Skip to content
M31A

28 Core Tools Catalog

Typed tool execution lifecycle, risk classes, and parameter schemas.


M31A provides 28 core typed tools across 15 capability families. Every tool defines strict JSON schemas generated by schemars.

Tool Execution Lifecycle

1. Schema Validation → Validate parameters against JSON schema contract
2. Policy Evaluation → 11-stage policy gate evaluation (ALLOW/DENY/ASK)
3. Budget Pre-Allocation → Two-phase reservation of tokens and memory
4. OS Confinement → Execution in cgroups v2, POSIX rlimits, clean env
5. Output Redaction → SecretRedactor scrubs API keys before persistence

Catalog of 28 Core Tools

Tool NameCategoryRisk ClassDescription
read_fileFilesystemReadOnlyReads file content within workspace root with optional byte pagination.
write_fileFilesystemWorkspaceMutationOverwrites or creates a new file at specified workspace path.
edit_fileFilesystemWorkspaceMutationApplies targeted line/range substitutions to an existing file.
apply_patchFilesystemWorkspaceMutationApplies a unified diff patch (git diff format) to workspace files.
list_filesFilesystemReadOnlyLists entries in workspace directory with size and type attributes.
globFilesystemReadOnlyFinds workspace files matching a glob pattern (e.g. src/**/*.rs).
grepFilesystemReadOnlySearches file contents using regular expressions or literal strings.
repo_searchRepositoryReadOnlyPerforms semantic or symbol-based search across repository codebase indexes.
repo_symbolsRepositoryReadOnlyExtracts AST definitions, functions, structs, traits, and enums from a file.
repo_dependenciesRepositoryReadOnlyAnalyzes package dependencies from Cargo.toml or package manifests.
run_commandProcessHighRiskMutationSpawns a synchronous child process under POSIX rlimits and cgroups confinement.
start_jobProcessHighRiskMutationLaunches an asynchronous background job with streaming spool output.
job_statusProcessReadOnlyInspects current status (Running, Completed, Failed) of a background job.
job_outputProcessReadOnlyReads streaming stdout/stderr output from a running or completed job.
job_stopProcessHighRiskMutationSends SIGTERM / SIGKILL to a background job process tree.
git_statusGitReadOnlyReturns clean/dirty state, staged changes, and untracked files.
git_diffGitReadOnlyComputes unified diff of working tree changes or specific commits.
git_logGitReadOnlyRetrieves commit history with hashes, author info, and trailer blocks.
git_showGitReadOnlyShows detailed commit metadata, commit message, and full patch diff.
git_branchGitWorkspaceMutationLists, creates, or switches branches within the local repository.
git_checkoutGitWorkspaceMutationChecks out a branch or reverts specified files to HEAD revision.
git_addGitWorkspaceMutationStages specified file modifications or untracked files for commit.
git_commitGitWorkspaceMutationCreates a new Git commit with RFC-compliant M31A attribution trailers.
run_testsVerificationHighRiskMutationExecutes project test suites (cargo test, etc.) and parses structured test results.
run_formatterVerificationWorkspaceMutationRuns code formatting (cargo fmt, etc.) in check or modification mode.
run_linterVerificationHighRiskMutationExecutes static analysis and linter suites (cargo clippy, etc.).
create_artifactArtifactsWorkspaceMutationStores an immutable content-addressed artifact with streaming quota checks.
read_artifactArtifactsReadOnlyRetrieves content and metadata of a previously stored artifact by ID.

Canonical Tool Error Taxonomy

Tools return strongly typed errors categorized into standard classifications: Validation, ResourceNotFound, PreconditionFailed, PermissionDenied, ExecutionFailed, ResourceExhausted, and CapabilityUnavailable.