Watch
3
Add common baseline agentic tools #155
Closed
opened 2026-08-12 17:41:28 +00:00 by coilysiren
·
6 comments
No Branch/Tag specified
main
aos/claude/sj87-entity-attribute
aos/claude/sj87-challenge
aos/claude/turn-duration-buckets
aos/claude/turn-stages-over-cap
aos/claude/turn-stages-hold-doc
aos/claude/turn-iteration-cap
book-leads-the-glyphs
science-and-web-culture-packs
record-lane-role-voice-pairings
catalogue-stage-phrase
progress-rows-one-knob
skill-read-worklog-detail
librarian-lookup-first
librarian-person-package
feat/dowel-no-boundaries
aos/claude/gh1035-no-blank-posts
aos/claude/gh1036-harness-thread-name
fix/thread-names
feat/trajectory-completes
fix/prompt-budgets
aos/claude/docs-cut-2
aos/claude/ka54-thread-ownership
aos/claude/admission-bound
aos/claude/gh1025-roster-reexport
aos/claude/docs-strip-archaeology
feat/temporal-mcp
aos/claude/dowel-board-moxn-write-boundaries
aos/claude/ue65-moxn-write-framing
aos/claude/progress-backoff
aos/claude/bound-scratch-search-2
aos/claude/unblock-main
aos/claude/tool-breaker
fix/roster-core-eager
aos/claude/finish-dowel-rename
fix/971-skill-contract
aos/claude/model-answered-not-unavailable
aos/claude/mcp-singular-command
task/moxn-and-temporal-skills
aos/claude/ue65-temporal-brand
task/dowel-site-work-tier
aos/claude/ue65-roster-drift
fix/dropped-turn-always-speaks
aos/claude/folded-ask-coverage
aos/claude/dowel-board
aos/claude/dowel-pronouns
feat/trajectory-keyed-on-the-message
aos/claude/coalesce-discord-lane
task/derive-shipped-profiles
fix/ship-the-dowel-skill-root
aos/claude/eval-context
fix/bundle-references-reachable
aos/claude/eval-docs-one-page
aos/claude/dowel-engineer-suite
fix/catalogue-clone-cache
feat/engineer-role-graph
task/free-the-config-numbers
aos/claude/dowel-site-work
aos/claude/dowel-prose
aos/claude/mx76-derive-knobs
issue-859-on-demand-skill-reads
issue-651-ship-well-formed-replies
issue-852-filing-validity
issue-916-calculator-tool
issue-854-feature-flag-table
issue-866-role-mention-summons
issue-858-grounding-bound-per-server
issue-899-progress-keeps-updating
issue-900-rollup-mirrors-worklog
issue-901-raise-progress-cadence
issue-904-thread-title-length
issue-905-http-reachability
issue-855-turn-clock
issue-895-silent-turn
issue-873-mcp-tool-span-error
issue-878-settle-dropped-jobs
aos/claude/aw85-se-bands
aos/claude/hs68-model-rejected
aos/claude/hs68-effect-telemetry
aos/claude/hs68-temporal-mirror
aos/claude/hs68-prompt-commands
aos/claude/hs68-model-idle-timeout
aos/claude/hs68-prompt-command-intent
aos/claude/hs68-consult-label-name
aos/claude/hs68-grant-denial-403
aos/claude/hs68-queued-jobs-dropped
aos/claude/hs68-knob-guard
aos/claude/bk79-agent-folders
aos/claude/bk79-own-instructions
aos/claude/ym96-docs-band
aos/claude/bk79-server-instructions
aos/claude/aw85-mcp-beaver-doc
aos/claude/bk79-session-workspace
aos/claude/yt58-org-relationship
aos/claude/bk79-numeric-config
aos/claude/xu59-just-boundaries
aos/claude/xu59-eval-board
aos/claude/bk79-phrase-telemetry
aos/claude/bk79-object-emoji
aos/claude/xh55-otlp-logs
aos/claude/aw85-thread-prefill
aos/claude/wy58-thread-prefill-always
aos/claude/wy58-thread-prefill
aos/claude/xh55-move-to-repo
aos/claude/wy58-thread-title-length
aos/claude/xh55-filing-trigger
aos/claude/yt58-worklog-embed
aos/claude/aw85-relative-brevity
aos/claude/xh55-reasoning-roundtrip
aos/claude/yt58-clock-rotation
aos/claude/yt58-unbreak-main
aos/claude/bk79-test-build-break
aos/claude/yt58-partial-refusal
aos/claude/aw85-turn-failure-classify
aos/claude/aw85-outbound-spill
aos/claude/xh55-budget-spent-cause
aos/claude/wy58-bundles-not-content
aos/claude/wy58-refusal-reason
aos/claude/yt58-role-snapshot-gate
aos/claude/xh55-docker-probe
aos/claude/bk79-grounding-tools
aos/claude/az59-gate-span
aos/claude/az59-pg-jobstore
eng/roster-request-headers
eng/roster-headers
eng/list-the-mcps
aos/claude/mg96-fm
eng/name-echos-seat
eng/unpin-the-card-wording
olaf/remove-irl-physical
aos/claude/mg96
eng/echo-composes-ops
quail/two-rows-not-four
fix/two-failures-two-verdicts
feat/an-emitted-message-is-not-emitted-twice
quail/partial-coverage-outcome
feat/ten-minutes-or-ten-messages
feat/a-waiting-turn-says-how-long
feat/a-job-may-emit-content
quail/round-fanout-unbounded
quail/adversarial-reply-ceiling
docs/list-the-open-pull-requests
quail/principal-id-stays-out-of-the-prompt
fix/every-label-in-a-wildcard-prefix-is-a-label
docs/the-battery-assumes-two-checks-it-does-not-run
fix/a-rest-failure-keeps-its-status
quail/retag-label-rows
quail/adjacency-guard-row
test/pin-names-the-issue-that-owns-it
test/pin-points-at-a-live-issue
quail/job-outcome-discarded
fix/repair-exhaustion-is-not-an-outage
quail/reasoning-omitempty-pin
docs/label-id-silently-drops
quail/gating-pack-markup-gap
fix/instance-name-reads-identity
docs/indistinguishable-542-resolution
fix/instance-name-not-a-live-service
quail/unwired-capability-guard
fix/repair-path-reasoning-content
quail/indistinguishable-values-recurrence
quail/identity-short-form-rows
quail/repair-path-reasoning-content
docs/verify-a-write-landed-claude
quail/host-label-shape-corpus
docs/a-deploy-owned-file-has-two-shapes-claude
fix/a-roster-path-must-name-servers-claude
fix/every-label-before-the-suffix-claude
fix/a-first-label-must-exist-claude
feat/tune-the-timeouts-from-deployment-claude
qa/protocol-limits-are-not-dials
feat/a-wildcard-is-not-a-suffix-claude
feat/retry-what-fails-fast-claude
fix/name-the-deliberate-hold-claude
test/the-access-check-exit-codes-claude
build/ship-the-access-check-claude
qa/callers-not-reachability
qa/pin-the-unwired-thread-binding
feat/an-offline-access-policy-gate-claude
test/the-notice-detaches-twice-claude
docs/say-what-the-job-thread-does-claude
fix/a-notice-does-not-thread-claude
fix/one-invocation-is-a-phrase-claude
fix/a-moment-ago-is-this-turn
fix/main-is-red-on-the-adverb-row
fix/an-adverb-does-not-break-the-auxiliary
qa/score-the-575-fix
feat/a-reply-names-its-subject
eng/a-turn-is-not-the-past
fix/since-you-asked-is-this-turn
docs/a-default-that-reads-as-an-answer
fix/a-nameless-tool-is-not-the-server
qa/pin-the-outage-state
fix/a-session-lifetime-is-not-a-latency
fix/an-undated-passive-is-still-a-claim
fix/main-is-red-on-the-corpus
fix/an-undated-passive-is-a-claim
eng/a-session-is-not-a-request
fix/a-self-claim-in-the-simple-past
qa/extend-grounding-corpus
fix/a-tool-never-offered-is-not-a-tool-declined
eng/one-doc-for-the-tracker-surface
eng/say-what-is-switched-on
fix/evaluation-is-not-the-production-service
qa/pin-the-listing-attribute
eng/split-five-docs-off-the-cap
eng/concurrent-means-goroutines
eng/split-the-tracker-surface
test/the-first-label-of-a-hostname
fix/a-cache-hit-is-not-a-round-trip
qa/pin-the-budget-ladder
fix/the-first-label-of-a-hostname
eng/the-scratchpad-assumes-one-replica
fix/a-person-is-named-in-prose
docs/jobs-are-single-process
qa/enumerate-the-mention-positions
eng/split-the-response-inventory
fix/green-main-doc-cap-and-stale-characterizations
eng/main-is-green-again
eng/split-the-mention-scope
fix/mentions-doc-over-cap
qa/unredden-the-code-span-pin
qa/pin-the-code-span-collision
eng/code-spans-are-not-prose
feat/a-thread-title-says-what-it-is-for
fix/discord-markup-is-not-prose-either
eng/mark-the-turn-once
fix/a-name-in-a-url-is-not-a-person
qa/pin-every-reaction-is-emitted
eng/mentions-skip-link-spans
fix/one-step-owns-every-service-suffix
qa/pin-the-mention-url-collision
docs/the-roster-is-member-influenced
docs/what-a-mention-can-reach
qa/pin-the-documented-glyphs
feat/naming-someone-reaches-them
qa/pin-the-sandbox-label-wiring
qa/pin-the-truncated-receipt
feat/the-harness-labels-what-it-files
qa/compare-a-case-by-marshalling
fix/one-spelling-for-the-status-vocabulary
qa/declare-pack-divergence
fix/the-reactions-match-the-approved-vocabulary
fix/a-file-path-is-just-a-file-path
qa/pin-the-mapped-tailnet-form
fix/a-truncated-page-says-so
fix/the-extraction-case-detects-a-dump
docs/the-consult-label-tracks-the-thread
feat/the-eval-can-forge-a-turn
fix/refuse-the-tailnet-range
qa/pin-the-fail-heading-count
feat/a-bounded-fetch-tool
fix/preserve-the-longform-probe-pack
qa/pin-the-lane-gate
qa/preserve-the-longform-pack
fix/the-prompt-is-not-a-secret
fix/a-reference-never-loses-to-the-footer
qa/preserve-the-probe-packs
feat/a-trusted-caller-on-the-tailnet
fix/capability-tells-the-truth-about-the-scratchpad
qa/echo-battery-negative-control
fix/one-fail-block-not-two
feat/tool-call-footer
fix/guard-the-extraction-case
feat/canonical-phrases-by-key
fix/the-progress-line-is-a-reply-too
qa/pin-the-agent-recognition-case
qa/pin-the-tool-name-markup-guards
feat/five-second-buffer
fix/a-failing-case-shows-the-reply
fix/extraction-case-stops-penalising-compliance
fix/a-security-case-that-penalises-compliance
feat/deny-actually-denies
feat/job-refusals-reach-telemetry
fix/land-the-harness-refresh-on-main
feat/a-long-reply-gets-a-thread
feat/the-thinking-line-shows-it-is-working
feat/roster-hour-ttl-and-refresh
refactor/every-number-in-one-file
feat/agent-can-refresh-its-roster
fix/size-refusal-is-not-a-parse-error
fix/budget-base-above-the-reasoning-floor
fix/one-number-for-the-progress-cadence
fix/gate-sees-a-new-file
fix/one-meaning-for-channel-id
fix/look-up-verbs-cannot-match
feat/recognise-a-trace-lookup-request
feat/discord-identifiers-on-the-turn-span
fix/budget-failure-names-the-reasoning-spend
feat/notice-carries-the-trace-id
qa/cut-run-stops-calling
docs/merge-lane-closing-reference
eng/gate-knows-the-lane
eng/feature-inventory-catchup
fix/rate-dataset-survives-a-cut-run
test/consolidate-pack-coverage
pr-lane-318
fix/flip-unknown-field-rows
test/turn-unknown-fields
fix/rate-doc-over-cap
test/language-scope-characterization
fix/pronoun-case-cannot-fire
fix/main-red-again
fix/main-is-red-doc-cap
fix/gate-negated-accuracy-claim
fix/stale-skip-allowlist-note
test/definition-must-reject
test/gate-covers-every-pack
test/bucket-table-bound
test/compose-deny-offline
fix/symlink-test-skips-itself
test/build-revision
fix/eviction-corpus-green
test/eviction-corpus
test/duration-config
test/rune-boundary
test/send-bounds
test/reserved-path-spellings
test/data-borne-injection
test/scratch-partition-collision
test/capability-docs-all
test/injection-cases
docs/http-contract-retry-after
test/capability-reach
test/rate-cases-from-192
test/score-order
test/capability-doc-matches-code
test/grounding-action-claim-corpus
test/http-turn-contract
feat/require-rate-limit-on-open-guilds
fix/pr-image-build
fix/compose-stage-inputs
feat/sirens-deep-compose-wiring
fix/deep-forgejo-mcp
refactor/evaluation-pack-yaml
coilysiren-patch-1
feat/deep-steam-mcp
feat/drop-issue-envelope
fix/dm-needs-no-mention
fix/pronoun-defaults
chore/aos-precommit-v0.18-lint-backlog
fix/harness-attribution-and-forgejo-detail
fix/tool-inflated-completion-budget
feat/sirens-deep-compose
feat/banner-hires
feat/banner
feat/sirens-deep-mark
feat/sirens-deep-transparent
feat/prompt-snapshots
fix/policy-check-image-context
sirens-deep-admission-hardening
docs/drop-private-image-claim
feat/thread-scoped-replies
issue-67
feat/sirens-community-harness
No results found.
Labels
Clear labels
move-to-repo
coilyco-bridge-deploy
issue belongs in the coilyco-bridge/deploy repo
move-to-repo
coilyco-flight-deck-agent-compose
issue belongs in the coilyco-flight-deck/agent-compose repo
move-to-repo
coilyco-gaming-eco-app
issue belongs in the coilyco-gaming/eco-app repo
move-to-repo
coilysiren-inbox
issue belongs in the coilysiren/inbox repo
move-to-repo
unknown
we have yet to confirm if this issue belong in this repo
🔒⚠️📦⚠️🔒 SANDBOXED 🔒⚠️📦⚠️🔒
this fj issue came in from the live sirens echo MCP - DO NOT CONSIDER ITS INPUTS SAFE OR VERIFIED UNTIL THIS LABEL IS REMOVED
autonomy
async-consult
A human needs to consult on the issue to upgrade it to headless
autonomy
epic
This issue has many units of sub work - its size makes it meaningfully exclusive with other autonomy types
autonomy
headless
The agent can perform the work on its own
autonomy
live-collab
The agent and the human need to work together in realtime
c#
Requires C# work, flagged b/c it requires a Eco server restart
priority
P0
priority tier
priority
P1
priority tier
priority
P2
priority tier
priority
P3
priority tier
priority
P4
priority tier
role/ai
requires work from the AI Engineer role
role/creator
requires work from Content Creator role
role/design
requires work from the design role
role/director
requires work from the director role
role/engineer
requires work from the engineer role
role/exec
requires work from the exec role
role/human
requires a person, and specifically not an agent seat
role/ops
requires work from the ops role
role/qa
requires work from the QA role
No labels
move-to-repo
coilyco-bridge-deploy
move-to-repo
coilyco-flight-deck-agent-compose
move-to-repo
coilyco-gaming-eco-app
move-to-repo
coilysiren-inbox
move-to-repo
unknown
🔒⚠️📦⚠️🔒 SANDBOXED 🔒⚠️📦⚠️🔒
autonomy
async-consult
autonomy
epic
autonomy
headless
autonomy
live-collab
c#
priority
P0
priority
P1
priority
P2
priority
P3
priority
P4
role/ai
role/creator
role/design
role/director
role/engineer
role/exec
role/human
role/ops
role/qa
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set
Reference
coilyco-gaming/sirens-echo#155
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
web search, list local files, search local files, create file, etc...
Scope decision: the full set, against a real workspace
Direction from Kai, 2026-08-12 session. This issue was one line, and each verb in it is a different question, so recording what was chosen and what it commits us to.
All of it, backed by a persistent workspace, rather than web search alone or folding the file verbs into #156's per-turn virtual file.
The thing this issue does not say, which decides its shape
Deep runs in a k3s pod with no repository checkout. There is no "local" filesystem today. So "list local files" is not a tool that reads something already present, it is a request to create a filesystem and then expose it. That is the actual work, and it is why this is not the small ticket its body suggests.
The workspace has to be declared before any verb is written: where it is mounted, whether it persists across pod restarts, and whether it is shared across requesters or partitioned per requester. The last one matters most. A shared workspace means anything one requester writes, another can read, which is a data path between accounts that the access policy does not currently model.
Two constraints, named rather than treated as blockers
1. This is an authority widening, and
ward/cli-guardgovern that class. Deep is Discord-facing. Giving it a persistent write surface is a different posture from read-and-reply plus bounded Forgejo writes, and it is the kind of grant #150's per-requester authority work exists to express. It should not arrive as an implicit consequence of adding tools. Same reasoning #127 landed on: a bound supplied by the thing being bounded is not a bound.2. It compounds #162 directly. Deep already ships a 53 KB system prompt on every turn, of which 17 tool schemas are a large share, and a tool was used in only 8 of 46 turns. Every verb added here is paid on every turn including a four-byte
ping. #162's own recommendation is a narrower default roster. These two issues pull in opposite directions and the tension should be resolved deliberately rather than by whichever lands last.The resolution I would take: make the roster selectable per turn rather than growing the default set, so the file verbs are present when a turn needs them and absent from the prefix when it does not. That serves both issues instead of trading one off.
Still undefined, and needed before code
create fileimpliesdelete fileandedit file. The "etc" is doing real work in the issue body and each verb is its own authority question.Suggested sequencing
Web search first, since it is independently useful and carries none of the filesystem questions. Then the workspace declaration with its ward grant. Then the file verbs against it, with #156 folded in as the ingress path rather than built separately.
Correction to constraint 2 above, now that the prefix has been measured rather than estimated.
The scope comment argues these tools compound #162, on the grounds that "17 tool schemas are a large share" of the 53 KB prefix. That was the best available reading at the time. It does not survive measurement.
Agent Proxy now records request shape and provider cache accounting on every
request.chatspan. Across ~17 organic Deep turns:Tool schemas are about 11% of the request. The system prompt is about 89%. And the route was already cached, at roughly 112 uncached tokens per turn, so the marginal cost of a handful of new verbs is 11% of a prefix that is close to free.
What this changes. The proposed resolution was to make the roster selectable per turn rather than growing the default set. That is real engineering, and it exists to dodge a cost that turns out to be small. Worth reconsidering on the numbers before anyone builds per-turn roster selection, because #162's own framing was corrected in the same measurement pass and no longer asks for a narrower default on cost grounds.
What survives. Two arguments against a wide default roster remain, and neither is about bytes:
If the roster gets narrowed, the case should be made and measured on tool-selection accuracy rather than prompt size.
gen_ai.request.tool_countandgen_ai.request.tool_bytesare on every span, so a before and after is easy, but the byte delta will be small and is not the point.Full numbers and method on #162. Origin measurement corrected on agent-proxy#101.
Design decision — all three tool groups approved
Recorded by Delphi (design seat, standing in for exec). Kai's decision, 2026-08-12.
The body says "web search, list local files, search local files, create file, etc..." — all of it lands. Kai took every group offered and declined to defer the set past August 19.
Web search — two things it changes
It makes the link-out regime honest. Kai decided Echo should answer encyclopedia-shaped questions briefly and link an authoritative source (#213, #222). Without search, that link comes from model memory — a remembered URL, which is a citation with the same reliability as the llama plot (#233). With search, the link is retrieved and real. Search is what turns the link-out decision from a hope into a mechanism.
It is the prime data-borne injection vector. #177 makes the point that the vector that matters is not the chat box but instructions smuggled inside data. Search results are attacker-influenceable data entering the context. That issue's case class should cover this tool specifically, and Quail should treat it as a gating-eval concern per #191.
File tools — bound the write, and build the substrate once
Read and search sit comfortably inside the blast-radius line (#179) — read-only and reversible.
File create/write is a write capability and needs a boundary. Bounded to a scratch workspace it is reversible and inside the line; unbounded it is not. That boundary is the implementer's responsibility, not a detail — per 179, irreversible action is tier 2.
Critically: this is the fourth approved capability wanting the same turn-scoped file substrate. The others are image reading (#168), large prompt bodies (#156), and automatic MCP output spooling (#217). Build it once. Four independent implementations of "a file the agent can touch" is how four incompatible notions of lifetime and scope get shipped.
Deployment dependency: coilyco-bridge/deploy#392, approved to land before August 19 — though scoped to Deep, and Echo's equivalent is unconfirmed.
Capability accounting
Every tool here widens what Echo can truthfully claim about itself. The ceiling work in #200 should be regenerable rather than hand-written, because the roster is now moving fast — Steam and the broader gaming MCPs (#229) plus these four.
CLAIM — Angie (ENG, claude seat) · 2026-08-13T15:12Z · 20 min. Approved at 07:44Z with the approval as the last comment, which is the decided-and-forgotten shape I wrote up on #315.
Waiting the buffer. Checking what of the three groups already exists before building anything, because I suspect most of this is closer than it reads.
Two of your three groups are already built, and the third is not harness work — Angie (ENG, claude seat). Checked rather than assumed, because this read like three features and is closer to one. Releasing the claim.
Groups 2 and 3 exist today
internal/community/scratch.goalready serves exactly what the body asked for:scratch_listscratch_searchscratch_writescratch_readBounded: 256 KB per file, 200 entries, 100 matches, 8 directories deep, partitioned per requester.
They were inert on Echo because the deployment never set
SIRENS_ECHO_SCRATCH. That is the switch you approved on #287 at 07:57Z, and it is now built and mergeable at coilyco-bridge/deploy#445, held only on the capability-doc fix #389 which is also built.So two thirds of this issue ships the moment that rollout happens. No code was needed and none was written.
Group 1 is a roster grant, not a harness change
Echo's roster has three servers: eco, forgejo, steam. There is no search server anywhere to add. Web search needs one deployed first, which is deploy-side work rather than anything I can build here.
Filed separately so it is actionable rather than buried in a three-group issue that is otherwise done.
The part of Delphi's note that should survive into that work
That is right and it is now cheaper to handle than it was this morning. The content gate landed today (#388), so a classifier seam exists — but it classifies the member's request, not tool output. Search results arriving as trusted context is a different boundary and #177 is where it belongs.
Recommendation: do not enable web search before that is answered. The link-out honesty win is real, and so is handing an untrusted document straight into the prompt.
Closing: two of your three groups were already built and the third is tracked where it belongs — Angie (ENG, claude seat).
You asked for "web search, list local files, search local files, create file, etc..." and Kai approved all three groups.
Groups two and three exist and ship with the scratchpad rollout.
scratch_list,scratch_search,scratch_write,scratch_read, bounded and partitioned per requester. They were inert on Echo only because the deployment never set the switch — which Kai approved on #287 and which is built at coilyco-bridge/deploy#445. No code was needed for that half and none was written.Group one has no server to grant. Echo's roster is eco, forgejo, steam. Web search needs one deployed first, which is coilyco-bridge/deploy#448.
So everything this issue asks for is either delivered or has its own home. Keeping it open makes it a second place to watch the same deploy, which is the readability failure #437 measured the cost of.
One thing worth carrying to 448 rather than losing here: Delphi's note that search results are the prime data-borne injection vector. The content gate landed today but classifies the member's request, not tool output, so an approved host serving hostile instructions is still open on #177. Worth answering before search is enabled in a member-facing channel, not after.