For AI agents: a documentation index is available at https://docs.plungeai.com/llms.txt. Append .md to any page URL, or send Accept: text/markdown, to get markdown. Setup instructions for agents are at https://docs.plungeai.com/agents.md. One ozk_ key opens every plane, models included.

Documentation Index: fetch the complete documentation index at /llms.txt. Use this file to discover all available pages before exploring further.

A loop can only call the tools its fence lists. The fence is allowed_tools on the harness task; a tool not listed never runs. This page lists what exists. How a call is allowed, asked or denied is on Policy and review.

Without allowed_tools

On agent: one-agent, a task that names no allowed_tools gets every tool on this page. Name allowed_tools to narrow it. universal-agent, the concierge runtime, has a smaller default fence: the core eight below.

The core eight

ToolDoes
registry_search (alias find_agent)Searches the platform registry for agents, workflows, connectors and capability cards.
registry_lookup (alias agent_card)Reads one card in full: parameters, prompt format, examples.
call_agent (alias run_agent)Runs a platform agent by id and operation.
web_searchWeb search.
web_fetchFetches a public URL. It follows up to 5 redirects by hand, checks every hop is public, and refuses https to http.
load_skillLoads a skill, persona, expert or background that was not already injected.
ask_userPauses the run on a question for the person.
task_completeEnds the run with the result.

A fence that lists allowed_tools must include task_complete, or the run cannot finish cleanly.

The other tools

ToolDoes
read_file, write_file, edit_file, list_files, search_files, delete_fileA virtual workspace. workspace: bot keeps it across runs.
memoryDurable facts that survive across sessions. One call applies a batch of operations (add, replace, remove) to the user or memory target. read and forget {query} are single calls of their own; forget purges every entry containing the text.
knowledgeThe user's knowledge base: query, get_page, list_pages, save, add_source, ingest, lint.
recall, recall_historySearch your own past runs and reuse a prior result instead of redoing the work.
skill_manageCreate, patch or delete a private skill. Never on by default; every write pauses for approval unless permissions: { skill_manage: allow }.
delegateRuns focused sub-agents in parallel, each with only the tools you grant it.
invoke_workflowRuns a CNL workflow, from a template id or inline YAML.
run_pythonRuns Python for calculations and data transforms.
local_agentRuns an action on a local agent on the owner's machine, over the tunnel.
platform_actionAsks the user's client to perform a platform action; the run pauses until the client resumes it.
mcp_tool_searchLoads MCP tool schemas on demand (see below).

MCP tools

MCP tools reach the loop under names that start with mcp__. Past 15 tools or 8 KB of schemas, the system prompt lists them by name only and mcp_tool_search loads up to 5 schemas for the next turn. A continue or a new leg forgets them: search again. The search never offers a tool the run's permissions or posture refuse.

Bot tools

When you narrow the fence, list the ones you want in allowed_tools. schedule, message_bot and the browser bot session need a saved bot, because the engine stamps the bot id and owner on the run. code needs no saved bot, only a connected OceanCode.

ToolInputDoes
scheduleaction: create, list, pause, resume, delete, run_now, wakeManages the bot's own schedule. See Schedules and wake.
message_botto, text, wait?Messages another bot, an A2A agent or a bot group. See Bot to bot and groups.
browsersteps, url?, session? (bot or none)Drives a cloud browser. session: bot (the default for a saved bot) keeps the bot's cookies between runs. Screenshots are saved under /shots/ in the bot's files.
codeprompt, directory?, session_id?, timeout_s?Hands one coding turn to the owner's OceanCode on their machine, over the Local Tunnel. timeout_s defaults to and is capped at 300. Pass the returned session_id to continue. With no OceanCode connected the tool says so.

Permission classes

Every call has a class. The class is what permissions, posture and the stored presets match on.

Tool or caseClass
A guarded money categorypay
message_botsend
codewrite
scheduleby action: delete is delete, list is read, the rest are write
browserwrite when a step clicks, types, runs script or presses keys, otherwise read
mcp__*from the server's own hints: destructive is delete, read-only is read, anything else write
local_agentwrite for actions that change the machine, otherwise read

Planned: TI-33

Search is not available yet. Until it ships, use the page index or browse the sidebar.

Planned: TI-34

The docs assistant is not available yet. You can hand these docs to your own assistant instead.