gen-tool-catalog.ts 27 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563
  1. /**
  2. * Generate `docs/tool-catalog.md` from schemas collected by booting each tool
  3. * plugin. Runtime registration is the source of truth for computed schemas;
  4. * the manifest is checked against every on-disk `tool-*` package. `--check`
  5. * verifies the committed artifact. Rationale and ownership live in
  6. * `.agents/notes/implemented/process/2026-07-02-tool-schema-catalog.md`.
  7. */
  8. import { globSync, readFileSync, writeFileSync } from 'node:fs'
  9. import { basename, resolve } from 'node:path'
  10. import { Context } from 'cordis'
  11. import type { ToolSchema } from '@deepseek-ai/dsh-llm'
  12. import AgentRegistry from '@deepseek-ai/dsh-agent'
  13. import SessionStore from '@deepseek-ai/dsh-session'
  14. import SessionQuerySqlite from '@deepseek-ai/dsh-session-query-sqlite'
  15. import GoalService from '@deepseek-ai/dsh-goal'
  16. import SystemPrompt from '@deepseek-ai/dsh-system-prompt'
  17. import ToolRegistry, { type Config as ToolsConfig } from '@deepseek-ai/dsh-tools'
  18. import { BashExecutor } from '@deepseek-ai/dsh-bash'
  19. import type { BashExecRequest, BashExecSpec, BashProcess, BashRunResult } from '@deepseek-ai/dsh-bash'
  20. import LocalBashExecutor from '@deepseek-ai/dsh-bash-local'
  21. import LocalSubprocessService from '@deepseek-ai/dsh-subprocess-local'
  22. import LocalFileSystem from '@deepseek-ai/dsh-fs-local'
  23. import UserInteractionService from '@deepseek-ai/dsh-user-interaction'
  24. import PlanModeService from '@deepseek-ai/dsh-plan-mode'
  25. import WebService from '@deepseek-ai/dsh-web'
  26. import * as WebSearchExa from '@deepseek-ai/dsh-web-search-exa'
  27. import * as WebFetchLocal from '@deepseek-ai/dsh-web-fetch-local'
  28. import SubagentService from '@deepseek-ai/dsh-subagent'
  29. import type { SubagentProvider } from '@deepseek-ai/dsh-subagent'
  30. import SkillService from '@deepseek-ai/dsh-skill'
  31. import * as SkillLocal from '@deepseek-ai/dsh-skill-local'
  32. import LocalTaskService from '@deepseek-ai/dsh-tasks-local'
  33. import * as ToolAskUser from '@deepseek-ai/dsh-tool-ask-user'
  34. import * as ToolBash from '@deepseek-ai/dsh-tool-bash'
  35. import * as ToolCordis from '@deepseek-ai/dsh-tool-cordis'
  36. import * as ToolFs from '@deepseek-ai/dsh-tool-fs'
  37. import * as ToolFsSearch from '@deepseek-ai/dsh-tool-fs-search'
  38. import PtyService from '@deepseek-ai/dsh-pty'
  39. import * as ToolPty from '@deepseek-ai/dsh-tool-pty'
  40. import * as ToolGoal from '@deepseek-ai/dsh-tool-goal'
  41. import Lsp from '@deepseek-ai/dsh-lsp'
  42. import * as ToolLsp from '@deepseek-ai/dsh-tool-lsp'
  43. import * as ToolSkill from '@deepseek-ai/dsh-tool-skill'
  44. import * as ToolSessionQuery from '@deepseek-ai/dsh-tool-session-query'
  45. import * as ToolTasks from '@deepseek-ai/dsh-tool-tasks'
  46. import * as ToolTodo from '@deepseek-ai/dsh-tool-todo'
  47. import * as ToolSubagent from '@deepseek-ai/dsh-tool-subagent'
  48. import * as ToolWeb from '@deepseek-ai/dsh-tool-web'
  49. import VmWorkflowEngine from '@deepseek-ai/dsh-workflow-workerthread'
  50. import * as ToolRalph from '@deepseek-ai/dsh-tool-ralph'
  51. import * as ToolWorkflow from '@deepseek-ai/dsh-tool-workflow'
  52. const root = resolve(import.meta.dirname, '..')
  53. const OUT = 'docs/tool-catalog.md'
  54. const CATALOG_RG_PROBE_COMMAND = 'command -v rg >/dev/null 2>&1'
  55. /**
  56. * Minimal bash service for harvesting `dsh-tool-fs-search` schemas. The search
  57. * plugin now probes `rg` at registration time, but the generated catalog must
  58. * remain independent of the host PATH and never execute a real search.
  59. */
  60. class CatalogSearchBashExecutor extends BashExecutor {
  61. override resolve(request: BashExecRequest): BashExecSpec {
  62. return {
  63. command: request.command,
  64. workdir: request.workdir ?? root,
  65. timeoutMs: request.timeoutMs ?? 60_000,
  66. stdoutMaxBytes: request.stdoutMaxBytes ?? 64_000,
  67. signal: request.signal,
  68. sandboxPolicy: request.sandboxPolicy,
  69. }
  70. }
  71. override run(spec: BashExecSpec): Promise<BashRunResult> {
  72. if (spec.command !== CATALOG_RG_PROBE_COMMAND) {
  73. throw new Error(`gen-tool-catalog: unexpected search bash command during schema harvest: ${spec.command}`)
  74. }
  75. return Promise.resolve({
  76. exitCode: 0,
  77. signal: null,
  78. timedOut: false,
  79. aborted: false,
  80. timeoutMs: spec.timeoutMs,
  81. stdout: { text: '', truncated: false },
  82. stderr: { text: '', truncated: false },
  83. })
  84. }
  85. override start(): BashProcess {
  86. throw new Error('gen-tool-catalog: search schema harvest must not start background processes')
  87. }
  88. }
  89. /**
  90. * Register the descriptor needed to mount schema-producing consumers. Declares
  91. * the full capability set of the shipped in-process providers so consumers
  92. * mount under their shipped defaults (tool-subagent's default numeric maxDepth
  93. * requires `depthLimit`).
  94. */
  95. function registerCatalogSubagentProvider(ctx: Context, name: string): void {
  96. const provider: SubagentProvider = {
  97. name,
  98. capabilities: { outputSchema: true, depthLimit: true, toolFilter: true, persona: true },
  99. inheritsParentContext: false,
  100. start: () => Promise.reject(new Error('tool-catalog provider cannot start a child')),
  101. }
  102. ctx.subagents.registerProvider(provider)
  103. }
  104. /**
  105. * Tool package plus its hand-maintained boot recipe. The caller mounts the
  106. * prompt and registry; each recipe supplies only package-specific seams and
  107. * config, while `dir` participates in the completeness check.
  108. */
  109. interface ToolPackage {
  110. /** The npm package name, used as the catalog section heading. */
  111. pkg: string
  112. /** The `packages/<group>/<dir>` leaf name — matched by the completeness guard. */
  113. dir: string
  114. /** Repo-relative source path linked from the catalog entry. */
  115. source: string
  116. /** Services or owning runtime surfaces the package requires at execution time. */
  117. requires: string[]
  118. /** Session events or other visible state the tools write or affect. */
  119. writes: string[]
  120. /** Additional model-visible names shipped by example/app config. */
  121. shippedNames?: string[]
  122. /** Plug the injected seams + the tool plugin onto a context that already
  123. * carries `systemPrompt` + `tools`. */
  124. mount: (ctx: Context) => Promise<void>
  125. /**
  126. * Config for the caller's `ToolRegistry` mount. The registry itself ships a
  127. * model-facing tool (`run_code`, registered under a non-native `mode`), so
  128. * ITS catalog entry boots the registry in the mode that surfaces it;
  129. * every other entry uses the default (native) registry.
  130. */
  131. toolsConfig?: ToolsConfig
  132. /**
  133. * A deployment note rendered after the package's tools, for a fact that
  134. * booting the package alone cannot show. The registered tool NAME can be a
  135. * load-time config (`tool-subagent`'s `toolName`), so one package may surface
  136. * under several names across deployments — the boot yields the package
  137. * DEFAULT, and this note records the shipped alternatives the model sees.
  138. */
  139. note?: string
  140. }
  141. /**
  142. * The boot manifest: every shipped tool package (a `tool-*` leaf under
  143. * `packages/`). Ordered by package name (the render order); the completeness
  144. * guard proves it is exhaustive against the on-disk glob.
  145. */
  146. const TOOL_PACKAGES: ToolPackage[] = [
  147. {
  148. pkg: '@deepseek-ai/dsh-tool-ask-user',
  149. dir: 'tool-ask-user',
  150. source: 'packages/ui/tool-ask-user/src/index.ts',
  151. requires: ['ctx.tools', 'ctx.userInteraction'],
  152. writes: ['tool/call', 'tool/result after a UI/provider answers the question'],
  153. async mount(ctx) {
  154. await ctx.plugin(UserInteractionService)
  155. await ctx.plugin(ToolAskUser)
  156. },
  157. note:
  158. 'ask_user_question pauses the tool call until the active UI provider returns a human answer.',
  159. },
  160. {
  161. pkg: '@deepseek-ai/dsh-tools',
  162. dir: 'tools',
  163. source: 'packages/core/tools/src/code-mode.ts',
  164. requires: ['ctx.tools', 'ctx.codeRuntime (execution time)', 'ctx.systemPrompt'],
  165. writes: ['tool/call', 'one tool/code-dispatch-start + tool/code-dispatch pair per bridged sub-call', 'tool/result'],
  166. // The registry's OWN tool: run_code exists only under a non-native mode
  167. // (the registry registers it in its constructor; the code runtime is read
  168. // at assembly/execution time, so the schema harvest needs none mounted).
  169. toolsConfig: { mode: 'code' },
  170. async mount() {},
  171. note:
  172. 'Owned by the tool registry as a reserved transport outside filterable capability layers under `mode: code` / `mode: both` (see the Code Mode Agent Note). Under `code` it is the registry\'s only wire contribution; the other visible capabilities are declared in a generated TypeScript SDK section, and a program calls them through bindings scheduled under the native concurrency contract (submission-ordered starts and policy; concurrency-safe bodies overlap up to `maxParallelSubCalls`) that re-enter the complete guarded tool pipeline and link each nested execution to this outer result.',
  173. },
  174. {
  175. pkg: '@deepseek-ai/dsh-plan-mode',
  176. dir: 'plan-mode',
  177. source: 'packages/plan/plan-mode/src/index.ts',
  178. requires: ['ctx.tools', 'ctx.systemPrompt', 'ctx.userInteraction (execution time, opportunistic)'],
  179. writes: ['tool/call', 'plan/mode inactive on an approved review', 'tool/result'],
  180. async mount(ctx) {
  181. await ctx.plugin(PlanModeService, { section: 'Tool catalog schema harvest.' })
  182. },
  183. note:
  184. 'exit_plan_mode stays in the model-facing schema while planning is inactive so transitions add no tool-catalog churn on top of the plan-policy change. Its execute path rejects calls outside plan mode; in plan mode it presents the plan over the user-interaction seam (approve / keep planning with feedback), and approval logs plan mode inactive at the step boundary.',
  185. },
  186. {
  187. pkg: '@deepseek-ai/dsh-tool-bash',
  188. dir: 'tool-bash',
  189. source: 'packages/bash/tool-bash/src/index.ts',
  190. requires: ['ctx.tools', 'ctx.bash', 'ctx.tasks at call time for run_in_background'],
  191. writes: ['tool/call', 'tool/result'],
  192. async mount(ctx) {
  193. await ctx.plugin(LocalSubprocessService)
  194. await ctx.plugin(LocalBashExecutor)
  195. await ctx.plugin(ToolBash)
  196. },
  197. note:
  198. 'The bash tool is the model-facing consumer of the bash executor seam. A `run_in_background` run registers with the generic `ctx.tasks` runtime and is collected/stopped through the `task_*` tools from `@deepseek-ai/dsh-tool-tasks`; the `enableRunInBackground` config (default true) removes the parameter entirely when disabled.',
  199. },
  200. {
  201. pkg: '@deepseek-ai/dsh-tool-cordis',
  202. dir: 'tool-cordis',
  203. source: 'packages/cordis/tool-cordis/src/index.ts',
  204. requires: ['ctx.tools'],
  205. writes: ['tool/call', 'tool/result', 'process-local temporary Plugin lifecycle'],
  206. async mount(ctx) {
  207. await ctx.plugin(ToolCordis)
  208. },
  209. note:
  210. 'Ships in examples/cordis-agent only (a deliberate opt-in — temporary Plugin code reaches the real runtime, see .agents/notes/implemented/feature/2026-07-08-self-referential-cordis-toolset.md). Plugins created by cordis_mount may register ADDITIONAL model-visible tools until unmounted or DSH restarts; a full changed request header logs those tool-set changes.',
  211. },
  212. {
  213. pkg: '@deepseek-ai/dsh-tool-fs',
  214. dir: 'tool-fs',
  215. source: 'packages/fs/tool-fs/src/index.ts',
  216. requires: ['ctx.tools', 'ctx.fs', 'ctx.systemPrompt'],
  217. writes: ['tool/call', 'fs/write-intent or fs/edit-intent for mutations', 'fs/observed after successful file operations', 'tool/result'],
  218. async mount(ctx) {
  219. // The tool needs `fs`; the bare provider is sufficient because policy
  220. // changes behavior, not schema shape.
  221. await ctx.plugin(LocalFileSystem)
  222. await ctx.plugin(ToolFs)
  223. },
  224. note:
  225. 'The read-before-write/edit policy is added by `@deepseek-ai/dsh-fs-policy` (an `fs/*` event-gate plugin, no schema change); a deployment that loads these tools is expected to also load it. The tool schemas above are identical with or without the policy plugin.',
  226. },
  227. {
  228. pkg: '@deepseek-ai/dsh-tool-fs-search',
  229. dir: 'tool-fs-search',
  230. source: 'packages/fs/tool-fs-search/src/index.ts',
  231. requires: ['ctx.tools', 'ctx.bash', 'ctx.systemPrompt'],
  232. writes: ['tool/call', 'tool/result'],
  233. async mount(ctx) {
  234. // The tools inject `bash` (search executes fixed `rg` commands through
  235. // the executor seam, not ctx.fs). Use a catalog-only executor so the
  236. // registration-time `rg` probe stays deterministic and the generator
  237. // never depends on the host PATH. `ctx.spillStore` is optional (read via
  238. // ctx.get) and does not affect the schemas, so no spill backend is mounted.
  239. await ctx.plugin(CatalogSearchBashExecutor)
  240. await ctx.plugin(ToolFsSearch)
  241. },
  242. note:
  243. 'glob and grep are conditional bash-backed discovery tools: they register only when ctx.bash can find `rg`, then run fixed ripgrep commands through ctx.bash as ordinary foreground calls (never background tasks). Capped results save the complete formatted list through the optional ctx.spillStore backend; returned locators are follow-up-readable/searchable when the backend exposes local paths in co-located deployments.',
  244. },
  245. {
  246. pkg: '@deepseek-ai/dsh-tool-pty',
  247. dir: 'tool-pty',
  248. source: 'packages/pty/tool-pty/src/index.ts',
  249. requires: ['ctx.tools', 'ctx.pty', 'ctx.systemPrompt', 'ctx.tasks at call time for run_in_background'],
  250. writes: ['tool/call', 'tool/result'],
  251. async mount(ctx) {
  252. await ctx.plugin(PtyService)
  253. await ctx.plugin(ToolPty)
  254. },
  255. note:
  256. 'The six terminal tools are opt-in and complement one-shot bash/filesystem tools. `terminal_send(run_in_background: true)` registers with `ctx.tasks`; TUI, named key sequences, BEL, resize, auto-start, and cross-agent sharing are absent from the schema.',
  257. },
  258. {
  259. pkg: '@deepseek-ai/dsh-tool-goal',
  260. dir: 'tool-goal',
  261. source: 'packages/goal/tool-goal/src/index.ts',
  262. requires: ['ctx.tools', 'ctx.agents', 'ctx.goals', 'ctx.systemPrompt', 'a calling Agent in an authorized open turn'],
  263. writes: ['tool/call', 'user/message goal snapshot for mutations', 'tool/result'],
  264. async mount(ctx) {
  265. await ctx.plugin(AgentRegistry)
  266. await ctx.plugin(GoalService)
  267. await ctx.plugin(ToolGoal)
  268. },
  269. note:
  270. 'create, edit, pause, and resume require direct-human root authority; complete and blocked also accept the exact current goal round. The default blocked lower bound is three admitted rounds.',
  271. },
  272. {
  273. pkg: '@deepseek-ai/dsh-tool-lsp',
  274. dir: 'tool-lsp',
  275. source: 'packages/lsp/tool-lsp/src/index.ts',
  276. requires: ['ctx.tools', 'ctx.lsp', 'ctx.systemPrompt'],
  277. writes: ['tool/call', 'tool/result'],
  278. async mount(ctx) {
  279. // The tool registers from the seam alone; the schema does not depend on any provider.
  280. await ctx.plugin(Lsp)
  281. await ctx.plugin(ToolLsp)
  282. },
  283. note:
  284. 'The lsp tool keeps provider selection and language-server subprocesses behind ctx.lsp, so its model-visible schema stays stable across providers. Requires a registered provider (e.g. `@deepseek-ai/dsh-lsp-local`) at runtime; without one, a query returns the structured `LSP_UNAVAILABLE` error rather than changing the schema.',
  285. },
  286. {
  287. pkg: '@deepseek-ai/dsh-tool-ralph',
  288. dir: 'tool-ralph',
  289. source: 'packages/workflow/tool-ralph/src/index.ts',
  290. requires: ['ctx.tools', 'ctx.workflows', 'ctx.subagents', 'ctx.systemPrompt', 'a calling Agent (exec.agent parents every fresh round)'],
  291. writes: ['tool/call', 'tool/result', 'workflow and child session events during execution'],
  292. async mount(ctx) {
  293. await ctx.plugin(SubagentService)
  294. registerCatalogSubagentProvider(ctx, 'mock')
  295. await ctx.plugin(VmWorkflowEngine, { provider: 'mock' })
  296. await ctx.plugin(ToolRalph, { subagentProvider: 'mock' })
  297. },
  298. note:
  299. 'A fixed foreground workflow starts one fresh structured child per round; the model selects only the immutable objective and an optional round cap.',
  300. },
  301. {
  302. pkg: '@deepseek-ai/dsh-tool-skill',
  303. dir: 'tool-skill',
  304. source: 'packages/skill/tool-skill/src/index.ts',
  305. requires: ['ctx.tools', 'ctx.skills'],
  306. writes: ['tool/call', 'tool/result'],
  307. async mount(ctx) {
  308. await ctx.plugin(SkillService)
  309. await ctx.plugin(SkillLocal, {
  310. dshHome: resolve(root, '.tmp/tool-catalog/.dsh'),
  311. agentsHome: resolve(root, '.tmp/tool-catalog/.agents'),
  312. })
  313. await ctx.plugin(ToolSkill)
  314. },
  315. },
  316. {
  317. pkg: '@deepseek-ai/dsh-tool-session-query',
  318. dir: 'tool-session-query',
  319. source: 'packages/session-query/tool-session-query/src/index.ts',
  320. requires: ['ctx.tools', 'ctx.systemPrompt', 'ctx.sessionQuery', 'a calling Agent for workspace authority'],
  321. writes: ['tool/call', 'tool/result'],
  322. async mount(ctx) {
  323. await ctx.plugin(SessionStore)
  324. await ctx.plugin(SessionQuerySqlite, { path: ':memory:' })
  325. await ctx.plugin(ToolSessionQuery)
  326. },
  327. note:
  328. 'The five read-only tools hide provider cursors and authorize every result from the immutable calling agent session. The package is opt-in; compositions that need enforced deadlines or bounded inline output also mount the generic timeout or spill policies.',
  329. },
  330. {
  331. pkg: '@deepseek-ai/dsh-tool-subagent',
  332. dir: 'tool-subagent',
  333. source: 'packages/subagent/tool-subagent/src/index.ts',
  334. requires: ['ctx.tools', 'ctx.subagents'],
  335. writes: ['tool/call', 'tool/result', 'child session events through the chosen provider'],
  336. shippedNames: ['subagent', 'subagent_fork'],
  337. async mount(ctx) {
  338. await ctx.plugin(SubagentService)
  339. registerCatalogSubagentProvider(ctx, 'mock')
  340. await ctx.plugin(ToolSubagent, { provider: 'mock' })
  341. },
  342. note:
  343. 'The registered tool name is the load-time `toolName` config (default `subagent`); the schema above is that default. The shipped example agents load this package once per subagent backend, so the model additionally sees `subagent_fork` (bound to the fork backend) with an identical schema — see `examples/tui-agent/cordis.yml` and `examples/acp-agent/cordis.yml`.',
  344. },
  345. {
  346. pkg: '@deepseek-ai/dsh-tool-tasks',
  347. dir: 'tool-tasks',
  348. source: 'packages/tasks/tool-tasks/src/index.ts',
  349. requires: ['ctx.tools', 'ctx.tasks', 'ctx.systemPrompt'],
  350. writes: ['tool/call', 'tool/result', 'user/message via agent.inject() for background completion notices'],
  351. async mount(ctx) {
  352. await ctx.plugin(LocalTaskService)
  353. await ctx.plugin(ToolTasks)
  354. },
  355. note:
  356. 'The kind-agnostic background-task control surface: background bash commands, PTY sends, and subagents are read, listed, and killed through the same three tools. Loading the plugin attaches the control surface that arms producers\' `ctx.tasks.start()`.',
  357. },
  358. {
  359. pkg: '@deepseek-ai/dsh-tool-todo',
  360. dir: 'tool-todo',
  361. source: 'packages/todo/tool-todo/src/index.ts',
  362. requires: ['ctx.tools', 'owning Agent session'],
  363. writes: ['tool/call', 'todo/write', 'tool/result'],
  364. async mount(ctx) {
  365. await ctx.plugin(ToolTodo)
  366. },
  367. note:
  368. 'todo_write is session-owned state; UIs render the latest todo/write event as a checklist.',
  369. },
  370. {
  371. pkg: '@deepseek-ai/dsh-tool-workflow',
  372. dir: 'tool-workflow',
  373. source: 'packages/workflow/tool-workflow/src/index.ts',
  374. requires: ['ctx.tools', 'ctx.workflows', 'ctx.systemPrompt', 'a calling Agent (exec.agent parents the script children)'],
  375. writes: ['tool/call', 'tool/result'],
  376. async mount(ctx) {
  377. // The tool injects `workflows`; boot the vm engine over a scripted
  378. // subagent provider to satisfy it. The schema does not depend on which
  379. // provider backs the engine.
  380. await ctx.plugin(SubagentService)
  381. registerCatalogSubagentProvider(ctx, 'mock')
  382. await ctx.plugin(VmWorkflowEngine, { provider: 'mock' })
  383. await ctx.plugin(ToolWorkflow)
  384. },
  385. },
  386. {
  387. pkg: '@deepseek-ai/dsh-tool-web',
  388. dir: 'tool-web',
  389. source: 'packages/web/tool-web/src/index.ts',
  390. requires: ['ctx.tools', 'ctx.web', 'ctx.systemPrompt'],
  391. writes: ['tool/call', 'tool/result'],
  392. async mount(ctx) {
  393. // Mount search and fetch providers so both tools register. Their schemas
  394. // do not depend on provider identity or availability.
  395. await ctx.plugin(WebService)
  396. await ctx.plugin(WebSearchExa)
  397. await ctx.plugin(WebFetchLocal)
  398. await ctx.plugin(ToolWeb)
  399. },
  400. note:
  401. 'web_search and web_fetch keep provider selection behind ctx.web so model-visible schemas stay stable across backend swaps.',
  402. },
  403. ]
  404. /** One package's contribution to the catalog: its schemas plus attribution. */
  405. interface CatalogPackage {
  406. pkg: string
  407. source: string
  408. requires: string[]
  409. writes: string[]
  410. shippedNames?: string[]
  411. schemas: ToolSchema[]
  412. /** A deployment note (see {@link ToolPackage.note}), rendered after the tools. */
  413. note?: string
  414. }
  415. /** The whole catalog: one entry per booted tool package, in manifest order. */
  416. export type ToolCatalog = CatalogPackage[]
  417. /**
  418. * Assert the boot manifest covers every shipped tool package on disk (a
  419. * `tool-*` leaf under `packages/`).
  420. * Booting has no source declaration to enumerate, so this glob restores the
  421. * "a new tool cannot be silently undocumented" guarantee: an unlisted package
  422. * fails the generator (and the freshness gate) until it is added to
  423. * {@link TOOL_PACKAGES}. Exported for a direct negative test.
  424. *
  425. * `scanRoot` defaults to the repo root; a test may point it at a fixture tree.
  426. */
  427. export function assertManifestComplete(packages: ToolPackage[] = TOOL_PACKAGES, scanRoot: string = root): void {
  428. const onDisk = globSync('packages/*/tool-*', { cwd: scanRoot }).map(p => basename(p)).sort()
  429. const listed = new Set(packages.map(p => p.dir))
  430. const missing = onDisk.filter(dir => !listed.has(dir))
  431. if (missing.length > 0) {
  432. throw new Error(
  433. `gen-tool-catalog: ${missing.length} tool package(s) not in the boot manifest: ${missing.join(', ')}. `
  434. + 'Add each to TOOL_PACKAGES in scripts/gen-tool-catalog.ts so its schema is catalogued.',
  435. )
  436. }
  437. }
  438. /**
  439. * Boot each tool package on a fresh Context and harvest its model-facing
  440. * schemas. A fresh Context per package keeps attribution clean (each entry's
  441. * schemas come from exactly that package) and isolates a boot failure to its
  442. * own entry. Disposed after harvest so no executor/provider outlives the run.
  443. */
  444. export async function collectToolCatalog(packages: ToolPackage[] = TOOL_PACKAGES): Promise<ToolCatalog> {
  445. assertManifestComplete(packages)
  446. const catalog: ToolCatalog = []
  447. for (const entry of packages) {
  448. const ctx = new Context()
  449. // Dispose in `finally` so a throw from `mount`/`schemas()` after earlier
  450. // plugins mounted still tears the context down (no leaked executor/provider
  451. // fiber) — the repo's "dispose must reach quiescence" rule.
  452. try {
  453. await ctx.plugin(SystemPrompt)
  454. await ctx.plugin(ToolRegistry, entry.toolsConfig ?? {})
  455. await entry.mount(ctx)
  456. const schemas = ctx.tools.schemas().sort((a, b) => a.name.localeCompare(b.name))
  457. catalog.push({
  458. pkg: entry.pkg,
  459. source: entry.source,
  460. requires: entry.requires,
  461. writes: entry.writes,
  462. schemas,
  463. ...entry.shippedNames !== undefined ? { shippedNames: entry.shippedNames } : {},
  464. ...entry.note !== undefined ? { note: entry.note } : {},
  465. })
  466. } finally {
  467. await ctx.fiber.dispose()
  468. }
  469. }
  470. return catalog
  471. }
  472. /** Render one tool's entry: name, description, JSON-Schema parameters, source. */
  473. function renderTool(schema: ToolSchema, source: string): string[] {
  474. const out = [`### \`${schema.name}\``, '']
  475. if (schema.description) out.push(schema.description, '')
  476. out.push('```json', JSON.stringify(schema.parameters, null, 2), '```', '')
  477. out.push(`Source: [\`${source}\`](../${source})`, '')
  478. return out
  479. }
  480. function codeList(values: string[] | undefined): string {
  481. return values?.length ? values.map(value => `\`${value}\``).join(', ') : '-'
  482. }
  483. function tableCell(value: string | undefined): string {
  484. return value ? value.replace(/\|/g, '\\|').replace(/\n/g, '<br>') : '-'
  485. }
  486. /** Render the full catalog (pure, deterministic given the manifest-ordered input). */
  487. export function render(catalog: ToolCatalog): string {
  488. const lines: string[] = [
  489. '<!-- Generated by scripts/gen-tool-catalog.ts — do not edit by hand.',
  490. ' Run `pnpm run gen-tool-catalog` to regenerate. -->',
  491. '',
  492. '# Tool Schema Catalog',
  493. '',
  494. 'Every model-facing tool a shipped plugin contributes to `ctx.tools`: the `name`, `description`, and JSON-Schema `parameters` the model receives via the system-prompt assembly. It complements the cordis [events](cordis-catalog/events.md) & [services](cordis-catalog/services.md) catalogs (the wiring a plugin listens to and calls) and [core-data-structures/](core-data-structures/core.md) (the types those signatures move) — this page is the *tools* the agent is offered.',
  495. '',
  496. 'This file is GENERATED and verified fresh by `pnpm run verify-tool-catalog` (part of `doc-sync`) — do not edit it by hand. Unlike the cordis catalog (a pure source-AST pass), this generator BOOTS each tool plugin on a real context and reads `ctx.tools.schemas()`, because a tool schema is not statically knowable (runtime-spread enums, concatenated descriptions, config-driven names, raw-JSON-Schema MCP tools). A completeness guard globs `packages/*/tool-*` and fails if any package is missing from the generator\'s boot manifest, so a new tool cannot be silently undocumented. See [the tool-schema-catalog Agent Note](../.agents/notes/implemented/process/2026-07-02-tool-schema-catalog.md).',
  497. '',
  498. 'Scope: shipped product tools under `packages/*/tool-*`, each booted with its DEFAULT config. The registered tool NAME can be a load-time config (e.g. `tool-subagent`\'s `toolName`), so a deployment may surface a package under a different or additional name — a per-package note records those shipped aliases where they exist. The `examples/` demo tools (e.g. `echo`) are excluded, matching the cordis catalog\'s packages-only scope.',
  499. '',
  500. '## Tool Package Map',
  501. '',
  502. 'This table connects model-visible tool names to the plugin package and service seams behind them. Exact JSON Schemas follow in the package sections below.',
  503. '',
  504. '| Tool package | Model-visible names | Requires | Writes / affects | Shipped aliases | Deployment note |',
  505. '| --- | --- | --- | --- | --- | --- |',
  506. ...catalog.map(entry => `| \`${entry.pkg}\` | ${codeList(entry.schemas.map(schema => schema.name))} | ${codeList(entry.requires)} | ${codeList(entry.writes)} | ${codeList(entry.shippedNames)} | ${tableCell(entry.note)} |`),
  507. '',
  508. ]
  509. for (const entry of catalog) {
  510. lines.push(`## \`${entry.pkg}\``, '')
  511. for (const schema of entry.schemas) lines.push(...renderTool(schema, entry.source))
  512. if (entry.note) lines.push(entry.note, '')
  513. }
  514. return lines.join('\n')
  515. }
  516. /** CLI entry: default writes the catalog, `--check` fails if the committed copy
  517. * is stale. Guarded behind an entry-point check so importing this module for
  518. * tests neither regenerates the committed file nor calls process.exit. */
  519. async function main(): Promise<void> {
  520. const content = render(await collectToolCatalog())
  521. if (process.argv.includes('--check')) {
  522. let committed: string | null = null
  523. try {
  524. committed = readFileSync(resolve(root, OUT), 'utf8')
  525. } catch {
  526. // Only ENOENT (not yet generated) is expected; a present-but-unreadable
  527. // file is not a state this repo produces. Either way the remedy is the
  528. // same — regenerate — so treat a read failure as "stale".
  529. committed = null
  530. }
  531. if (committed === content) {
  532. console.log(`gen-tool-catalog: ${OUT} is up to date.`)
  533. process.exit(0)
  534. }
  535. console.error(`gen-tool-catalog: ${OUT} is stale. Run \`pnpm run gen-tool-catalog\` and commit ${OUT}.`)
  536. process.exit(1)
  537. }
  538. writeFileSync(resolve(root, OUT), content)
  539. console.log(`gen-tool-catalog: wrote ${OUT}.`)
  540. }
  541. // Run only when invoked as a script, not when imported by a test.
  542. if (process.argv[1] && import.meta.filename === resolve(process.argv[1])) {
  543. await main()
  544. }