Standard toolkit
Source:
harness/docs/canon/standard-toolkit.mdStatus: Current source; staged verbatim for ingestion.
Standard toolkit
Section titled “Standard toolkit”Always-on FS stdlib for model-callable work — one toolkit pack, one path membrane. Observe-search (glob, fff_search, grep) is one FileFinder index; read/list/mutate stay the JS path membrane. Not a per-tool package graph, not app slash commands, not inference drivers, not MCP packs.
Canon siblings: grain.md · proposals.md
Membership
Section titled “Membership”| Tool | Class | Obligation |
|---|---|---|
read_file |
read | UTF-8 file under project root |
list_dir |
read | Directory listing under project root |
grep |
read | Indexed content search (plain / regex / fuzzy) under project root |
glob |
read | Exact glob enumeration under project root (same index as grep/fff_search) |
fff_search |
read | Fuzzy filename search under project root (same index) |
write_file |
write | Create, or replace contents in place (O_TRUNC, same inode). Existing path requires overwriteExisting; omit/false is a door that names the flag. Host stores prior UTF-8 text on FileMutateToolJob.priorContent (null if binary, too large, or missing) for the tape Diff. Tape/cover: create vs update from admit existed. existed / priorContent are host-injected, not model arguments |
edit_file |
write | Exact-string replace |
Laws of the set
- Paths resolve under the session workspace root (lexical + realpath containment).
glob/fff_searchtakecwd(directory under that root; default the project). An absolute path under the project is the project. write/effectdo not freestyle past approval:write_file/edit_fileadmit asFileMutateToolJob(is-aSystemToolJob); other native mutators admit asSystemToolJob(ToolCallJobis-aApprovableJob). Sole home:../runtime/approval.md. Catalog class isread|write|effect|meta.- Denial is a sealed tool outcome the model can read — not a transport failure.
globenumerates exact path patterns.fff_searchis fuzzy name-search.grep’sglobargument only constrains which files content-search opens.- glob / fff_search / grep share one FileFinder per workspace root. They are not a second JS walker.
- No shell / process spawn in this set.
shellis a separately registered host tool (effect).
Explicit non-members
| Surface | Where it lives instead |
|---|---|
Bash / run / process |
Host-registered shell — ordinary catalog row; permission is not workspace auto |
| Web search | Host-registered web_search (effect) — intern PEW on a web-search connection; not FS |
| Web extract | Host-registered web_extract (effect) — intern PEW on a web-extract connection; not FS. Pin KV web-extract-connection is independent of search. |
| Session-list label | Host-registered update_metadata (meta) — side-channel; not FS, not approval, not ReACT-alone |
| Context expectation | Host-registered context_need (meta) — side-channel; operands only; host owns compact |
| MCP / third-party tools | Catalog expand(connection) and optional packs |
| Slash / internal commands | Named actions via the action door — shell builtins, not model tools |
| Autonomous bot-call tools | Pack JSON tools (memory providers and others); not Scheme symbols, not FS |
Scheme mixer
Section titled “Scheme mixer”Catalog fact, not a vault essay. Completion tools[] is a projection of the catalog (registered ∪ expand(connection)), not the catalog.
JSON tools[]: prior verbs (write_file edit_file shell) + scheme_repl scheme_watch + side-channel update_metadata context_need + pack bot-call tools.
Scheme symbols, not JSON tools[]: read_file, observe-search (list_dir grep glob fff_search), web_search web_extract, MCP (mcp/call), packs (each pack tool is its own symbol), agent comms (agent/send agent/ask agent/one-shot/send agent/one-shot/ask agent/respond agent/void agent/notify agent/message). scheme_repl function.description is a live catalog (bound signatures + derived slugs) projected at list/snapshot time. Host memory tools (tingle / offload) are autonomous bot-call JSON tools, not symbols, and not named-bot wrappers.
scheme_repl is a catalog projection. Admit mints a bare ProgrammaticJob (orchestration, not PEW, not Approvable). CLI eval mints that same bag on the turn queue. Inner invocations reuse the admit door as ordinary ToolCallJobs. The bag is not remainder; inner leaves still license (../runtime/approval.md).
agent/send/agent/ask/agent/one-shot/send/agent/one-shot/askadmitAgentCallJob(is-aToolCallJob). Spec is a recipe name, not a per-bot catalog wire. Kernel broadcasts the message onto the worker session queue and registers the callback. Send:voidLegaltrue (void or respond settles). Ask: stampsvoidLegalfalse — respond required. Bare send/ask reuse the generator.agent/one-shot/sendandagent/one-shot/askmintAskAgentSpecstamped with the recipe (no roster, dies). Omitted-spec ask mints one-shotAskAgentSpec(class, not a nature, not a catalog recipe).periodis the same bag’s clock (re-invokeexpr; not a sibling Job):"N minutes"/"N hours"/"N days". expr must call reachable(meta-reactivity/done-condition …). Idle wait is not on the per-tick timeout or inner-call ceiling.background(mint arg or later Job write) releases ReACT join once the bag is orchestrated.self/notifyis an origin atom (does not settle). Bag-home recall only when background; a sitter writes the enclosing Call.
Mutator Permission
Section titled “Mutator Permission”Tool-calls are ToolCallJob (is-a ApprovableJob). Policy always runs. A human may write approved. The leaf execute runs BODY after an allow-side guard. The Actor does not consider UAC. Sole home: ../runtime/approval.md.
Related
Section titled “Related”| Doc | Link |
|---|---|
| Grain | grain.md |
| Crossings on PEW/Work | proposals.md |
| Approval | ../runtime/approval.md |
| Session product kinds | ../packages/harness-sdk/src/models/session/ |
| Toolkit | ../packages/harness-server/src/toolkit/ |