Architecture
The tool system is built on three pillars:Tool Trait
All tools implement theTool trait defined in src/tools/tool.rs:
src/tools/tool.rs:178-266
Tool Domains
Tools are separated by execution domain for security:
Location:
src/tools/tool.rs:64-74
Orchestrator tools run in the main agent process and have no filesystem access. Container tools run inside Docker containers with isolated filesystems.
Tool Registry
TheToolRegistry manages all available tools and provides registration methods for different tool types.
Location: src/tools/registry.rs:74-87
Registration Methods
- Built-in:
src/tools/registry.rs:210-224 - Container:
src/tools/registry.rs:236-242 - Memory:
src/tools/registry.rs:274-285 - WASM:
src/tools/registry.rs:470-539
Protected Tool Names
Certain built-in tools cannot be shadowed by dynamic registrations to prevent security bypasses:src/tools/registry.rs:36-72
Approval Requirements
Tools can specify when they need user approval:src/tools/tool.rs:13-21
Example from ShellTool:
Rate Limiting
Tools can specify per-user rate limits:src/tools/tool.rs:31-62
Read-only tools (echo, time, json, file_read) return None for rate limits. Write/external tools (shell, http, file_write) return sensible limits.
Tool Output
Tools return structured output with metadata:src/tools/tool.rs:101-147
Schema Validation
All tool parameter schemas are validated at registration time:src/tools/tool.rs:314-378
Rules enforced:
- Top-level must have
"type": "object" - Top-level must have
"properties"as an object - Every key in
"required"must exist in"properties" - Nested objects follow the same rules recursively
- Array properties should have
"items"defined
"type" field are allowed (freeform/any-type), used by tools like json and http for OpenAI compatibility.
Extension Points
The tool system provides multiple extension points:1. Built-in Tools (Rust)
Create new Rust tools by implementing theTool trait.
See: Built-in Tools Reference
2. WASM Tools (Sandboxed)
Build sandboxed tools in Rust that compile to WebAssembly. See: WASM Tool System3. MCP Servers (External)
Connect to external tool servers using the Model Context Protocol. See: MCP Integration4. Software Builder (LLM-driven)
Use thebuild_software tool to create new tools using AI.
See: Building Custom Tools
Next Steps
Built-in Tools
Explore the complete reference of built-in tools
WASM Tools
Learn about the sandboxed WASM tool system
MCP Integration
Connect external tool servers via MCP
Build Tools
Create custom tools using the builder