Skip to main content

Overview

Tools are IronClaw’s interface to the outside world. They enable the agent to perform actions: call APIs, read files, execute code, search memory, and more. The tool system is designed for security, extensibility, and self-expansion.

Tool Types

Built-in Tools

Core tools written in Rust
  • echo, time, json
  • http, web_fetch
  • shell, read_file, write_file
  • memory_search, memory_write

WASM Tools

Sandboxed tools in WebAssembly
  • User-built tools
  • Dynamically created by agent
  • Capability-based security
  • Hot-reloadable

MCP Servers

Model Context Protocol extensions
  • Filesystem access
  • Database connections
  • External APIs
  • Third-party integrations

Tool Trait

All tools implement a common interface:

Built-in Tools

Utility Tools

Description: Simple echo for testing and debuggingParameters:
Example:
Description: Returns current time in various formatsParameters:
Example:
Description: Query, transform, and validate JSON dataParameters:
Example:

Network Tools

Description: Call external APIs with full controlParameters:
Credential Injection:
The tool requests a credential by name, but never sees the actual value. The orchestrator injects it at the HTTP boundary.
Description: Fetch URLs and convert HTML to readable markdownParameters:
Example:
Features:
  • HTML to Markdown conversion
  • CSS selector filtering
  • JavaScript rendering (headless browser)
  • Image alt-text extraction

File Tools

Description: Read files from the working directoryDomain: Container (sandboxed environment only)Parameters:
Security:
  • Only available in Docker containers
  • Cannot read files outside job workspace
  • Path traversal (../) blocked
Description: Create or overwrite filesDomain: ContainerParameters:
Approval: Requires user approval for destructive operations
Description: List files and directoriesDomain: ContainerParameters:
Description: Apply code changes via unified diff formatDomain: ContainerParameters:
Example:

Memory Tools

Description: Full-text + semantic search using Reciprocal Rank FusionParameters:
Example:
Returns:
Description: Create or update workspace filesParameters:
Automatic Indexing: Written content is automatically:
  • Chunked (500 char chunks with 50 char overlap)
  • Embedded (vector embeddings for semantic search)
  • Indexed (BM25 for full-text search)
Description: Read a specific workspace file by pathParameters:
Description: List workspace files and directoriesParameters:

WASM Sandbox

Untrusted tools run in isolated WebAssembly containers.

Architecture

Capability System

WASM tools start with zero capabilities:

Security Boundaries

Threat: Infinite loops, CPU exhaustionProtection:
Behavior:
  • Fuel consumed per WASM instruction
  • Automatic termination when fuel exhausted
  • Per-execution timeout (30s default)

Host Functions

WASM tools can call host-provided functions:

Building WASM Tools

1

Create Rust Project

2

Add Dependencies

3

Implement Tool

4

Build WASM Module

5

Register with IronClaw

Use the build_software tool to have IronClaw build WASM tools for you automatically.

Dynamic Tool Building

IronClaw can build new tools on the fly.

Build Software Tool

Build Process

Iterative Refinement

The builder uses an iterative loop:
  1. Plan: Break down requirements into steps
  2. Generate: Write code using LLM
  3. Compile: Build in Docker sandbox
  4. Test: Run test cases
  5. Fix: If tests fail, analyze errors and regenerate
  6. Validate: Ensure schema matches
  7. Register: Add to tool registry
The builder can iterate up to 10 times to fix compilation errors and test failures.

MCP Protocol

Model Context Protocol servers provide additional capabilities.

MCP Architecture

MCP Server Configuration

MCP Tool Wrapping

MCP server tools are automatically wrapped as IronClaw tools:
MCP servers run as untrusted processes. Do not grant them access to sensitive credentials.

Tool Registry

Central registry managing all available tools.

Protected Tool Names

Core tools cannot be shadowed:
Dynamically registered tools (WASM, MCP) cannot override protected names. This prevents malicious tools from replacing security-critical operations.

Tool Discovery

Rate Limiting

Per-tool rate limits prevent abuse:

Approval System

Sensitive operations require user approval:
Example: Conditional Approval
Approval Flow:
  1. Tool execution requested
  2. Check requires_approval(params)
  3. If required, send StatusUpdate::ApprovalNeeded
  4. Wait for user response
  5. Execute if approved, skip if denied

Next Steps

WASM Sandbox

Deep dive into WASM security and capabilities

MCP Integration

Connect Model Context Protocol servers

Building Tools

Create custom tools dynamically

Tool Examples

Real-world tool implementations