Skip to main content
Tools

Built-in Tools

The file and shell tools every agent gets, where they run, and how to limit them.

With a sandbox, an agent gets seven built-in tools that run in the sandbox, not on your worker.

ToolWhat it does
read, write, editRead, create, and change files.
grep, find, lsSearch files and list directories.
bashRun a shell command.
client.tsReviewer agentSandboxexecuteBashread, grep, find, lsbash, edit, write excluded
  • excludeTools turns tools off by name, so this reviewer can read and search files but can’t run commands or change them. tools does the opposite and enables only the tools you list.
  • executeBash runs a command in the agent’s sandbox from your backend, without the model. It works even though the reviewer can’t run bash itself. excludeFromContext keeps the output out of the conversation.
  • File tools only reach paths inside the sandbox’s working directory. bash accepts a timeout, and long output is truncated before it reaches the model.
  • Without a sandbox, the agent has no built-in tools. See Sandboxes.

To give an agent your own tools, see Custom Tools.