src/tools/wasm/
Architecture
- Compile once, instantiate fresh: Tools are validated and compiled at registration time. Each execution creates a fresh instance (NEAR pattern).
- Fuel metering: CPU usage is limited via Wasmtime’s fuel system.
- Memory limits: Memory growth is bounded via ResourceLimiter (default 10MB).
- Capability-based security: Features are opt-in via Capabilities.
- Credential isolation: Tools never see raw credentials, only placeholder names.
src/tools/wasm/mod.rs:1-75
Security Constraints
Location:
src/tools/wasm/mod.rs:32-50
WIT Interface
WASM tools implement thesandboxed-tool world defined in wit/tool.wit:
wit/tool.wit
Capabilities System
Capabilities define what a WASM tool is allowed to do. They are declared in a<tool-name>.capabilities.json file.
Location: src/tools/wasm/capabilities.rs
HTTP Capability
github-tool.capabilities.json):
src/tools/wasm/capabilities_schema.rs:28-80
Workspace Capability
Secrets Capability
Tool Invoke Capability
Resource Limits
src/tools/wasm/limits.rs:10-42
Constants:
src/tools/wasm/limits.rs:7-9
Credential Injection
WASM tools never see raw credentials. The host injects them at request time. Location:src/tools/wasm/credential_injector.rs
Credential Mapping
src/tools/wasm/credential_injector.rs:28-150
Placeholder Substitution
Tools can reference credentials by placeholder in URLs and headers:src/tools/wasm/wrapper.rs:129-145
Leak Detection
All WASM tool outputs are scanned for credential leakage:src/tools/wasm/wrapper.rs:300-320
Secrets are replaced with [REDACTED:SECRET_NAME] before returning to the LLM.
Building a WASM Tool
1. Create Project
2. Configure Cargo.toml
3. Implement Tool
4. Create Capabilities File
my-tool.capabilities.json:
5. Build
target/wasm32-wasip2/release/my_tool.wasm
6. Install
Runtime APIs
WasmToolRuntime
Location:src/tools/wasm/runtime.rs
src/tools/wasm/runtime.rs:52-150
WasmToolWrapper
Location:src/tools/wasm/wrapper.rs
src/tools/wasm/wrapper.rs:67-98
Storage
WASM tools can be stored in a database with integrity verification. Location:src/tools/wasm/storage.rs
Store Tool
Load Tool
- BLAKE3 hash computed on store
- Hash verified on load
- Prevents WASM tampering
src/tools/wasm/storage.rs:120-280
Tool Discovery
Discover WASM tools in thetools-src/ directory:
Location: src/tools/wasm/loader.rs
src/tools/wasm/loader.rs:28-150
OAuth Authentication
WASM tools can declare OAuth requirements in capabilities:- Check
env_var- if set in environment, use it directly - Check
oauth- if configured, open browser for OAuth flow - Fall back to
instructions+ manual token entry
src/tools/README.md:49-103
Examples
Real-world WASM tools intools-src/:
- GitHub (
tools-src/github/) - Repository management, issues, PRs, workflows - Gmail (
tools-src/gmail/) - Search, read, send emails - Slack (
tools-src/slack/) - Post messages, read channels - Telegram (
tools-src/telegram/) - Send messages, manage conversations - Google Calendar (
tools-src/google-calendar/) - Manage events - Google Drive (
tools-src/google-drive/) - File management - Google Sheets (
tools-src/google-sheets/) - Spreadsheet operations - Google Docs (
tools-src/google-docs/) - Document editing
Best Practices
- Minimize allowlist scope: Only allow the specific hosts/paths your tool needs
- Use credential injection: Never hardcode secrets
- Validate inputs: Check parameter lengths and formats
- Handle errors gracefully: Return descriptive error messages
- Log appropriately: Use host
log()for debugging - Optimize binary size: Use
opt-level = "z"andstrip = true - Test thoroughly: Test with and without credentials
- Document schema: Provide clear descriptions for all parameters
Next Steps
MCP Integration
Learn about MCP server integration
Building Tools
Use the software builder to create tools