Skip to content

Standard toolkit

Source: harness/docs/canon/standard-toolkit.md Status: Current source; staged verbatim for ingestion.

Always-on FS stdlib for model-callable work — one toolkit pack, one path membrane. Observe-search (glob, fff_search, grep) is one FileFinder index; read/list/mutate stay the JS path membrane. Not a per-tool package graph, not app slash commands, not inference drivers, not MCP packs.

Canon siblings: grain.md · proposals.md


Tool Class Obligation
read_file read UTF-8 file under project root
list_dir read Directory listing under project root
grep read Indexed content search (plain / regex / fuzzy) under project root
glob read Exact glob enumeration under project root (same index as grep/fff_search)
fff_search read Fuzzy filename search under project root (same index)
write_file write Create, or replace contents in place (O_TRUNC, same inode). Existing path requires overwriteExisting; omit/false is a door that names the flag. Host stores prior UTF-8 text on FileMutateToolJob.priorContent (null if binary, too large, or missing) for the tape Diff. Tape/cover: create vs update from admit existed. existed / priorContent are host-injected, not model arguments
edit_file write Exact-string replace

Laws of the set

  • Paths resolve under the session workspace root (lexical + realpath containment). glob / fff_search take cwd (directory under that root; default the project). An absolute path under the project is the project.
  • write / effect do not freestyle past approval: write_file / edit_file admit as FileMutateToolJob (is-a SystemToolJob); other native mutators admit as SystemToolJob (ToolCallJob is-a ApprovableJob). Sole home: ../runtime/approval.md. Catalog class is read | write | effect | meta.
  • Denial is a sealed tool outcome the model can read — not a transport failure.
  • glob enumerates exact path patterns. fff_search is fuzzy name-search. grep’s glob argument only constrains which files content-search opens.
  • glob / fff_search / grep share one FileFinder per workspace root. They are not a second JS walker.
  • No shell / process spawn in this set. shell is a separately registered host tool (effect).

Explicit non-members

Surface Where it lives instead
Bash / run / process Host-registered shell — ordinary catalog row; permission is not workspace auto
Web search Host-registered web_search (effect) — intern PEW on a web-search connection; not FS
Web extract Host-registered web_extract (effect) — intern PEW on a web-extract connection; not FS. Pin KV web-extract-connection is independent of search.
Session-list label Host-registered update_metadata (meta) — side-channel; not FS, not approval, not ReACT-alone
Context expectation Host-registered context_need (meta) — side-channel; operands only; host owns compact
MCP / third-party tools Catalog expand(connection) and optional packs
Slash / internal commands Named actions via the action door — shell builtins, not model tools
Autonomous bot-call tools Pack JSON tools (memory providers and others); not Scheme symbols, not FS

Catalog fact, not a vault essay. Completion tools[] is a projection of the catalog (registered ∪ expand(connection)), not the catalog.

JSON tools[]: prior verbs (write_file edit_file shell) + scheme_repl scheme_watch + side-channel update_metadata context_need + pack bot-call tools.

Scheme symbols, not JSON tools[]: read_file, observe-search (list_dir grep glob fff_search), web_search web_extract, MCP (mcp/call), packs (each pack tool is its own symbol), agent comms (agent/send agent/ask agent/one-shot/send agent/one-shot/ask agent/respond agent/void agent/notify agent/message). scheme_repl function.description is a live catalog (bound signatures + derived slugs) projected at list/snapshot time. Host memory tools (tingle / offload) are autonomous bot-call JSON tools, not symbols, and not named-bot wrappers.

scheme_repl is a catalog projection. Admit mints a bare ProgrammaticJob (orchestration, not PEW, not Approvable). CLI eval mints that same bag on the turn queue. Inner invocations reuse the admit door as ordinary ToolCallJobs. The bag is not remainder; inner leaves still license (../runtime/approval.md).

  • agent/send / agent/ask / agent/one-shot/send / agent/one-shot/ask admit AgentCallJob (is-a ToolCallJob). Spec is a recipe name, not a per-bot catalog wire. Kernel broadcasts the message onto the worker session queue and registers the callback. Send: voidLegal true (void or respond settles). Ask: stamps voidLegal false — respond required. Bare send/ask reuse the generator. agent/one-shot/send and agent/one-shot/ask mint AskAgentSpec stamped with the recipe (no roster, dies). Omitted-spec ask mints one-shot AskAgentSpec (class, not a nature, not a catalog recipe).
  • period is the same bag’s clock (re-invoke expr; not a sibling Job): "N minutes" / "N hours" / "N days". expr must call reachable (meta-reactivity/done-condition …). Idle wait is not on the per-tick timeout or inner-call ceiling.
  • background (mint arg or later Job write) releases ReACT join once the bag is orchestrated.
  • self/notify is an origin atom (does not settle). Bag-home recall only when background; a sitter writes the enclosing Call.

Tool-calls are ToolCallJob (is-a ApprovableJob). Policy always runs. A human may write approved. The leaf execute runs BODY after an allow-side guard. The Actor does not consider UAC. Sole home: ../runtime/approval.md.


Doc Link
Grain grain.md
Crossings on PEW/Work proposals.md
Approval ../runtime/approval.md
Session product kinds ../packages/harness-sdk/src/models/session/
Toolkit ../packages/harness-server/src/toolkit/