> ## Documentation Index
> Fetch the complete documentation index at: https://docs.plungeai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# One Agent tools

> The tools a one-agent loop can call. What a task gets without allowed_tools, the core eight, the other tools and the four bot tools, with what each does and its permission class.


A loop can only call the tools its fence lists. The fence is `allowed_tools` on the harness task; a tool not listed never runs. This page lists what exists. How a call is allowed, asked or denied is on [Policy and review](/one-agent/policy-and-review).

## Without `allowed_tools`

On `agent: one-agent`, a task that names no `allowed_tools` gets every tool on this page. Name `allowed_tools` to narrow it. `universal-agent`, the concierge runtime, has a smaller default fence: the core eight below.

## The core eight

| Tool | Does |
|---|---|
| `registry_search` (alias `find_agent`) | Searches the platform registry for agents, workflows, connectors and capability cards. |
| `registry_lookup` (alias `agent_card`) | Reads one card in full: parameters, prompt format, examples. |
| `call_agent` (alias `run_agent`) | Runs a platform agent by id and operation. |
| `web_search` | Web search. |
| `web_fetch` | Fetches a public URL. It follows up to 5 redirects by hand, checks every hop is public, and refuses https to http. |
| `load_skill` | Loads a skill, persona, expert or background that was not already injected. |
| `ask_user` | Pauses the run on a question for the person. |
| `task_complete` | Ends the run with the result. |

A fence that lists `allowed_tools` must include `task_complete`, or the run cannot finish cleanly.

## The other tools

| Tool | Does |
|---|---|
| `read_file`, `write_file`, `edit_file`, `list_files`, `search_files`, `delete_file` | A virtual workspace. `workspace: bot` keeps it across runs. |
| `memory` | Durable facts that survive across sessions. One call applies a batch of `operations` (`add`, `replace`, `remove`) to the `user` or `memory` target. `read` and `forget {query}` are single calls of their own; `forget` purges every entry containing the text. |
| `knowledge` | The user's knowledge base: `query`, `get_page`, `list_pages`, `save`, `add_source`, `ingest`, `lint`. |
| `recall`, `recall_history` | Search your own past runs and reuse a prior result instead of redoing the work. |
| `skill_manage` | Create, patch or delete a private skill. Never on by default; every write pauses for approval unless `permissions: { skill_manage: allow }`. |
| `delegate` | Runs focused sub-agents in parallel, each with only the tools you grant it. |
| `invoke_workflow` | Runs a CNL workflow, from a template id or inline YAML. |
| `run_python` | Runs Python for calculations and data transforms. |
| `local_agent` | Runs an action on a local agent on the owner's machine, over the tunnel. |
| `platform_action` | Asks the user's client to perform a platform action; the run pauses until the client resumes it. |
| `mcp_tool_search` | Loads MCP tool schemas on demand (see below). |

### MCP tools

MCP tools reach the loop under names that start with `mcp__`. Past 15 tools or 8 KB of schemas, the system prompt lists them by name only and `mcp_tool_search` loads up to 5 schemas for the next turn. A continue or a new leg forgets them: search again. The search never offers a tool the run's permissions or posture refuse.

## Bot tools

When you narrow the fence, list the ones you want in `allowed_tools`. `schedule`, `message_bot` and the `browser` bot session need a saved bot, because the engine stamps the bot id and owner on the run. `code` needs no saved bot, only a connected OceanCode.

| Tool | Input | Does |
|---|---|---|
| `schedule` | `action`: `create`, `list`, `pause`, `resume`, `delete`, `run_now`, `wake` | Manages the bot's own schedule. See [Schedules and wake](/bots/schedules-and-wake). |
| `message_bot` | `to`, `text`, `wait?` | Messages another bot, an A2A agent or a bot group. See [Bot to bot and groups](/bots/bot-to-bot-and-groups). |
| `browser` | `steps`, `url?`, `session?` (`bot` or `none`) | Drives a cloud browser. `session: bot` (the default for a saved bot) keeps the bot's cookies between runs. Screenshots are saved under `/shots/` in the bot's files. |
| `code` | `prompt`, `directory?`, `session_id?`, `timeout_s?` | Hands one coding turn to the owner's OceanCode on their machine, over the Local Tunnel. `timeout_s` defaults to and is capped at 300. Pass the returned `session_id` to continue. With no OceanCode connected the tool says so. |

## Permission classes

Every call has a class. The class is what `permissions`, `posture` and the stored presets match on.

| Tool or case | Class |
|---|---|
| A guarded money category | `pay` |
| `message_bot` | `send` |
| `code` | `write` |
| `schedule` | by action: `delete` is `delete`, `list` is `read`, the rest are `write` |
| `browser` | `write` when a step clicks, types, runs script or presses keys, otherwise `read` |
| `mcp__*` | from the server's own hints: destructive is `delete`, read-only is `read`, anything else `write` |
| `local_agent` | `write` for actions that change the machine, otherwise `read` |
