Skip to main content
IronClaw’s WASM tool system allows you to build custom tools in Rust that compile to WebAssembly and run in a sandboxed environment with strict security controls. Location: src/tools/wasm/

Architecture

Key principles:
  • Compile once, instantiate fresh: Tools are validated and compiled at registration time. Each execution creates a fresh instance (NEAR pattern).
  • Fuel metering: CPU usage is limited via Wasmtime’s fuel system.
  • Memory limits: Memory growth is bounded via ResourceLimiter (default 10MB).
  • Capability-based security: Features are opt-in via Capabilities.
  • Credential isolation: Tools never see raw credentials, only placeholder names.
Location: src/tools/wasm/mod.rs:1-75

Security Constraints

Location: src/tools/wasm/mod.rs:32-50

WIT Interface

WASM tools implement the sandboxed-tool world defined in wit/tool.wit:
Location: wit/tool.wit

Capabilities System

Capabilities define what a WASM tool is allowed to do. They are declared in a <tool-name>.capabilities.json file. Location: src/tools/wasm/capabilities.rs

HTTP Capability

Example (github-tool.capabilities.json):
Location: src/tools/wasm/capabilities_schema.rs:28-80

Workspace Capability

Example:

Secrets Capability

Example:

Tool Invoke Capability

Example:

Resource Limits

Location: src/tools/wasm/limits.rs:10-42 Constants:
Location: src/tools/wasm/limits.rs:7-9

Credential Injection

WASM tools never see raw credentials. The host injects them at request time. Location: src/tools/wasm/credential_injector.rs

Credential Mapping

Example injection locations:
Location: src/tools/wasm/credential_injector.rs:28-150

Placeholder Substitution

Tools can reference credentials by placeholder in URLs and headers:
Location: src/tools/wasm/wrapper.rs:129-145

Leak Detection

All WASM tool outputs are scanned for credential leakage:
Location: src/tools/wasm/wrapper.rs:300-320 Secrets are replaced with [REDACTED:SECRET_NAME] before returning to the LLM.

Building a WASM Tool

1. Create Project

2. Configure Cargo.toml

3. Implement Tool

4. Create Capabilities File

my-tool.capabilities.json:

5. Build

Output: target/wasm32-wasip2/release/my_tool.wasm

6. Install

Runtime APIs

WasmToolRuntime

Location: src/tools/wasm/runtime.rs
Location: src/tools/wasm/runtime.rs:52-150

WasmToolWrapper

Location: src/tools/wasm/wrapper.rs
Location: src/tools/wasm/wrapper.rs:67-98

Storage

WASM tools can be stored in a database with integrity verification. Location: src/tools/wasm/storage.rs

Store Tool

Load Tool

Integrity verification:
  • BLAKE3 hash computed on store
  • Hash verified on load
  • Prevents WASM tampering
Location: src/tools/wasm/storage.rs:120-280

Tool Discovery

Discover WASM tools in the tools-src/ directory: Location: src/tools/wasm/loader.rs
Example:
Location: src/tools/wasm/loader.rs:28-150

OAuth Authentication

WASM tools can declare OAuth requirements in capabilities:
Auth flow priority:
  1. Check env_var - if set in environment, use it directly
  2. Check oauth - if configured, open browser for OAuth flow
  3. Fall back to instructions + manual token entry
Location: See src/tools/README.md:49-103

Examples

Real-world WASM tools in tools-src/:
  • GitHub (tools-src/github/) - Repository management, issues, PRs, workflows
  • Gmail (tools-src/gmail/) - Search, read, send emails
  • Slack (tools-src/slack/) - Post messages, read channels
  • Telegram (tools-src/telegram/) - Send messages, manage conversations
  • Google Calendar (tools-src/google-calendar/) - Manage events
  • Google Drive (tools-src/google-drive/) - File management
  • Google Sheets (tools-src/google-sheets/) - Spreadsheet operations
  • Google Docs (tools-src/google-docs/) - Document editing

Best Practices

  1. Minimize allowlist scope: Only allow the specific hosts/paths your tool needs
  2. Use credential injection: Never hardcode secrets
  3. Validate inputs: Check parameter lengths and formats
  4. Handle errors gracefully: Return descriptive error messages
  5. Log appropriately: Use host log() for debugging
  6. Optimize binary size: Use opt-level = "z" and strip = true
  7. Test thoroughly: Test with and without credentials
  8. Document schema: Provide clear descriptions for all parameters

Next Steps

MCP Integration

Learn about MCP server integration

Building Tools

Use the software builder to create tools