Skip to main content
IronClaw provides a powerful, security-first tool system that allows agents to interact with external services, execute code, manage data, and extend their capabilities through custom tools.

Architecture

The tool system is built on three pillars:

Tool Trait

All tools implement the Tool trait defined in src/tools/tool.rs:
Location: src/tools/tool.rs:178-266

Tool Domains

Tools are separated by execution domain for security: Location: src/tools/tool.rs:64-74 Orchestrator tools run in the main agent process and have no filesystem access. Container tools run inside Docker containers with isolated filesystems.

Tool Registry

The ToolRegistry manages all available tools and provides registration methods for different tool types. Location: src/tools/registry.rs:74-87

Registration Methods

Locations:
  • Built-in: src/tools/registry.rs:210-224
  • Container: src/tools/registry.rs:236-242
  • Memory: src/tools/registry.rs:274-285
  • WASM: src/tools/registry.rs:470-539

Protected Tool Names

Certain built-in tools cannot be shadowed by dynamic registrations to prevent security bypasses:
Location: src/tools/registry.rs:36-72

Approval Requirements

Tools can specify when they need user approval:
Location: src/tools/tool.rs:13-21 Example from ShellTool:

Rate Limiting

Tools can specify per-user rate limits:
Location: src/tools/tool.rs:31-62 Read-only tools (echo, time, json, file_read) return None for rate limits. Write/external tools (shell, http, file_write) return sensible limits.

Tool Output

Tools return structured output with metadata:
Location: src/tools/tool.rs:101-147

Schema Validation

All tool parameter schemas are validated at registration time:
Location: src/tools/tool.rs:314-378 Rules enforced:
  1. Top-level must have "type": "object"
  2. Top-level must have "properties" as an object
  3. Every key in "required" must exist in "properties"
  4. Nested objects follow the same rules recursively
  5. Array properties should have "items" defined
Properties without a "type" field are allowed (freeform/any-type), used by tools like json and http for OpenAI compatibility.

Extension Points

The tool system provides multiple extension points:

1. Built-in Tools (Rust)

Create new Rust tools by implementing the Tool trait. See: Built-in Tools Reference

2. WASM Tools (Sandboxed)

Build sandboxed tools in Rust that compile to WebAssembly. See: WASM Tool System

3. MCP Servers (External)

Connect to external tool servers using the Model Context Protocol. See: MCP Integration

4. Software Builder (LLM-driven)

Use the build_software tool to create new tools using AI. See: Building Custom Tools

Next Steps

Built-in Tools

Explore the complete reference of built-in tools

WASM Tools

Learn about the sandboxed WASM tool system

MCP Integration

Connect external tool servers via MCP

Build Tools

Create custom tools using the builder