Overview
Tools are IronClaw’s interface to the outside world. They enable the agent to perform actions: call APIs, read files, execute code, search memory, and more. The tool system is designed for security, extensibility, and self-expansion.Tool Types
Built-in Tools
Core tools written in Rust
echo,time,jsonhttp,web_fetchshell,read_file,write_filememory_search,memory_write
WASM Tools
Sandboxed tools in WebAssembly
- User-built tools
- Dynamically created by agent
- Capability-based security
- Hot-reloadable
MCP Servers
Model Context Protocol extensions
- Filesystem access
- Database connections
- External APIs
- Third-party integrations
Tool Trait
All tools implement a common interface:Built-in Tools
Utility Tools
echo - Echo input back
echo - Echo input back
Description: Simple echo for testing and debuggingParameters:Example:
time - Get current time
time - Get current time
Description: Returns current time in various formatsParameters:Example:
json - Parse and manipulate JSON
json - Parse and manipulate JSON
Description: Query, transform, and validate JSON dataParameters:Example:
Network Tools
http - Make HTTP requests
http - Make HTTP requests
Description: Call external APIs with full controlParameters:Credential Injection:
web_fetch - Fetch and convert web pages
web_fetch - Fetch and convert web pages
Description: Fetch URLs and convert HTML to readable markdownParameters:Example:Features:
- HTML to Markdown conversion
- CSS selector filtering
- JavaScript rendering (headless browser)
- Image alt-text extraction
File Tools
read_file - Read file contents
read_file - Read file contents
Description: Read files from the working directoryDomain: Security:
Container (sandboxed environment only)Parameters:- Only available in Docker containers
- Cannot read files outside job workspace
- Path traversal (
../) blocked
write_file - Write file contents
write_file - Write file contents
Description: Create or overwrite filesDomain: Approval: Requires user approval for destructive operations
ContainerParameters:list_dir - List directory contents
list_dir - List directory contents
Description: List files and directoriesDomain:
ContainerParameters:apply_patch - Apply unified diff patch
apply_patch - Apply unified diff patch
Description: Apply code changes via unified diff formatDomain: Example:
ContainerParameters:Memory Tools
memory_search - Hybrid search across workspace
memory_search - Hybrid search across workspace
Description: Full-text + semantic search using Reciprocal Rank FusionParameters:Example:Returns:
memory_write - Write to workspace
memory_write - Write to workspace
Description: Create or update workspace filesParameters:Automatic Indexing: Written content is automatically:
- Chunked (500 char chunks with 50 char overlap)
- Embedded (vector embeddings for semantic search)
- Indexed (BM25 for full-text search)
memory_read - Read workspace file
memory_read - Read workspace file
Description: Read a specific workspace file by pathParameters:
memory_tree - Browse workspace structure
memory_tree - Browse workspace structure
Description: List workspace files and directoriesParameters:
WASM Sandbox
Untrusted tools run in isolated WebAssembly containers.Architecture
Capability System
WASM tools start with zero capabilities:Security Boundaries
- Fuel Metering
- Memory Limits
- Network Isolation
- Credential Injection
Threat: Infinite loops, CPU exhaustionProtection:Behavior:
- Fuel consumed per WASM instruction
- Automatic termination when fuel exhausted
- Per-execution timeout (30s default)
Host Functions
WASM tools can call host-provided functions:Building WASM Tools
1
Create Rust Project
2
Add Dependencies
3
Implement Tool
4
Build WASM Module
5
Register with IronClaw
Dynamic Tool Building
IronClaw can build new tools on the fly.Build Software Tool
Build Process
Iterative Refinement
The builder uses an iterative loop:- Plan: Break down requirements into steps
- Generate: Write code using LLM
- Compile: Build in Docker sandbox
- Test: Run test cases
- Fix: If tests fail, analyze errors and regenerate
- Validate: Ensure schema matches
- Register: Add to tool registry
The builder can iterate up to 10 times to fix compilation errors and test failures.
MCP Protocol
Model Context Protocol servers provide additional capabilities.MCP Architecture
MCP Server Configuration
MCP Tool Wrapping
MCP server tools are automatically wrapped as IronClaw tools:Tool Registry
Central registry managing all available tools.Protected Tool Names
Core tools cannot be shadowed:Tool Discovery
Rate Limiting
Per-tool rate limits prevent abuse:Approval System
Sensitive operations require user approval:- Tool execution requested
- Check
requires_approval(params) - If required, send
StatusUpdate::ApprovalNeeded - Wait for user response
- Execute if approved, skip if denied
Next Steps
WASM Sandbox
Deep dive into WASM security and capabilities
MCP Integration
Connect Model Context Protocol servers
Building Tools
Create custom tools dynamically
Tool Examples
Real-world tool implementations