Tools and permissions
The model selects from advertised tools. The runtime owns registration, validation, execution, and the results returned to the model.
One capability boundary
Each handler supplies its specification. The finalized router advertises and dispatches the same capabilities; a model-supplied name cannot enable an unregistered tool. Calls execute sequentially after response validation.
Most calls use JSON function arguments. apply_patch carries raw patch text.
The router preserves their payload kinds and call IDs in retained history.
Permission modes
Main and workers retain configured permissions. Role guidance directs how they coordinate. Child agents inherit effective permissions and model settings; Echo makes no model requests and executes no tools.
File tools enforce workspace path boundaries. Full mode executes unsandboxed host shell commands without per-call approval. A failed tool can leave effects already applied, so errors and prior results remain visible to later steps.
Coordination tools manage conversations and delivery. Hosted web search is executed by the provider inside the model request.
Implementation: tools/.