One Agent
One Agent tools
The tools a one-agent loop can call. What a task gets without allowed_tools, the core eight, the other tools and the four bot tools, with what each does and its permission class.
A loop can only call the tools its fence lists. The fence is allowed_tools on the harness task; a tool not listed never runs. This page lists what exists. How a call is allowed, asked or denied is on Policy and review.
Without allowed_tools
On agent: one-agent, a task that names no allowed_tools gets every tool on this page. Name allowed_tools to narrow it. universal-agent, the concierge runtime, has a smaller default fence: the core eight below.
The core eight
| Tool | Does |
|---|---|
registry_search (alias find_agent) | Searches the platform registry for agents, workflows, connectors and capability cards. |
registry_lookup (alias agent_card) | Reads one card in full: parameters, prompt format, examples. |
call_agent (alias run_agent) | Runs a platform agent by id and operation. |
web_search | Web search. |
web_fetch | Fetches a public URL. It follows up to 5 redirects by hand, checks every hop is public, and refuses https to http. |
load_skill | Loads a skill, persona, expert or background that was not already injected. |
ask_user | Pauses the run on a question for the person. |
task_complete | Ends the run with the result. |
A fence that lists allowed_tools must include task_complete, or the run cannot finish cleanly.
The other tools
| Tool | Does |
|---|---|
read_file, write_file, edit_file, list_files, search_files, delete_file | A virtual workspace. workspace: bot keeps it across runs. |
memory | Durable facts that survive across sessions. One call applies a batch of operations (add, replace, remove) to the user or memory target. read and forget {query} are single calls of their own; forget purges every entry containing the text. |
knowledge | The user's knowledge base: query, get_page, list_pages, save, add_source, ingest, lint. |
recall, recall_history | Search your own past runs and reuse a prior result instead of redoing the work. |
skill_manage | Create, patch or delete a private skill. Never on by default; every write pauses for approval unless permissions: { skill_manage: allow }. |
delegate | Runs focused sub-agents in parallel, each with only the tools you grant it. |
invoke_workflow | Runs a CNL workflow, from a template id or inline YAML. |
run_python | Runs Python for calculations and data transforms. |
local_agent | Runs an action on a local agent on the owner's machine, over the tunnel. |
platform_action | Asks the user's client to perform a platform action; the run pauses until the client resumes it. |
mcp_tool_search | Loads MCP tool schemas on demand (see below). |
MCP tools
MCP tools reach the loop under names that start with mcp__. Past 15 tools or 8 KB of schemas, the system prompt lists them by name only and mcp_tool_search loads up to 5 schemas for the next turn. A continue or a new leg forgets them: search again. The search never offers a tool the run's permissions or posture refuse.
Bot tools
When you narrow the fence, list the ones you want in allowed_tools. schedule, message_bot and the browser bot session need a saved bot, because the engine stamps the bot id and owner on the run. code needs no saved bot, only a connected OceanCode.
| Tool | Input | Does |
|---|---|---|
schedule | action: create, list, pause, resume, delete, run_now, wake | Manages the bot's own schedule. See Schedules and wake. |
message_bot | to, text, wait? | Messages another bot, an A2A agent or a bot group. See Bot to bot and groups. |
browser | steps, url?, session? (bot or none) | Drives a cloud browser. session: bot (the default for a saved bot) keeps the bot's cookies between runs. Screenshots are saved under /shots/ in the bot's files. |
code | prompt, directory?, session_id?, timeout_s? | Hands one coding turn to the owner's OceanCode on their machine, over the Local Tunnel. timeout_s defaults to and is capped at 300. Pass the returned session_id to continue. With no OceanCode connected the tool says so. |
Permission classes
Every call has a class. The class is what permissions, posture and the stored presets match on.
| Tool or case | Class |
|---|---|
| A guarded money category | pay |
message_bot | send |
code | write |
schedule | by action: delete is delete, list is read, the rest are write |
browser | write when a step clicks, types, runs script or presses keys, otherwise read |
mcp__* | from the server's own hints: destructive is delete, read-only is read, anything else write |
local_agent | write for actions that change the machine, otherwise read |