Tools
Built-in Tools
The file and shell tools every agent gets, where they run, and how to limit them.
With a sandbox, an agent gets seven built-in tools that run in the sandbox, not on your worker.
| Tool | What it does |
|---|---|
read, write, edit | Read, create, and change files. |
grep, find, ls | Search files and list directories. |
bash | Run a shell command. |
import { pi } from "@rivet-dev/pi";
import { agentOSProvider } from "@rivet-dev/sandbox-adapter/agentos";
import { setup } from "rivetkit";
const reviewer = pi({
model: "anthropic/claude-opus-5-5",
sandbox: agentOSProvider(),
excludeTools: ["bash", "edit", "write"],
});
export const registry = setup({ use: { reviewer } });
import { createClient } from "rivetkit/client";
import type { registry } from "./server";
const client = createClient<typeof registry>();
const reviewer = client.reviewer.getOrCreate(["pr-123"]);
const checkout = await reviewer.executeBash(
"git clone https://github.com/acme/app . && git checkout pr-123",
{ excludeFromContext: true },
);
if (checkout.exitCode !== 0) throw new Error(checkout.output);
await reviewer.prompt("Review the changes on this branch.");
console.log(await reviewer.getLastAssistantText());
excludeToolsturns tools off by name, so this reviewer can read and search files but can’t run commands or change them.toolsdoes the opposite and enables only the tools you list.executeBashruns a command in the agent’s sandbox from your backend, without the model. It works even though the reviewer can’t runbashitself.excludeFromContextkeeps the output out of the conversation.- File tools only reach paths inside the sandbox’s working directory.
bashaccepts a timeout, and long output is truncated before it reaches the model. - Without a sandbox, the agent has no built-in tools. See Sandboxes.
To give an agent your own tools, see Custom Tools.