Tools
What the agent can do — read and write files, run commands, search the web, handle documents — and how you set the boundaries.
Overview
The agent works through tools — reading and writing files, running commands, searching content, browsing the web, handling documents. You never pick tools manually; the agent chooses them based on the task.
Tool categories
Files · Code
| Tool | Purpose |
|---|---|
| Read file | View file contents |
| Edit file | Modify code or text |
| Create file | Create and write new files |
| List directory | Browse the directory structure |
| Content search | Find specific text inside files |
| Filename search | Find files by pattern |
Shell commands
- Run command — synchronous execution with timeout and working-directory support
- Background tasks — long-running operations (e.g.
npm run dev,docker build,watchmode) run in the background; you can inspect output or stop them at any time
Web · Browser
- Web fetch — retrieve a page's main content
- Web search — search the internet
- Browser automation — drive a browser: click links, fill forms, take screenshots, and more (see browser automation)
- Canvas management — manage what's shown in the right-pane canvas
Version control
Git tools: diffs, logs, blame, commits, branch management, staging, and more.
Documents
- Spreadsheets — read and write spreadsheet content
- Word — edit document paragraphs and styles
- PDF — extract PDF content
Collaboration & planning
| Tool | Purpose |
|---|---|
| Skill launcher | Run built-in or custom skills |
| Delayed wake-up | Schedule the agent to resume at a given time (see scheduled tasks) |
| User consultation | The agent asks you when a decision is needed |
| Plan management | Maintain TODO lists and progress (see planning) |
| Scheduled tasks | Create, list, and delete scheduled tasks |
Adding more tools
Beyond the built-ins, you can connect external services via MCP. MCP tools are named mcp__<server>__<tool>; once connected, the agent discovers and uses them on its own.
Execution control
The approvalMode setting controls when the agent needs your confirmation:
| Mode | Behavior |
|---|---|
auto (default) | Only critical operations (deleting system or home directories, formatting disks, writing shell startup files, SQL DROP, and so on) ask for confirmation; everything else runs automatically |
manual | Everything other than reading (writing files, deleting, shell commands, and so on) asks for confirmation |
dangerous | Nothing asks for confirmation, including irreversible operations. Use only in disposable environments |
In manual, an identical (command, directory) pair won't prompt twice within a session; critical operations prompt every time. In dangerous, no confirmation is ever shown.
Safety
- Commands that don't return promptly move to the background automatically, so the conversation never stalls
- An optional OS-level sandbox isolates commands the agent runs
See the security notes.
Platform availability
Files, commands, Git, web fetch and search, slides, and image generation work in both the CLI and the desktop app. The visual set — browser automation, the right-pane canvas, spreadsheets, and Word — is desktop-only.

