"
135 }
136 },
137 {
138 "Name": "edit_file",
139 "Description": "Replace an exact string in a file with another. old_string must occur exactly once; add surrounding context to disambiguate. Use for targeted edits instead of rewriting the whole file.",
140 "ReadOnly": false,
141 "Schema": {
142 "properties": {
143 "new_string": {
144 "description": "Replacement text (may be empty to delete)",
145 "type": "string"
146 },
147 "old_string": {
148 "description": "Exact text to replace (must be unique in the file)",
149 "type": "string"
150 },
151 "path": {
152 "description": "File path",
153 "type": "string"
154 }
155 },
156 "required": [
157 "new_string",
158 "old_string",
159 "path"
160 ],
161 "type": "object"
162 }
163 },
164 {
165 "Name": "get_goal",
166 "Description": "Read the current same-session goal, including its exact id/revision, objective, phase, admitted rounds, optional round limit, blocker reason, and live activation. Call this before update_goal.",
167 "ReadOnly": true,
168 "Schema": {
169 "additionalProperties": false,
170 "properties": {},
171 "required": [],
172 "type": "object"
173 }
174 },
175 {
176 "Name": "job_kill",
177 "Description": "Request cancellation of a running background job by job id. Returns immediately; the process tree settles as killed once shutdown completes.",
178 "ReadOnly": false,
179 "Schema": {
180 "properties": {
181 "job_id": {
182 "description": "Job id returned by the tool that started the background work.",
183 "type": "string"
184 },
185 "reason": {
186 "description": "Optional short reason for stopping the job.",
187 "type": "string"
188 }
189 },
190 "required": [
191 "job_id"
192 ],
193 "type": "object"
194 }
195 },
196 {
197 "Name": "job_output",
198 "Description": "Read output from a background job. Reads are non-blocking unless wait=true; every response includes the current status. Do not busy-poll a running job.",
199 "ReadOnly": true,
200 "Schema": {
201 "properties": {
202 "filter": {
203 "description": "Optional regular expression; only matching lines of new output are returned.",
204 "type": "string"
205 },
206 "job_id": {
207 "description": "Job id returned by the tool that started the background work.",
208 "type": "string"
209 },
210 "timeout_ms": {
211 "description": "Maximum wait in milliseconds. Defaults to 30000 and is capped at 600000.",
212 "maximum": 600000,
213 "minimum": 1,
214 "type": "integer"
215 },
216 "wait": {
217 "description": "Wait until the job finishes or timeout_ms elapses. A timeout leaves the job running.",
218 "type": "boolean"
219 }
220 },
221 "required": [
222 "job_id"
223 ],
224 "type": "object"
225 }
226 },
227 {
228 "Name": "pwsh",
229 "Description": "Execute one PowerShell command in an isolated process and return combined stdout/stderr. The host prefers PowerShell 7 and can fall back to Windows PowerShell 5.1, so use syntax accepted by both:\n - chaining: ';' runs both commands; use 'if ($?) { ... }' for conditional execution.\n - redirect/vars: $null not /dev/null; $env:VAR not $VAR; '2\u003e$null' drops stderr.\n - file ops: Get-ChildItem (ls), Remove-Item -Recurse -Force (rm -rf), Copy-Item (cp), Select-String (grep).\n - file text: read with read_file and change with edit_file/write_file, not Get-Content, Set-Content, Out-File or '\u003e'. Windows PowerShell 5.1 reads BOM-less UTF-8 as the ANSI code page and writes ANSI or UTF-16; the built-in tools keep each file's encoding and BOM.\n - no head/tail/which/touch: use Select-Object -First/-Last N, (Get-Command x).Source, New-Item.\n - services/watchers: set run_in_background=true and manage the returned job id with job_output/job_kill.\n - multi-line text to a native exe (e.g. git commit -m): use a single-quoted here-string @'...'@ (closing '@ at column 0). Use for builds, tests, git, package managers, etc. To search/read/list/edit/move files, prefer the dedicated tools (grep, read_file, ls, glob, edit_file, move_file) over shell grep/cat/ls/find/sed/mv/Move-Item — they behave identically on every OS. For symbol search or architecture questions, prefer LSP/read tools and targeted grep before shell commands.",
230 "ReadOnly": false,
231 "Schema": {
232 "properties": {
233 "additional_write_dirs": {
234 "description": "Directories this command must write outside the workspace. Directories only, no globs. Accepts absolute paths, workspace-relative paths, ~, and ${HOME}. Request the smallest set needed; the host will not infer paths from the command text.",
235 "items": {
236 "type": "string"
237 },
238 "type": "array"
239 },
240 "command": {
241 "description": "PowerShell command to execute",
242 "type": "string"
243 },
244 "denial_id": {
245 "description": "Host-issued denial identifier required when retrying with danger-full-access.",
246 "type": "string"
247 },
248 "description": {
249 "description": "Clear 5-10 word active-voice description shown in the UI",
250 "type": "string"
251 },
252 "justification": {
253 "description": "Required when additional_write_dirs or sandbox_permissions is set. Explain why the access is needed.",
254 "type": "string"
255 },
256 "run_in_background": {
257 "description": "Run without a foreground timeout and return a pwsh job id immediately. Read it with job_output or stop it with job_kill.",
258 "type": "boolean"
259 },
260 "sandbox_permissions": {
261 "description": "Optional per-call permission escalation. Use workspace-write for an authorized write while the session is read-only. danger-full-access is accepted only after a host-recorded denial and explicit authorization.",
262 "enum": [
263 "workspace-write",
264 "danger-full-access"
265 ],
266 "type": "string"
267 },
268 "timeout_ms": {
269 "description": "Optional foreground timeout in milliseconds, capped by the configured shell timeout",
270 "minimum": 1,
271 "type": "integer"
272 }
273 },
274 "required": [
275 "command",
276 "description"
277 ],
278 "type": "object"
279 }
280 },
281 {
282 "Name": "read_file",
283 "Description": "Read one bounded text window with optional line offset/limit. Output prefixes each line with its 1-based number. Any successful window observes the current file version for later structured edits. Use the next-window hint to page only when more content is useful. Legacy intent and cursor fields are accepted as navigation hints and never create a whole-file completion requirement.",
284 "ReadOnly": true,
285 "Schema": {
286 "properties": {
287 "cursor": {
288 "description": "Optional continuation cursor from a prior result. Invalid legacy cursors should be replaced with an explicit offset and limit.",
289 "type": "string"
290 },
291 "intent": {
292 "description": "Compatibility hint. Every value reads only this bounded window and creates no whole-file obligation.",
293 "enum": [
294 "inspect",
295 "range",
296 "full"
297 ],
298 "type": "string"
299 },
300 "limit": {
301 "description": "Maximum lines to return (default 2000)",
302 "minimum": 1,
303 "type": "integer"
304 },
305 "offset": {
306 "description": "0-based line offset to start reading from (default 0)",
307 "minimum": 0,
308 "type": "integer"
309 },
310 "path": {
311 "description": "File path",
312 "type": "string"
313 }
314 },
315 "required": [
316 "path"
317 ],
318 "type": "object"
319 }
320 },
321 {
322 "Name": "todo_write",
323 "Description": "Replace the current turn's complete task list. Send the full flat list on every call; an empty list clears it. Items may be reordered, removed, replanned, or have any number in progress. Each item contains only content and status (pending|in_progress|completed).",
324 "ReadOnly": true,
325 "Schema": {
326 "additionalProperties": false,
327 "properties": {
328 "todos": {
329 "description": "The complete flat task list for this turn. Replaces the previous list; [] clears it.",
330 "items": {
331 "additionalProperties": false,
332 "properties": {
333 "content": {
334 "description": "Task text. Leading and trailing whitespace is removed.",
335 "minLength": 1,
336 "type": "string"
337 },
338 "status": {
339 "enum": [
340 "pending",
341 "in_progress",
342 "completed"
343 ],
344 "type": "string"
345 }
346 },
347 "required": [
348 "content",
349 "status"
350 ],
351 "type": "object"
352 },
353 "type": "array"
354 }
355 },
356 "required": [
357 "todos"
358 ],
359 "type": "object"
360 }
361 },
362 {
363 "Name": "update_goal",
364 "Description": "Update the exact current goal revision. edit, pause, and resume require current direct-human authority; complete and blocked are also allowed during the exact autonomous goal round. There is no continue action: leaving an active goal unchanged continues it automatically. Only edit consumes objective/max_goal_rounds; only blocked consumes blocked_reason. Omit unused fields; supplied unused fields are ignored.",
365 "ReadOnly": false,
366 "Schema": {
367 "additionalProperties": false,
368 "properties": {
369 "action": {
370 "enum": [
371 "edit",
372 "pause",
373 "resume",
374 "complete",
375 "blocked"
376 ],
377 "type": "string"
378 },
379 "blocked_reason": {
380 "anyOf": [
381 {
382 "type": "string"
383 },
384 {
385 "type": "null"
386 }
387 ],
388 "description": "Non-empty concrete blocker required for blocked. Ignored for other actions."
389 },
390 "goal_id": {
391 "minLength": 1,
392 "type": "string"
393 },
394 "max_goal_rounds": {
395 "anyOf": [
396 {
397 "minimum": 1,
398 "type": "integer"
399 },
400 {
401 "type": "null"
402 }
403 ],
404 "description": "Replacement limit for edit; omit to keep it, null removes the limit. Ignored for other actions."
405 },
406 "objective": {
407 "anyOf": [
408 {
409 "type": "string"
410 },
411 {
412 "type": "null"
413 }
414 ],
415 "description": "Replacement non-empty objective for edit; omit or null to keep it. Ignored for other actions."
416 },
417 "revision": {
418 "minimum": 1,
419 "type": "integer"
420 }
421 },
422 "required": [
423 "action",
424 "goal_id",
425 "revision"
426 ],
427 "type": "object"
428 }
429 },
430 {
431 "Name": "use_capability",
432 "Description": "Fixed-schema capability proxy. Prefer search(query, limit\u003c=8), then inspect one exact capability, then call it. list is a compact diagnostic inventory only. Supports stable ids such as tool:grep, skill:review, mcp-tool:server/tool, task:subagent, workflow:name, and web:/lsp:/session:/memory: namespaces. memory:remember saves facts (description+body required; activation=\"relevant\" on create; omit activation on update; \"pinned\" only if user asks); memory:forget(name); tool:memory(operation=search|read|list). decline records a reason for a prefer capability. Independent list/search/inspect calls are read-only and may be issued together. Calls keep the provider-visible schema fixed; real writers still pass permission, plan mode, sandbox, write-path, and workspace-lease checks.",
433 "ReadOnly": true,
434 "Schema": {
435 "additionalProperties": false,
436 "properties": {
437 "action": {
438 "description": "Use search for discovery, inspect one exact result, then call. list is diagnostic only.",
439 "enum": [
440 "list",
441 "search",
442 "inspect",
443 "call",
444 "decline"
445 ],
446 "type": "string"
447 },
448 "arguments": {
449 "description": "Raw MCP tool arguments for action=call",
450 "type": "object"
451 },
452 "capability_id": {
453 "description": "Capability id such as skill:review, mcp-server:github, or mcp-tool:github/search_issues. Not required for action=list.",
454 "type": "string"
455 },
456 "cursor": {
457 "description": "Opaque cursor returned by action=list. It is valid only for the same catalog version.",
458 "type": "string"
459 },
460 "limit": {
461 "description": "Maximum results. Search defaults to 5 and allows at most 8; list defaults to 50 and allows at most 100.",
462 "maximum": 100,
463 "minimum": 1,
464 "type": "integer"
465 },
466 "query": {
467 "description": "Local catalog query required for action=search. No process or network is started.",
468 "type": "string"
469 },
470 "reason": {
471 "description": "Required non-empty reason when action=decline",
472 "type": "string"
473 }
474 },
475 "required": [
476 "action"
477 ],
478 "type": "object"
479 }
480 },
481 {
482 "Name": "view_image",
483 "Description": "Read a local PNG, JPEG, GIF, or WebP image by path and return visual content through native vision or the configured image-understanding model. Use this for image paths instead of read_file. Maximum file size: 3 MiB; maximum dimensions: 40 million pixels.",
484 "ReadOnly": true,
485 "Schema": {
486 "properties": {
487 "path": {
488 "description": "Image file path",
489 "type": "string"
490 }
491 },
492 "required": [
493 "path"
494 ],
495 "type": "object"
496 }
497 },
498 {
499 "Name": "write_file",
500 "Description": "Write content to a file at the given path (overwriting existing content). Creates parent directories as needed.",
501 "ReadOnly": false,
502 "Schema": {
503 "properties": {
504 "content": {
505 "description": "Full content to write",
506 "type": "string"
507 },
508 "path": {
509 "description": "File path",
510 "type": "string"
511 }
512 },
513 "required": [
514 "content",
515 "path"
516 ],
517 "type": "object"
518 }
519 }
520 ]
521
521 lines JSON