| 1 | [ |
| 2 | { |
| 3 | "name": "bash", |
| 4 | "description": "Execute a shell command in the workspace and return stdout and stderr. Output keeps the last 2000 lines or 50KB. An optional timeout is expressed in seconds; when omitted the command is killed after 120 seconds, so pass an explicit timeout for work expected to take longer. In Ask, after a sandbox denial, retry the exact command once with sandbox_permissions (the narrowest wider mode that suffices) and a one-sentence justification; the approval prompt asks the user.", |
| 5 | "input_schema": { |
| 6 | "additionalProperties": false, |
| 7 | "properties": { |
| 8 | "command": { |
| 9 | "description": "The command to execute. Actual execution shell: `/bin/bash`. Use Bash syntax: pipelines, redirections, $(command), and && / || are supported. Quote paths and variable expansions, such as \"$path\"; use single quotes for literal text. For literal multiline input, use a quoted heredoc delimiter (<<'EOF') with its closing delimiter on a separate line. Use only installed programs; do not assume GNU-specific flags on macOS/BSD. Example: printf '%s\\n' 'sample'.", |
| 10 | "type": "string" |
| 11 | }, |
| 12 | "justification": { |
| 13 | "description": "Required with sandbox_permissions: one sentence explaining why this exact command needs wider access.", |
| 14 | "type": "string" |
| 15 | }, |
| 16 | "read_only": { |
| 17 | "description": "Set true to run analysis code (including Python/SQLite) with mandatory native filesystem read-only isolation and no network. Available during peer writes. Refused when native enforcement is unavailable; no background, stdin, external backend, or sandbox escalation.", |
| 18 | "type": "boolean" |
| 19 | }, |
| 20 | "sandbox_permissions": { |
| 21 | "description": "The wider sandbox mode this exact command needs. Use only as a one-shot retry after a sandbox denial; requires justification and user approval in Ask.", |
| 22 | "enum": [ |
| 23 | "workspace-write", |
| 24 | "danger-full-access" |
| 25 | ], |
| 26 | "type": "string" |
| 27 | }, |
| 28 | "timeout": { |
| 29 | "description": "Optional timeout in seconds; when omitted the command is killed after 120 seconds.", |
| 30 | "type": "number" |
| 31 | } |
| 32 | }, |
| 33 | "required": [ |
| 34 | "command" |
| 35 | ], |
| 36 | "type": "object" |
| 37 | }, |
| 38 | "allowed_callers": [ |
| 39 | "direct" |
| 40 | ], |
| 41 | "defer_loading": false |
| 42 | }, |
| 43 | { |
| 44 | "name": "create_goal", |
| 45 | "description": "Create the session's one persistent goal: a completion objective Codewhale keeps working toward across turns until it is verified complete, blocked, or the user stops it. You decide when a request is a durable objective worth carrying across turns — a multi-step outcome the user will want continued and verified. Do not create a goal for a question, a greeting, a one-shot edit, or a conversational probe; those are ordinary turns. When the user explicitly asks to use `/goal` or asks you to make something the goal, call `create_goal` before doing the rest of the work; acknowledging it in prose is not sufficient. Keep the user's full objective, not a shortened one-turn version. Set token_budget only when the user explicitly provides one. Creating a goal shows the user a one-line receipt (they can /goal pause or /goal clear); do not also ask for confirmation. Only one unfinished goal exists at a time: complete or clear it before creating another.", |
| 46 | "input_schema": { |
| 47 | "additionalProperties": false, |
| 48 | "properties": { |
| 49 | "objective": { |
| 50 | "description": "The full objective to pursue. Keep the complete user goal, not a shortened one-turn version.", |
| 51 | "type": "string" |
| 52 | }, |
| 53 | "token_budget": { |
| 54 | "description": "Optional soft token budget for the goal.", |
| 55 | "minimum": 0, |
| 56 | "type": "integer" |
| 57 | } |
| 58 | }, |
| 59 | "required": [ |
| 60 | "objective" |
| 61 | ], |
| 62 | "type": "object" |
| 63 | }, |
| 64 | "allowed_callers": [ |
| 65 | "direct" |
| 66 | ], |
| 67 | "defer_loading": false |
| 68 | }, |
| 69 | { |
| 70 | "name": "edit", |
| 71 | "description": "Edit one file with targeted text replacements. Every edits[].oldText must identify a unique, non-overlapping region of the original file. Merge nearby or overlapping changes into one edit.", |
| 72 | "input_schema": { |
| 73 | "additionalProperties": false, |
| 74 | "properties": { |
| 75 | "edits": { |
| 76 | "description": "One or more disjoint replacements, all matched against the original file.", |
| 77 | "items": { |
| 78 | "additionalProperties": false, |
| 79 | "properties": { |
| 80 | "newText": { |
| 81 | "description": "Replacement text; may be empty to delete the matched span.", |
| 82 | "type": "string" |
| 83 | }, |
| 84 | "oldText": { |
| 85 | "description": "Text identifying one unique region to replace.", |
| 86 | "type": "string" |
| 87 | } |
| 88 | }, |
| 89 | "required": [ |
| 90 | "newText", |
| 91 | "oldText" |
| 92 | ], |
| 93 | "type": "object" |
| 94 | }, |
| 95 | "type": "array" |
| 96 | }, |
| 97 | "path": { |
| 98 | "description": "Path to the file to edit (relative or absolute).", |
| 99 | "type": "string" |
| 100 | } |
| 101 | }, |
| 102 | "required": [ |
| 103 | "edits", |
| 104 | "path" |
| 105 | ], |
| 106 | "type": "object" |
| 107 | }, |
| 108 | "allowed_callers": [ |
| 109 | "direct" |
| 110 | ], |
| 111 | "defer_loading": false |
| 112 | }, |
| 113 | { |
| 114 | "name": "get_goal", |
| 115 | "description": "Inspect the current runtime goal state, including objective, status, token budget, elapsed time, evidence, and blocker.", |
| 116 | "input_schema": { |
| 117 | "additionalProperties": false, |
| 118 | "properties": {}, |
| 119 | "type": "object" |
| 120 | }, |
| 121 | "allowed_callers": [ |
| 122 | "direct" |
| 123 | ], |
| 124 | "defer_loading": false |
| 125 | }, |
| 126 | { |
| 127 | "name": "load_skill", |
| 128 | "description": "Load a named skill's SKILL.md body and companion file list into this turn. Use when the user names a skill, or when an entry in the system prompt's `## Skills` index matches the task -- load it before starting the work, not after. Pass query=\"...\" to search names and descriptions, or name=\"list\" for the whole catalogue. Resolves global and plugin skills that `read` cannot reach.", |
| 129 | "input_schema": { |
| 130 | "additionalProperties": false, |
| 131 | "properties": { |
| 132 | "name": { |
| 133 | "description": "Skill id to load. Omit or pass \"list\" to see all available skills.", |
| 134 | "type": "string" |
| 135 | }, |
| 136 | "query": { |
| 137 | "description": "Search term matched against skill names and descriptions. Use when the index was truncated or no name is known.", |
| 138 | "type": "string" |
| 139 | } |
| 140 | }, |
| 141 | "type": "object" |
| 142 | }, |
| 143 | "allowed_callers": [ |
| 144 | "direct" |
| 145 | ], |
| 146 | "defer_loading": false |
| 147 | }, |
| 148 | { |
| 149 | "name": "read", |
| 150 | "description": "Read a text file. The whole file comes back in one call when it fits this call's output budget — 100000 bytes by default, raisable to 500000 with max_bytes. There is no line cap. Use offset and limit for an exact line range; when output is budget-limited the footer names the exact offset to continue from. Every response reports the file's byte size, line count, and whether output was truncated.", |
| 151 | "input_schema": { |
| 152 | "additionalProperties": false, |
| 153 | "properties": { |
| 154 | "limit": { |
| 155 | "description": "Maximum number of lines to read.", |
| 156 | "type": "number" |
| 157 | }, |
| 158 | "max_bytes": { |
| 159 | "description": "Output budget in bytes for this one call. Defaults to 100000; values above the 500000 maximum are clamped down rather than rejected, and a value below the active default leaves the default in place.", |
| 160 | "type": "number" |
| 161 | }, |
| 162 | "offset": { |
| 163 | "description": "Line number to start reading from (1-indexed).", |
| 164 | "type": "number" |
| 165 | }, |
| 166 | "path": { |
| 167 | "description": "Path to the file to read (relative or absolute).", |
| 168 | "type": "string" |
| 169 | } |
| 170 | }, |
| 171 | "required": [ |
| 172 | "path" |
| 173 | ], |
| 174 | "type": "object" |
| 175 | }, |
| 176 | "allowed_callers": [ |
| 177 | "direct" |
| 178 | ], |
| 179 | "defer_loading": false |
| 180 | }, |
| 181 | { |
| 182 | "name": "todo_write", |
| 183 | "description": "Replace the To-do list shown to the user. Optional: use it when a visible plan helps; at most one item may be in_progress at a time.", |
| 184 | "input_schema": { |
| 185 | "properties": { |
| 186 | "todos": { |
| 187 | "description": "The complete list of To-do items. This replaces the existing list.", |
| 188 | "items": { |
| 189 | "properties": { |
| 190 | "content": { |
| 191 | "description": "The task description", |
| 192 | "type": "string" |
| 193 | }, |
| 194 | "status": { |
| 195 | "description": "Task status", |
| 196 | "enum": [ |
| 197 | "pending", |
| 198 | "in_progress", |
| 199 | "completed", |
| 200 | "cancelled" |
| 201 | ], |
| 202 | "type": "string" |
| 203 | } |
| 204 | }, |
| 205 | "required": [ |
| 206 | "content", |
| 207 | "status" |
| 208 | ], |
| 209 | "type": "object" |
| 210 | }, |
| 211 | "type": "array" |
| 212 | } |
| 213 | }, |
| 214 | "required": [ |
| 215 | "todos" |
| 216 | ], |
| 217 | "type": "object" |
| 218 | }, |
| 219 | "allowed_callers": [ |
| 220 | "direct" |
| 221 | ], |
| 222 | "defer_loading": false |
| 223 | }, |
| 224 | { |
| 225 | "name": "update_goal", |
| 226 | "description": "Update the runtime goal completion gate by calling this tool; a prose status in your answer does not change the goal or stop continuation. Critical verification may seal one immutable completion contract. Advisory review is append-only context and never completes, blocks, or pauses the goal. Mark blocked when progress requires user input.", |
| 227 | "input_schema": { |
| 228 | "additionalProperties": false, |
| 229 | "properties": { |
| 230 | "advisory": { |
| 231 | "description": "Required when status is advisory. Appended separately from the judged completion contract.", |
| 232 | "type": "string" |
| 233 | }, |
| 234 | "blocker": { |
| 235 | "description": "Required when status is blocked. Explain the condition preventing progress.", |
| 236 | "type": "string" |
| 237 | }, |
| 238 | "evidence": { |
| 239 | "description": "Required when status is complete. Briefly cite the proof that the goal is done.", |
| 240 | "type": "string" |
| 241 | }, |
| 242 | "progress": { |
| 243 | "additionalProperties": false, |
| 244 | "description": "Optional with not_achieved or advisory: your current best estimate of overall completion, shown to the user as reported progress. Keep percent honest — it is an estimate, never a verified fraction.", |
| 245 | "properties": { |
| 246 | "next": { |
| 247 | "description": "One short line: what comes next.", |
| 248 | "type": "string" |
| 249 | }, |
| 250 | "now": { |
| 251 | "description": "One short line: what is being worked on right now.", |
| 252 | "type": "string" |
| 253 | }, |
| 254 | "percent": { |
| 255 | "description": "Estimated percent complete, 0-100.", |
| 256 | "maximum": 100, |
| 257 | "minimum": 0, |
| 258 | "type": "integer" |
| 259 | } |
| 260 | }, |
| 261 | "required": [ |
| 262 | "percent" |
| 263 | ], |
| 264 | "type": "object" |
| 265 | }, |
| 266 | "status": { |
| 267 | "description": "Use complete only when a critical verifier proves the goal; not_achieved to record verifier gaps; blocked when meaningful progress cannot continue; advisory to append best-effort context without changing lifecycle state.", |
| 268 | "enum": [ |
| 269 | "complete", |
| 270 | "blocked", |
| 271 | "not_achieved", |
| 272 | "advisory" |
| 273 | ], |
| 274 | "type": "string" |
| 275 | }, |
| 276 | "verification": { |
| 277 | "additionalProperties": false, |
| 278 | "description": "Required when status is complete or not_achieved. A verifier-as-judge receipt from a concrete check, such as Run action=\"verifiers\" or an equivalent project-specific gate.", |
| 279 | "properties": { |
| 280 | "check": { |
| 281 | "description": "The verifier/check that passed.", |
| 282 | "type": "string" |
| 283 | }, |
| 284 | "gaps": { |
| 285 | "description": "Concrete remaining gaps. Required for critical not_achieved reviews; order and duplicate wording do not affect the stall fingerprint.", |
| 286 | "items": { |
| 287 | "type": "string" |
| 288 | }, |
| 289 | "type": "array" |
| 290 | }, |
| 291 | "role": { |
| 292 | "description": "Critical reviews may satisfy the judged completion contract. Advisory reviews are fail-open and cannot complete it. Defaults to critical for compatibility.", |
| 293 | "enum": [ |
| 294 | "critical", |
| 295 | "advisory" |
| 296 | ], |
| 297 | "type": "string" |
| 298 | }, |
| 299 | "status": { |
| 300 | "description": "Use passed when a concrete verifier/check succeeded; not_applicable when no automated verifier applies; not_achieved when the verifier found concrete remaining gaps.", |
| 301 | "enum": [ |
| 302 | "passed", |
| 303 | "not_applicable", |
| 304 | "not_achieved" |
| 305 | ], |
| 306 | "type": "string" |
| 307 | }, |
| 308 | "summary": { |
| 309 | "description": "Brief result summary from the verifier/check.", |
| 310 | "type": "string" |
| 311 | } |
| 312 | }, |
| 313 | "required": [ |
| 314 | "check", |
| 315 | "status", |
| 316 | "summary" |
| 317 | ], |
| 318 | "type": "object" |
| 319 | } |
| 320 | }, |
| 321 | "required": [ |
| 322 | "status" |
| 323 | ], |
| 324 | "type": "object" |
| 325 | }, |
| 326 | "allowed_callers": [ |
| 327 | "direct" |
| 328 | ], |
| 329 | "defer_loading": false |
| 330 | }, |
| 331 | { |
| 332 | "name": "write", |
| 333 | "description": "Write content to a file. Creates the file if it does not exist, overwrites it if it does, and creates parent directories automatically.", |
| 334 | "input_schema": { |
| 335 | "additionalProperties": false, |
| 336 | "properties": { |
| 337 | "content": { |
| 338 | "description": "Content to write to the file.", |
| 339 | "type": "string" |
| 340 | }, |
| 341 | "path": { |
| 342 | "description": "Path to the file to write (relative or absolute).", |
| 343 | "type": "string" |
| 344 | } |
| 345 | }, |
| 346 | "required": [ |
| 347 | "content", |
| 348 | "path" |
| 349 | ], |
| 350 | "type": "object" |
| 351 | }, |
| 352 | "allowed_callers": [ |
| 353 | "direct" |
| 354 | ], |
| 355 | "defer_loading": false, |
| 356 | "cache_control": { |
| 357 | "type": "ephemeral" |
| 358 | } |
| 359 | }, |
| 360 | { |
| 361 | "type": "tool_search_20251119", |
| 362 | "name": "tool_search", |
| 363 | "description": "Search deferred tool definitions and return matching tool references.", |
| 364 | "input_schema": { |
| 365 | "type": "object", |
| 366 | "properties": { |
| 367 | "query": { |
| 368 | "type": "string", |
| 369 | "description": "Search query for tool discovery." |
| 370 | }, |
| 371 | "match": { |
| 372 | "type": "string", |
| 373 | "enum": [ |
| 374 | "bm25", |
| 375 | "regex" |
| 376 | ], |
| 377 | "default": "bm25", |
| 378 | "description": "Matching algorithm: bm25 for natural-language matching, regex for a regular expression over tool names/descriptions/schema." |
| 379 | }, |
| 380 | "max_results": { |
| 381 | "type": "integer", |
| 382 | "minimum": 1, |
| 383 | "maximum": 8, |
| 384 | "default": 8, |
| 385 | "description": "Maximum number of matching tool references to return." |
| 386 | } |
| 387 | }, |
| 388 | "required": [ |
| 389 | "query" |
| 390 | ] |
| 391 | }, |
| 392 | "allowed_callers": [ |
| 393 | "direct" |
| 394 | ], |
| 395 | "defer_loading": false |
| 396 | } |
| 397 | ] |
| 398 |