Skip to content
902 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step1//! The MCP server's tools: a few resource tools, each with an `action`.
2//!
3//! Every operation is one action of one tool. A call is dispatched to the
4//! operation it names, so permissions, the audit log, billing and outcomes
5//! are exactly those of the REST API. A token sees only the actions its
6//! scopes allow, and a tool none of whose actions it may use is not listed.
7//!
8//! The listed input schema is one flat object: `action`, then every field
9//! any of its actions takes. Which fields each action needs is in the
10//! `action` field's description and checked on every call. Claude's API,
11//! and so most MCP clients, refuse a tool whose input schema has `oneOf`
12//! at its top level, so the schema keyed by action, with each action's
13//! required fields, is [`discriminated`], published on the server's card
14//! and in the docs.
15
16use g1t_contracts::credentials::NEVER;
17use g1t_contracts::identity::AgentScope;
18use g1t_contracts::scopes::{Level, NO_SCOPE, TokenAccess, scope_for};
19use serde_json::{Map, Value, json};
20
21use crate::operations::Op;
Checks: statuses and check runs on every commit, for CI and integrations22use crate::checks::ChecksOp;
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge23use crate::rules::RulesOp;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar24use crate::security::SecurityOp;
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step25
26pub struct Action {
27 pub name: &'static str,
28 pub op: Op,
29 /// One line, for the `action` field's description.
30 pub summary: &'static str,
31}
32
33pub struct Tool {
34 pub name: &'static str,
35 pub title: &'static str,
36 /// What it is for, in a sentence or two.
37 pub description: &'static str,
38 pub actions: &'static [Action],
39 /// The action a call without one runs.
40 pub default_action: Option<&'static str>,
41}
42
43const fn a(name: &'static str, op: Op, summary: &'static str) -> Action {
44 Action { name, op, summary }
45}
46
47pub const TOOLS: &[Tool] = &[
48 Tool {
49 name: "search",
50 title: "Search",
51 description: "Find things. `code` (the default) searches all of g1t you can see: repositories, code, issues, pull requests and people, with qualifiers like repo:owner/name, language:rust, is:issue. `context` searches one workspace's catalog, docs, issues and memory by meaning.",
52 default_action: Some("code"),
53 actions: &[
54 a("code", Op::Search, "Search all of g1t: repositories, code, issues, pull requests, people"),
55 a("context", Op::SearchContext, "Search a workspace's context hub by meaning"),
56 a("entity", Op::GetEntity, "One catalog entry and its relations"),
57 a("ticket", Op::GetContext, "A Jira, Linear or Sentry item the work refers to, as it is now"),
58 ],
59 },
60 Tool {
61 name: "repository",
62 title: "Repositories",
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge63 description: "Repositories: find, read and create them, change their settings and rulesets (what may happen to branches and tags, and what a pull request needs to merge), check their CODEOWNERS file, manage their labels and milestones, and see and dismiss their security alerts (secrets and vulnerable dependencies). Name one as \"owner/name\". Deleting, transferring and changing visibility need `confirm`.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step64 default_action: None,
65 actions: &[
66 a("list", Op::ListRepos, "Repositories you can see"),
67 a("get", Op::GetRepo, "One repository"),
68 a("create", Op::CreateRepo, "Create one, empty or copied from a public git URL"),
69 a("update", Op::UpdateRepo, "Change description, website, topics, default branch, protection"),
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge70 a("get_settings", Op::GetRepoSettings, "How pull requests merge, and the default branch's protection as its rules stack"),
71 a("update_settings", Op::UpdateRepoSettings, "Change how pull requests merge and the default branch protection ruleset"),
72 a("check_names", Op::ListCheckNames, "Check names reported lately, to require in a ruleset"),
73 a("list_rulesets", Op::Rules(RulesOp::ListRepoRulesets), "Its rulesets, and its workspace's that hold in it"),
74 a("get_ruleset", Op::Rules(RulesOp::GetRepoRuleset), "One ruleset"),
75 a("create_ruleset", Op::Rules(RulesOp::CreateRepoRuleset), "Create a ruleset for its branches or tags"),
76 a("update_ruleset", Op::Rules(RulesOp::UpdateRepoRuleset), "Change a ruleset"),
77 a("delete_ruleset", Op::Rules(RulesOp::DeleteRepoRuleset), "Delete a ruleset"),
78 a("branch_rules", Op::Rules(RulesOp::GetBranchRules), "Every rule that holds for a branch or tag, and where it comes from"),
79 a("rule_evaluations", Op::Rules(RulesOp::ListRuleEvaluations), "How its rules judged pushes and merges, with insights"),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar80 a("codeowners", Op::GetCodeownersErrors, "Problems in its CODEOWNERS file, by line"),
81 a("list_labels", Op::ListLabels, "Labels, with colors and how many issues and pull requests carry each"),
82 a("create_label", Op::CreateLabel, "Create a label"),
83 a("update_label", Op::UpdateLabel, "Rename a label or change its color or description"),
84 a("delete_label", Op::DeleteLabel, "Delete a label, from everything that carries it"),
85 a("add_default_labels", Op::AddDefaultLabels, "Add the default labels it is missing"),
86 a("list_milestones", Op::ListMilestones, "Milestones, with progress and due dates"),
87 a("get_milestone", Op::GetMilestone, "One milestone with its issues and pull requests"),
88 a("create_milestone", Op::CreateMilestone, "Create a milestone"),
89 a("update_milestone", Op::UpdateMilestone, "Change a milestone's title, description, due date or state"),
90 a("delete_milestone", Op::DeleteMilestone, "Delete a milestone"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step91 a("list_events", Op::ListEvents, "Timeline: pushes, issues, pull requests, comments"),
92 a("rename_branch", Op::RenameBranch, "Rename a branch"),
93 a("rename", Op::RenameRepo, "Rename it; old addresses redirect"),
94 a("transfer", Op::TransferRepo, "Move it to another workspace you own"),
95 a("archive", Op::ArchiveRepo, "Make it read-only"),
96 a("unarchive", Op::UnarchiveRepo, "Make it writable again"),
97 a("set_visibility", Op::SetRepoVisibility, "Make it public or private"),
98 a("delete", Op::DeleteRepo, "Delete it; restorable for 30 days"),
99 a("list_deleted", Op::ListDeletedRepos, "A workspace's deleted repositories"),
100 a("restore", Op::RestoreRepo, "Restore a deleted one"),
101 a("purge", Op::PurgeRepo, "Remove a deleted one for good"),
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily102 a("security_alerts", Op::ListSecurityAlerts, "Secret and dependency alerts, filtered by state"),
103 a("dismiss_alert", Op::DismissSecurityAlert, "Dismiss an alert with a reason"),
104 a("reopen_alert", Op::ReopenSecurityAlert, "Reopen a dismissed alert"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step105 ],
106 },
107 Tool {
108 name: "issue",
109 title: "Issues",
110 description: "Issues: what should change. Read one before working on it to see the pull requests already made for it. Issues and pull requests share numbers; `comment` works on either.",
111 default_action: None,
112 actions: &[
113 a("list", Op::ListIssues, "Issues on a repository, newest first"),
Fast pages, required checks on the branch, self-hosted runners, honest incidents114 a("get", Op::GetIssue, "One issue with comments and its pull requests"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step115 a("create", Op::CreateIssue, "Open an issue"),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar116 a("update", Op::UpdateIssue, "Change title, body, labels, milestone or assignees"),
117 a("labels", Op::ListIssueLabels, "The labels an issue or pull request carries"),
118 a("add_labels", Op::AddIssueLabels, "Add labels to an issue or pull request"),
119 a("set_labels", Op::SetIssueLabels, "Replace the labels of an issue or pull request"),
120 a("remove_labels", Op::RemoveIssueLabels, "Take labels off an issue or pull request"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step121 a("close", Op::CloseIssue, "Close it without a pull request"),
122 a("reopen", Op::ReopenIssue, "Reopen it"),
123 a("comment", Op::AddComment, "Comment on an issue or pull request; path and line for one line of a change"),
124 a("import", Op::ImportIssue, "Open an issue from a Jira, Linear or Sentry item"),
125 ],
126 },
127 Tool {
128 name: "pull_request",
129 title: "Pull requests",
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar130 description: "Pull requests: start a change for an issue, record your session, mark it ready, ask people and teams to review, review and merge. Read `overlaps` and `behind` on `get` before going far, and `code_owners` for whose approval it needs.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step131 default_action: None,
132 actions: &[
133 a("list", Op::ListPullRequests, "Pull requests on a repository, newest first"),
Fast pages, required checks on the branch, self-hosted runners, honest incidents134 a("get", Op::GetPullRequest, "Status, checks and required checks, reviews, overlaps, whether it is behind"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step135 a("changes", Op::GetPullRequestChanges, "Files and line-by-line diff"),
136 a("create", Op::CreatePullRequest, "Start a draft with its own fork to push to, or open one from a pushed branch"),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar137 a("update", Op::UpdatePullRequest, "Change its base branch, labels, milestone, assignees or reviewers"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step138 a("record_session", Op::RecordSession, "Append prompt, reasoning and tool entries to its session"),
139 a("read_session", Op::ReadSession, "Its recorded session"),
140 a("ready", Op::MarkPullRequestReady, "Mark a draft ready, with a summary"),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar141 a("request_reviewers", Op::RequestReviewers, "Ask people or teams to review it"),
142 a("remove_requested_reviewers", Op::RemoveRequestedReviewers, "Stop asking people or teams to review it"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step143 a("review", Op::ReviewPullRequest, "Approve or request changes"),
144 a("close", Op::ClosePullRequest, "Close without merging"),
145 a("merge", Op::MergePullRequest, "Land it, or join the merge queue"),
146 a("merge_queue", Op::GetMergeQueue, "The repository's merge queue"),
147 ],
148 },
149 Tool {
150 name: "agent",
151 title: "g1t agents",
152 description: "Put g1t's agent to work and talk to it. One agent per issue; to do more at once, use more issues. Starting an agent uses the workspace's money.",
153 default_action: None,
154 actions: &[
155 a("delegate", Op::Delegate, "Open an issue and put an agent on it in one step"),
156 a("assign", Op::AssignIssue, "Put an agent on an existing issue"),
157 a("message", Op::MessageAgent, "Tell the agent on a pull request something, or ask another agent"),
158 a("answer", Op::AnswerMessage, "Answer a question or handoff sent to you"),
159 a("take_messages", Op::TakeMessages, "For a g1t agent: messages not seen yet"),
160 ],
161 },
162 Tool {
163 name: "plan",
164 title: "Plans",
Fast pages, required checks on the branch, self-hosted runners, honest incidents165 description: "Turn an outcome into issues: an agent proposes them with what done means and their dependencies; nothing opens until you apply the plan.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step166 default_action: None,
167 actions: &[
168 a("create", Op::PlanWork, "Ask an agent for a plan; read it with get until ready"),
169 a("get", Op::GetPlan, "A plan and the issues it proposes"),
170 a("apply", Op::ApplyPlan, "Open its issues; with assign, agents start in dependency order"),
171 ],
172 },
173 Tool {
174 name: "memory",
175 title: "Memory",
176 description: "What the project and its workspace remember for the next agent: how to build, conventions, decisions, traps. Recall before you start; remember one short fact at a time, never a secret.",
177 default_action: None,
178 actions: &[
179 a("recall", Op::Recall, "Search memory, or list it all"),
180 a("remember", Op::Remember, "Save one fact"),
181 ],
182 },
183 Tool {
184 name: "workflow",
185 title: "Workflows",
Checks: statuses and check runs on every commit, for CI and integrations186 description: "GitHub Actions workflows from .g1t/workflows: their runs, jobs and logs, and running, cancelling or rerunning them. Checks on commits: statuses, check runs (a g1t Actions job is one) and check suites, to read where a commit stands or report on it from CI or an integration. Also the self-hosted runners they run on: a workspace's (`workspace`) or a repository's own (`repo`), their groups, and where agent work runs.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step187 default_action: None,
188 actions: &[
189 a("list", Op::ListWorkflows, "Workflows on the default branch"),
190 a("list_runs", Op::ListWorkflowRuns, "Runs, newest first"),
191 a("get_run", Op::GetWorkflowRun, "One run with its jobs and steps"),
192 a("job_logs", Op::GetJobLogs, "A job's log after a sequence number"),
193 a("dispatch", Op::DispatchWorkflow, "Run a workflow_dispatch workflow"),
194 a("cancel", Op::CancelWorkflowRun, "Cancel a run"),
195 a("rerun", Op::RerunWorkflowRun, "Run a finished run again"),
196 a("update", Op::UpdateWorkflow, "Turn a workflow on or off"),
Checks: statuses and check runs on every commit, for CI and integrations197 a("combined_status", Op::Checks(ChecksOp::GetCombinedStatus), "A commit's statuses and the state they add up to"),
198 a("list_statuses", Op::Checks(ChecksOp::ListCommitStatuses), "A commit's statuses, newest first"),
199 a("set_status", Op::Checks(ChecksOp::CreateCommitStatus), "Set a status on a commit"),
200 a("list_check_runs", Op::Checks(ChecksOp::ListCheckRunsForRef), "A commit's check runs, g1t Actions jobs included"),
201 a("get_check_run", Op::Checks(ChecksOp::GetCheckRun), "One check run with its report"),
202 a("check_run_annotations", Op::Checks(ChecksOp::ListCheckRunAnnotations), "What a check run says about lines of files"),
203 a("create_check_run", Op::Checks(ChecksOp::CreateCheckRun), "Report a check run on a commit"),
204 a("update_check_run", Op::Checks(ChecksOp::UpdateCheckRun), "Move a check run on, complete it, add annotations"),
205 a("rerequest_check_run", Op::Checks(ChecksOp::RerequestCheckRun), "Ask for a check run to run again"),
206 a("list_check_suites", Op::Checks(ChecksOp::ListCheckSuitesForRef), "A commit's check suites, one per reporter or workflow run"),
207 a("get_check_suite", Op::Checks(ChecksOp::GetCheckSuite), "One check suite"),
208 a("rerequest_check_suite", Op::Checks(ChecksOp::RerequestCheckSuite), "Ask for a check suite to run again"),
Fast pages, required checks on the branch, self-hosted runners, honest incidents209 a("list_runners", Op::ListRunners, "Self-hosted runners, with status, labels and what each is doing"),
210 a("create_runner_token", Op::CreateRunnerRegistrationToken, "A one-hour token for g1t-runner register"),
211 a("remove_runner", Op::RemoveRunner, "Remove a self-hosted runner"),
212 a("list_runner_groups", Op::ListRunnerGroups, "A workspace's runner groups"),
213 a("create_runner_group", Op::CreateRunnerGroup, "Make a group, for some repositories"),
214 a("update_runner_group", Op::UpdateRunnerGroup, "Rename a group or change its repositories"),
215 a("delete_runner_group", Op::DeleteRunnerGroup, "Delete a group; its runners join the default"),
216 a("get_runner_settings", Op::GetRunnerSettings, "Where agent work runs; whether forks may use runners"),
217 a("update_runner_settings", Op::UpdateRunnerSettings, "Change them"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step218 ],
219 },
220 Tool {
221 name: "secret",
222 title: "Secrets and variables",
223 description: "A repository's or workspace's secrets and variables, read by workflows and deployments. Secret values are never returned.",
224 default_action: None,
225 actions: &[
226 a("list_secrets", Op::ListActionsSecrets, "Secrets, without values"),
227 a("set_secret", Op::SetActionsSecret, "Add or change a secret"),
228 a("delete_secret", Op::DeleteActionsSecret, "Remove a secret"),
229 a("list_variables", Op::ListActionsVariables, "Variables, with values"),
230 a("set_variable", Op::SetActionsVariable, "Add or change a variable"),
231 a("delete_variable", Op::DeleteActionsVariable, "Remove a variable"),
232 ],
233 },
234 Tool {
235 name: "webhook",
236 title: "Webhooks",
237 description: "HTTPS addresses sent signed events as they happen, for a repository or a whole workspace.",
238 default_action: None,
239 actions: &[
240 a("list", Op::ListWebhooks, "Webhooks, without secrets"),
241 a("create", Op::CreateWebhook, "Register one; a ping is sent"),
242 a("update", Op::UpdateWebhook, "Change address, events or active"),
243 a("delete", Op::DeleteWebhook, "Remove one"),
244 a("ping", Op::PingWebhook, "Send a ping"),
245 a("list_deliveries", Op::ListWebhookDeliveries, "Latest deliveries"),
246 a("redeliver", Op::RedeliverWebhook, "Send a delivery again"),
247 ],
248 },
249 Tool {
250 name: "access",
251 title: "Who has access",
252 description: "Who has access to a repository and with which role (read, triage, write, maintain, admin), outside collaborators, and a workspace's base permission.",
253 default_action: None,
254 actions: &[
255 a("list_collaborators", Op::ListCollaborators, "Everyone with a role, and pending invitations"),
256 a("get_permission", Op::GetCollaboratorPermission, "One person's role and capabilities"),
257 a("add_collaborator", Op::AddCollaborator, "Give someone a role, by username or email"),
258 a("update_collaborator", Op::UpdateCollaborator, "Change a direct role"),
259 a("remove_collaborator", Op::RemoveCollaborator, "Take away a direct role"),
260 a("list_invitations", Op::ListRepoInvitations, "Pending invitations to a repository"),
261 a("revoke_invitation", Op::RevokeRepoInvitation, "Withdraw one"),
262 a("set_base_permission", Op::SetBasePermission, "What every member gets on each repository"),
263 a("list_outside_collaborators", Op::ListOutsideCollaborators, "People with roles who are not members"),
264 ],
265 },
266 Tool {
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar267 name: "team",
268 title: "Teams",
269 description: "Teams: groups of a workspace's members, given roles on repositories together, mentioned as @workspace/team and asked to review together. Name one by `workspace` and its slug (`team`). Any member may create a team; the workspace's owners and the team's maintainers manage it. A secret team is seen only by its people and the owners.",
270 default_action: None,
271 actions: &[
272 a("list", Op::ListTeams, "A workspace's teams you can see"),
273 a("get", Op::GetTeam, "One team"),
274 a("create", Op::CreateTeam, "Create a team; you become its maintainer"),
275 a("update", Op::UpdateTeam, "Change its name, slug, description, visibility, parent or notifications"),
276 a("delete", Op::DeleteTeam, "Delete it; its child teams move up"),
277 a("list_members", Op::ListTeamMembers, "Its people and their roles, child teams' with include_child_teams"),
278 a("set_member", Op::SetTeamMember, "Add a member of the workspace, or change their role"),
279 a("remove_member", Op::RemoveTeamMember, "Take someone out of it"),
280 a("list_child_teams", Op::ListChildTeams, "The teams nested under it"),
281 a("list_repos", Op::ListTeamRepos, "The repositories it has a role on"),
282 a("set_repo", Op::SetTeamRepo, "Give it a role on a repository"),
283 a("remove_repo", Op::RemoveTeamRepo, "Take its role on a repository away"),
284 a("set_review_assignment", Op::SetTeamReviewAssignment, "Whom it picks when asked to review"),
285 a("list_user_teams", Op::ListUserTeams, "The teams someone is in"),
286 ],
287 },
288 Tool {
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step289 name: "workspace",
290 title: "Workspaces",
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge291 description: "Workspaces own repositories (g1t.sh/{workspace}/{repo}): create, update or delete one, invite members, connect integrations and model providers, set rulesets that hold across its repositories, and keep your own pinned projects at the top of its sidebar.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step292 default_action: None,
293 actions: &[
Merge branch 'worktree-agent-ad7c6d88d93adc817'294 a("get", Op::GetWorkspace, "A workspace's details and settings"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step295 a("create", Op::CreateWorkspace, "Create a workspace"),
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member296 a("delete", Op::DeleteWorkspace, "Delete a workspace and everything in it (support can restore it for 30 days)"),
Merge branch 'worktree-agent-ad7c6d88d93adc817'297 a("update", Op::UpdateWorkspace, "Change its name, description, base permission or who may create teams"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step298 a("list_invites", Op::ListWorkspaceInvites, "Its invites"),
299 a("invite_member", Op::InviteMember, "Invite an email address"),
300 a("revoke_invite", Op::RevokeWorkspaceInvite, "Revoke a pending invite"),
301 a("list_integrations", Op::ListIntegrations, "Model providers, alert sources, trackers"),
302 a("connect_integration", Op::ConnectIntegration, "Connect one"),
303 a("disconnect_integration", Op::DisconnectIntegration, "Remove one"),
304 a("test_integration", Op::TestIntegration, "Check its credentials"),
305 a("get_model_routes", Op::GetModelRoutes, "Where each kind of work's model requests go"),
306 a("set_model_routes", Op::SetModelRoutes, "Replace them"),
API: pinned projects over REST and MCP307 a("list_pinned_projects", Op::ListPinnedProjects, "Your pinned projects in it, in your order"),
308 a("pin_project", Op::PinProject, "Pin a project, at a position or the end"),
309 a("unpin_project", Op::UnpinProject, "Unpin a project"),
310 a("reorder_pinned_projects", Op::ReorderPinnedProjects, "Put your pins in a new order"),
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge311 a("list_rulesets", Op::Rules(RulesOp::ListWorkspaceRulesets), "Its rulesets, which hold across its repositories"),
312 a("get_ruleset", Op::Rules(RulesOp::GetWorkspaceRuleset), "One of its rulesets"),
313 a("create_ruleset", Op::Rules(RulesOp::CreateWorkspaceRuleset), "Create a ruleset for some or all of its repositories"),
314 a("update_ruleset", Op::Rules(RulesOp::UpdateWorkspaceRuleset), "Change one of its rulesets"),
315 a("delete_ruleset", Op::Rules(RulesOp::DeleteWorkspaceRuleset), "Delete one of its rulesets"),
316 a("rule_evaluations", Op::Rules(RulesOp::ListWorkspaceRuleEvaluations), "How rules judged changes across its repositories"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step317 ],
318 },
319 Tool {
Usage, Billing settings and prepaid AI credit; fixes from the UX audit320 name: "billing",
321 title: "Billing",
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens322 description: "A workspace's billing: its usage by product, project and day, its budget (the monthly spend limit, alerts and whether usage pauses at it), its AI credit, its invoices, and its AI Gateway requests. Amounts are whole millionths of a dollar (`_micros`), or cents (`_cents`) where named. Members read it; changing the budget and buying credit are for owners, as people, and never for g1t's agents.",
Usage, Billing settings and prepaid AI credit; fixes from the UX audit323 default_action: Some("usage"),
324 actions: &[
325 a("usage", Op::GetUsage, "Usage over a range of days, by product, meter, project and day, and what paid for it"),
326 a("budget", Op::GetBudget, "The monthly spend limit, what was spent, alerts and whether usage pauses at the limit"),
327 a("set_budget", Op::SetBudget, "Change the spend limit, alerts, pausing or the alert webhook"),
328 a("ai_credit", Op::GetAiCredit, "AI credit left, its grants, auto-reload and how to buy more"),
329 a("buy_ai_credit", Op::BuyAiCredit, "A payment page to buy AI credit, for a person to open"),
330 a("invoices", Op::ListInvoices, "Every invoice, the itemised usage invoices, and the next one so far"),
331 a("billing_details", Op::GetBillingDetails, "Who invoices are made out to and the payment method on file"),
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens332 a("gateway_requests", Op::ListGatewayRequests, "Recent AI Gateway requests: model, tokens, cost, status and token"),
Usage, Billing settings and prepaid AI credit; fixes from the UX audit333 ],
334 },
335 Tool {
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar336 name: "security",
337 title: "Security",
338 description: "A repository's security: secret scanning alerts and push protection bypasses, custom secret patterns, code scanning alerts and SARIF uploads, vulnerability alerts, the dependency graph and its SBOM, dependency review, settings, and a workspace's overview. Fix an alert with g1t. Findings are shown to those who can change the code only. Give `repo` (owner/name), or `workspace` for lists across one.",
339 default_action: Some("secret_alerts"),
340 actions: &[
341 a("secret_alerts", Op::Security(SecurityOp::ListSecretAlerts), "Secret scanning alerts; by state, secret_type, validity, bypassed"),
342 a("secret_alert", Op::Security(SecurityOp::GetSecretAlert), "One secret alert, with where it was found and its bypass requests"),
343 a("update_secret_alert", Op::Security(SecurityOp::UpdateSecretAlert), "Dismiss a secret alert with a reason, or reopen it"),
344 a("secret_locations", Op::Security(SecurityOp::ListSecretLocations), "Every file, line and commit a secret is in"),
345 a("bypass", Op::Security(SecurityOp::BypassPushProtection), "Push past push protection with a reason, or ask to"),
346 a("check_validity", Op::Security(SecurityOp::CheckSecretValidity), "Ask a secret's issuer whether it still works"),
347 a("bypass_requests", Op::Security(SecurityOp::ListBypassRequests), "A workspace's push protection bypass requests"),
348 a("review_bypass", Op::Security(SecurityOp::ReviewBypassRequest), "Approve, deny or cancel a bypass request"),
349 a("patterns", Op::Security(SecurityOp::ListCustomPatterns), "Custom secret patterns of a repository or workspace"),
350 a("create_pattern", Op::Security(SecurityOp::CreateCustomPattern), "Create a custom secret pattern, as a draft or published"),
351 a("update_pattern", Op::Security(SecurityOp::UpdateCustomPattern), "Change, publish or unpublish a custom pattern"),
352 a("delete_pattern", Op::Security(SecurityOp::DeleteCustomPattern), "Delete a custom pattern"),
353 a("dry_run_pattern", Op::Security(SecurityOp::DryRunCustomPattern), "Run a pattern over the default branch without saving it"),
354 a("code_alerts", Op::Security(SecurityOp::ListCodeAlerts), "Code scanning alerts; by state, severity, tool, rule_id"),
355 a("code_alert", Op::Security(SecurityOp::GetCodeAlert), "One code scanning alert by number"),
356 a("update_code_alert", Op::Security(SecurityOp::UpdateCodeAlert), "Dismiss a code scanning alert with a reason, or reopen it"),
357 a("analyses", Op::Security(SecurityOp::ListAnalyses), "Code scanning analyses, newest first"),
358 a("upload_sarif", Op::Security(SecurityOp::UploadSarif), "Upload a SARIF file, gzipped and base64-encoded"),
359 a("sarif_upload", Op::Security(SecurityOp::GetSarifUpload), "Whether a SARIF upload was read, and its analyses"),
360 a("vulnerability_alerts", Op::Security(SecurityOp::ListVulnerabilityAlerts), "Vulnerable dependencies; by state, severity, ecosystem, package"),
361 a("vulnerability_alert", Op::Security(SecurityOp::GetVulnerabilityAlert), "One vulnerability alert"),
362 a("update_vulnerability_alert", Op::Security(SecurityOp::UpdateVulnerabilityAlert), "Dismiss a vulnerability alert with a reason, or reopen it"),
363 a("fix", Op::Security(SecurityOp::FixAlert), "Put g1t on an issue to fix an alert"),
364 a("dependency_graph", Op::Security(SecurityOp::GetDependencyGraph), "Every package the lockfiles resolve, direct or transitive"),
365 a("sbom", Op::Security(SecurityOp::GetSbom), "The dependency graph as an SPDX 2.3 document"),
366 a("compare_dependencies", Op::Security(SecurityOp::CompareDependencies), "What changes in dependencies between base...head"),
367 a("settings", Op::Security(SecurityOp::GetSettings), "A repository's security settings"),
368 a("update_settings", Op::Security(SecurityOp::UpdateSettings), "Change when checks fail and dependency review's policy"),
369 a("workspace_settings", Op::Security(SecurityOp::GetWorkspaceSettings), "A workspace's delegated bypass and validity checks"),
370 a("update_workspace_settings", Op::Security(SecurityOp::UpdateWorkspaceSettings), "Turn delegated bypass or validity checks on or off"),
371 a("overview", Op::Security(SecurityOp::GetOverview), "A workspace's alerts, trends and coverage"),
372 ],
373 },
374 Tool {
API: notifications over REST and MCP, with notifications scopes375 name: "notifications",
376 title: "Notifications",
377 description: "Your inbox: what needs you, and what you follow. One thread per issue, pull request, workflow or deployment, with why you were told (`reason`): an agent waiting on you, a review asked of you, an assignment, a mention, your work's checks, or what you subscribe to and watch. Mark threads read or done once handled, and choose what you hear of with subscribe, unsubscribe and watch. Your own: a personal token.",
378 default_action: Some("list"),
379 actions: &[
380 a("list", Op::ListNotifications, "Unread threads, latest first; all, a view, a reason, a repository"),
381 a("get", Op::GetNotificationThread, "One thread with its recent activity and your subscription"),
382 a("mark_read", Op::MarkThreadRead, "Mark a thread read, or unread"),
383 a("mark_all_read", Op::MarkNotificationsRead, "Mark everything read up to a time, or one repository's"),
384 a("done", Op::MarkThreadDone, "Mark a thread done; new activity brings it back"),
385 a("save", Op::SaveThread, "Save a thread, or unsave it"),
386 a("snooze", Op::SnoozeThread, "Snooze a thread until a time, or bring it back"),
387 a("subscription", Op::GetThreadSubscription, "Your subscription to an issue or pull request"),
388 a("subscribe", Op::SetThreadSubscription, "Subscribe to an issue or pull request, or ignore it"),
389 a("unsubscribe", Op::DeleteThreadSubscription, "Unsubscribe until you comment or are mentioned"),
390 a("watching", Op::GetRepoSubscription, "How you watch a repository"),
391 a("watch", Op::SetRepoSubscription, "Watch a repository: participating, all, ignore or custom"),
392 a("unwatch", Op::DeleteRepoSubscription, "Stop watching a repository"),
393 a("watched", Op::ListWatchedRepos, "Repositories you watch other than the default way"),
394 ],
395 },
396 Tool {
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step397 name: "account",
398 title: "Your account",
399 description: "Who this token acts as and its workspaces (`whoami`), your email addresses, your invites, and invitations to repositories waiting for you.",
400 default_action: Some("whoami"),
401 actions: &[
402 a("whoami", Op::Whoami, "Who the token acts as, and its workspaces"),
403 a("list_emails", Op::ListEmails, "Your addresses"),
404 a("add_email", Op::AddEmail, "Add an address"),
405 a("remove_email", Op::RemoveEmail, "Remove an address"),
406 a("update_email_settings", Op::UpdateEmailSettings, "Primary, backup and privacy"),
407 a("list_invites", Op::ListInvites, "Your invites to g1t"),
408 a("create_invite", Op::CreateInvite, "Make an invite"),
409 a("revoke_invite", Op::RevokeInvite, "Revoke one"),
410 a("list_repository_invitations", Op::ListMyRepoInvitations, "Invitations to repositories for you"),
411 a("accept_repository_invitation", Op::AcceptRepoInvitation, "Accept one"),
412 a("decline_repository_invitation", Op::DeclineRepoInvitation, "Decline one"),
413 ],
414 },
415];
416
417/// Operations that cannot be undone, or reach beyond g1t's own records:
418/// clients ask before running a tool that has any of them.
419fn destructive(op: Op) -> bool {
420 matches!(
421 op,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar422 Op::Security(SecurityOp::DeleteCustomPattern | SecurityOp::BypassPushProtection)
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge423 | Op::Rules(RulesOp::DeleteRepoRuleset | RulesOp::DeleteWorkspaceRuleset)
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar424 | Op::DeleteWorkspace
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily425 | Op::UpdateWorkspace
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step426 | Op::DeleteRepo
427 | Op::PurgeRepo
428 | Op::TransferRepo
429 | Op::SetRepoVisibility
430 | Op::RemoveEmail
431 | Op::RemoveCollaborator
432 | Op::DisconnectIntegration
433 | Op::DeleteWebhook
434 | Op::DeleteActionsSecret
435 | Op::DeleteActionsVariable
436 | Op::SetActionsSecret
437 | Op::SetActionsVariable
438 | Op::SetModelRoutes
439 | Op::SetBasePermission
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar440 | Op::DeleteTeam
441 | Op::RemoveTeamRepo
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step442 | Op::MergePullRequest
Fast pages, required checks on the branch, self-hosted runners, honest incidents443 | Op::RemoveRunner
444 | Op::DeleteRunnerGroup
445 | Op::UpdateRunnerSettings
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step446 )
447}
448
449/// Whether an operation only reads.
450pub fn reads_only(op: Op) -> bool {
451 NO_SCOPE.contains(&op.name())
452 || scope_for(op.name()).is_some_and(|scope| scope.level() == Level::Read)
453}
454
455/// What decides which actions a caller sees.
456pub enum Gate<'a> {
457 /// No limit beyond the person's own role.
458 Everything,
459 /// A g1t agent's token: the operations its run lists.
460 Agent(&'a AgentScope),
461 /// An access token with scopes.
462 Token(&'a TokenAccess),
463}
464
465impl Gate<'_> {
466 pub fn allows(&self, op: Op) -> bool {
467 match self {
468 Gate::Everything => true,
469 Gate::Agent(scope) => op.allowed_by(scope) && !NEVER.contains(&op.name()),
470 Gate::Token(access) => {
471 if NO_SCOPE.contains(&op.name()) {
472 return true;
473 }
474 match scope_for(op.name()) {
475 Some(scope) => access.allows(scope),
476 None => access.scopes.is_none(),
477 }
478 }
479 }
480 }
481}
482
483impl Tool {
484 pub fn by_name(name: &str) -> Option<&'static Tool> {
485 TOOLS.iter().find(|tool| tool.name == name)
486 }
487
488 pub fn action(&self, name: &str) -> Option<&'static Action> {
489 // The tools are 'static; find through TOOLS to keep the lifetime.
490 TOOLS
491 .iter()
492 .find(|tool| tool.name == self.name)
493 .and_then(|tool| tool.actions.iter().find(|action| action.name == name))
494 }
495
496 pub fn visible(&self, gate: &Gate) -> Vec<&'static Action> {
497 TOOLS
498 .iter()
499 .find(|tool| tool.name == self.name)
500 .map(|tool| tool.actions.iter().filter(|action| gate.allows(action.op)).collect())
501 .unwrap_or_default()
502 }
503
504 /// The flat input schema of the actions given.
505 pub fn input_schema(&self, actions: &[&Action]) -> Value {
506 let mut properties = Map::new();
507 let lines: Vec<String> = actions
508 .iter()
509 .map(|action| {
510 let required: Vec<String> = action.op.required();
511 if required.is_empty() {
512 format!("{}: {}.", action.name, action.summary)
513 } else {
514 format!("{} ({}): {}.", action.name, required.join(", "), action.summary)
515 }
516 })
517 .collect();
518 let mut action_schema = json!({
519 "type": "string",
520 "enum": actions.iter().map(|action| action.name).collect::<Vec<_>>(),
521 "description": lines.join("\n"),
522 });
523 if let Some(default) = self.default_action.filter(|name| actions.iter().any(|action| action.name == *name)) {
524 action_schema["default"] = json!(default);
525 }
526 properties.insert("action".to_owned(), action_schema);
527 for action in actions {
528 for (name, schema) in action.op.properties() {
529 merge_property(&mut properties, name, schema);
530 }
531 }
532 let mut required = vec![];
533 if self.default_action.is_none() {
534 required.push("action");
535 }
536 let mut schema = json!({ "type": "object", "properties": properties });
537 if !required.is_empty() {
538 schema["required"] = json!(required);
539 }
540 schema
541 }
542
543 /// The input schema keyed by action: one `oneOf` branch per action,
544 /// each with its own fields and the ones it needs.
545 pub fn discriminated(&self, actions: &[&Action]) -> Value {
546 let branches: Vec<Value> = actions
547 .iter()
548 .map(|action| {
549 let mut properties = Map::new();
550 properties.insert("action".to_owned(), json!({ "const": action.name }));
551 properties.extend(action.op.properties());
552 let mut required = vec![Value::String("action".to_owned())];
553 // The default action may leave `action` out.
554 if self.default_action == Some(action.name) {
555 required.clear();
556 }
557 required.extend(action.op.required().into_iter().map(Value::String));
558 json!({
559 "title": action.name,
560 "description": action.summary,
561 "type": "object",
562 "properties": properties,
563 "required": required,
564 })
565 })
566 .collect();
567 json!({ "type": "object", "oneOf": branches })
568 }
569
570 /// MCP's hints about the actions given: whether the tool only reads,
571 /// whether it can destroy something, and whether calling it twice is
572 /// the same as once.
573 pub fn annotations(&self, actions: &[&Action]) -> Value {
574 let read_only = actions.iter().all(|action| reads_only(action.op));
575 json!({
576 "title": self.title,
577 "readOnlyHint": read_only,
578 "destructiveHint": !read_only && actions.iter().any(|action| destructive(action.op)),
579 "idempotentHint": read_only,
580 "openWorldHint": false,
581 })
582 }
583
584 /// The tool as `tools/list` gives it, for a caller behind `gate`, or
585 /// `None` when it may use none of its actions.
586 pub fn listed(&self, gate: &Gate) -> Option<Value> {
587 let actions = self.visible(gate);
588 if actions.is_empty() {
589 return None;
590 }
591 Some(json!({
592 "name": self.name,
593 "title": self.title,
594 "description": self.description,
595 "inputSchema": self.input_schema(&actions),
596 "annotations": self.annotations(&actions),
597 }))
598 }
599}
600
601/// Adds a property to a tool's flat schema. The first action to use a name
602/// describes it; a later one with other allowed values adds them.
603fn merge_property(properties: &mut Map<String, Value>, name: String, schema: Value) {
604 match properties.get_mut(&name) {
605 None => {
606 properties.insert(name, schema);
607 }
608 Some(existing) => {
609 if let (Some(Value::Array(had)), Some(Value::Array(more))) =
610 (existing.get("enum").cloned(), schema.get("enum"))
611 {
612 let mut merged = had;
613 for value in more {
614 if !merged.contains(value) {
615 merged.push(value.clone());
616 }
617 }
618 existing["enum"] = Value::Array(merged);
619 }
620 // Different kinds of value under one name: say less, accept both.
621 if existing.get("type") != schema.get("type")
622 && let Some(fields) = existing.as_object_mut()
623 {
624 fields.remove("type");
625 fields.remove("items");
626 }
627 }
628 }
629}
630
631/// What a call to a tool runs: the operation its action names, or why not.
632pub fn resolve(tool: &Tool, arguments: &Value) -> Result<Op, String> {
633 let names = || {
634 tool.actions
635 .iter()
636 .map(|action| action.name)
637 .collect::<Vec<_>>()
638 .join(", ")
639 };
640 let Some(name) = arguments["action"].as_str().or(tool.default_action) else {
641 return Err(format!("Give an action: one of {}.", names()));
642 };
643 let Some(action) = tool.action(name) else {
644 return Err(format!("{} has no action {name}. Its actions: {}.", tool.name, names()));
645 };
646 let missing: Vec<String> = action
647 .op
648 .required()
649 .into_iter()
650 .filter(|field| arguments.get(field).is_none_or(Value::is_null))
651 .collect();
652 if !missing.is_empty() {
653 return Err(format!("{}.{name} needs {}.", tool.name, missing.join(", ")));
654 }
655 Ok(action.op)
656}
657
658#[cfg(test)]
659mod tests {
660 use super::*;
661 use g1t_contracts::scopes::{Preset, Scope};
662
663 fn listed(gate: &Gate) -> Vec<Value> {
664 TOOLS.iter().filter_map(|tool| tool.listed(gate)).collect()
665 }
666
667 fn token(scopes: Option<Vec<Scope>>) -> TokenAccess {
668 TokenAccess {
669 token_id: "tok_1".to_owned(),
670 scopes: scopes.map(|scopes| scopes.iter().map(|scope| scope.as_str().to_owned()).collect()),
671 legacy: false,
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens672 name: None,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step673 }
674 }
675
676 #[test]
677 fn every_operation_is_exactly_one_action_of_one_tool() {
678 for op in Op::ALL {
679 let count = TOOLS
680 .iter()
681 .flat_map(|tool| tool.actions.iter())
682 .filter(|action| action.op == op)
683 .count();
684 assert_eq!(count, 1, "{} is {count} actions", op.name());
685 }
686 for tool in TOOLS {
687 let mut names = std::collections::HashSet::new();
688 for action in tool.actions {
689 assert!(names.insert(action.name), "{}.{} twice", tool.name, action.name);
690 }
691 if let Some(default) = tool.default_action {
692 assert!(tool.action(default).is_some(), "{}", tool.name);
693 }
694 }
Usage, Billing settings and prepaid AI credit; fixes from the UX audit695 assert!(TOOLS.len() <= 17, "{} tools", TOOLS.len());
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step696 }
697
698 #[test]
699 fn every_operation_needs_exactly_one_scope_or_none() {
700 use g1t_contracts::scopes::OPERATIONS;
701 for op in Op::ALL {
702 let mapped = OPERATIONS.iter().filter(|(name, _)| *name == op.name()).count();
703 let free = NO_SCOPE.contains(&op.name());
704 assert_eq!(mapped + usize::from(free), 1, "{}", op.name());
705 }
706 for (name, _) in OPERATIONS {
707 assert!(Op::by_name(name).is_some(), "{name} is not an operation");
708 }
709 }
710
711 #[test]
712 fn each_tool_schema_is_valid_with_one_branch_per_action() {
713 for tool in TOOLS {
714 let actions: Vec<&Action> = tool.actions.iter().collect();
715 let flat = tool.input_schema(&actions);
716 assert_eq!(flat["type"], "object");
717 assert!(flat.get("oneOf").is_none(), "no oneOf at the top level");
718 let listed: Vec<&str> = flat["properties"]["action"]["enum"]
719 .as_array()
720 .unwrap()
721 .iter()
722 .map(|name| name.as_str().unwrap())
723 .collect();
724 assert_eq!(listed, tool.actions.iter().map(|action| action.name).collect::<Vec<_>>());
725 for action in tool.actions {
726 for field in action.op.required() {
727 assert!(flat["properties"].get(&field).is_some(), "{}.{}: {field}", tool.name, action.name);
728 }
729 }
730 let keyed = tool.discriminated(&actions);
731 let branches = keyed["oneOf"].as_array().unwrap();
732 assert_eq!(branches.len(), tool.actions.len());
733 for (branch, action) in branches.iter().zip(tool.actions) {
734 assert_eq!(branch["properties"]["action"]["const"], action.name);
735 for field in branch["required"].as_array().unwrap() {
736 assert!(branch["properties"].get(field.as_str().unwrap()).is_some(), "{}.{}: {field}", tool.name, action.name);
737 }
738 }
739 // A well-formed JSON Schema object throughout.
740 let text = serde_json::to_string(&flat).unwrap();
741 assert!(serde_json::from_str::<Value>(&text).is_ok());
742 }
743 }
744
745 #[test]
746 fn a_read_only_token_sees_read_actions_only() {
747 let access = token(Preset::ReadOnly.scopes());
748 let gate = Gate::Token(&access);
749 for tool in TOOLS {
750 for action in tool.visible(&gate) {
751 assert!(reads_only(action.op), "{}.{}", tool.name, action.name);
752 }
753 }
754 let tools = listed(&gate);
755 for tool in &tools {
756 assert_eq!(tool["annotations"]["readOnlyHint"], true, "{}", tool["name"]);
757 assert_eq!(tool["annotations"]["destructiveHint"], false);
758 }
759 let issue = tools.iter().find(|tool| tool["name"] == "issue").unwrap();
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar760 assert_eq!(issue["inputSchema"]["properties"]["action"]["enum"], json!(["list", "get", "labels"]));
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step761 // Nothing of the agent tool is a read.
762 assert!(!tools.iter().any(|tool| tool["name"] == "agent"));
763 }
764
765 #[test]
766 fn a_narrow_token_sees_only_its_tools() {
767 let access = token(Some(vec![Scope::IssuesWrite]));
768 let names: Vec<Value> = listed(&Gate::Token(&access)).into_iter().map(|tool| tool["name"].clone()).collect();
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar769 // Labels and milestones are the repository's, managed with issues:write.
770 assert_eq!(names, vec![json!("repository"), json!("issue"), json!("plan"), json!("account")]);
API: notifications over REST and MCP, with notifications scopes771 // Notifications are a resource of their own: reading them lists
772 // only what reads.
773 let reader = token(Some(vec![Scope::NotificationsRead]));
774 let tools = listed(&Gate::Token(&reader));
775 let notifications = tools.iter().find(|tool| tool["name"] == "notifications").unwrap();
776 assert_eq!(
777 notifications["inputSchema"]["properties"]["action"]["enum"],
778 json!(["list", "get", "subscription", "watching", "watched"])
779 );
780 assert_eq!(notifications["annotations"]["readOnlyHint"], true);
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step781 let full = token(None);
782 assert_eq!(listed(&Gate::Token(&full)).len(), TOOLS.len());
783 assert_eq!(listed(&Gate::Everything).len(), TOOLS.len());
784 }
785
786 #[test]
787 fn a_tool_that_can_destroy_says_so() {
788 let tools = listed(&Gate::Everything);
789 let repository = tools.iter().find(|tool| tool["name"] == "repository").unwrap();
790 assert_eq!(repository["annotations"]["destructiveHint"], true);
791 assert_eq!(repository["annotations"]["readOnlyHint"], false);
792 let memory = tools.iter().find(|tool| tool["name"] == "memory").unwrap();
793 assert_eq!(memory["annotations"]["destructiveHint"], false);
794 }
795
796 #[test]
797 fn calls_resolve_to_their_operation_or_say_what_is_missing() {
798 let issue = Tool::by_name("issue").unwrap();
799 assert_eq!(resolve(issue, &json!({ "action": "get", "repo": "a/b", "number": 1 })), Ok(Op::GetIssue));
800 assert_eq!(resolve(issue, &json!({ "action": "get", "repo": "a/b" })), Err("issue.get needs number.".to_owned()));
801 assert!(resolve(issue, &json!({})).unwrap_err().starts_with("Give an action"));
802 assert!(resolve(issue, &json!({ "action": "explode" })).unwrap_err().contains("no action explode"));
803 let search = Tool::by_name("search").unwrap();
804 assert_eq!(resolve(search, &json!({ "query": "x" })), Ok(Op::Search));
805 let account = Tool::by_name("account").unwrap();
806 assert_eq!(resolve(account, &json!({})), Ok(Op::Whoami));
807 }
808
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar809 #[test]
810 fn teams_are_one_tool_and_a_workspace_reader_sees_only_its_reads() {
811 let team = Tool::by_name("team").unwrap();
812 let names: Vec<&str> = team.actions.iter().map(|action| action.name).collect();
813 assert_eq!(
814 names,
815 [
816 "list",
817 "get",
818 "create",
819 "update",
820 "delete",
821 "list_members",
822 "set_member",
823 "remove_member",
824 "list_child_teams",
825 "list_repos",
826 "set_repo",
827 "remove_repo",
828 "set_review_assignment",
829 "list_user_teams",
830 ]
831 );
832 let reader = token(Some(vec![Scope::WorkspaceRead]));
833 let tools = listed(&Gate::Token(&reader));
834 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
835 assert_eq!(
836 listed_team["inputSchema"]["properties"]["action"]["enum"],
837 json!(["list", "get", "list_members", "list_child_teams", "list_repos", "list_user_teams"])
838 );
839 assert_eq!(listed_team["annotations"]["readOnlyHint"], true);
840 // A team's role on a repository is who has access.
841 let admin = token(Some(vec![Scope::WorkspaceAdmin]));
842 let tools = listed(&Gate::Token(&admin));
843 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
844 let actions = listed_team["inputSchema"]["properties"]["action"]["enum"].as_array().unwrap();
845 assert!(actions.contains(&json!("set_review_assignment")) && !actions.contains(&json!("set_repo")));
846 let access = token(Some(vec![Scope::AccessAdmin]));
847 let tools = listed(&Gate::Token(&access));
848 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
849 assert_eq!(listed_team["inputSchema"]["properties"]["action"]["enum"], json!(["set_repo", "remove_repo"]));
850 // Both kinds of role a schema names are offered.
851 let roles = &listed(&Gate::Everything).into_iter().find(|tool| tool["name"] == "team").unwrap()["inputSchema"]
852 ["properties"]["role"]["enum"];
853 for role in ["member", "maintainer", "read", "admin"] {
854 assert!(roles.as_array().unwrap().contains(&json!(role)), "{role}");
855 }
856 assert_eq!(
857 resolve(team, &json!({ "action": "set_repo", "workspace": "acme", "team": "backend", "repo": "rocket" })),
858 Err("team.set_repo needs role.".to_owned())
859 );
860 }
861
862 #[test]
863 fn reviewers_and_code_owners_are_actions_of_their_tools() {
864 let pull = Tool::by_name("pull_request").unwrap();
865 assert_eq!(
866 resolve(pull, &json!({ "action": "request_reviewers", "repo": "a/b", "number": 1, "team_reviewers": ["backend"] })),
867 Ok(Op::RequestReviewers)
868 );
869 assert_eq!(pull.action("remove_requested_reviewers").map(|action| action.op), Some(Op::RemoveRequestedReviewers));
870 let repository = Tool::by_name("repository").unwrap();
871 assert_eq!(resolve(repository, &json!({ "action": "codeowners", "repo": "a/b" })), Ok(Op::GetCodeownersErrors));
872 assert!(reads_only(Op::GetCodeownersErrors));
873 assert!(!reads_only(Op::RequestReviewers));
874 }
875
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step876 /// How much smaller `tools/list` is than one tool per operation. Run
877 /// with `--nocapture` to see the numbers.
878 #[test]
879 fn the_tool_list_is_much_smaller_than_one_tool_per_operation() {
880 let before: Vec<Value> = Op::ALL
881 .into_iter()
882 .map(|op| json!({ "name": op.name(), "description": op.description(), "inputSchema": op.input() }))
883 .collect();
884 let after = listed(&Gate::Everything);
885 let before_bytes = serde_json::to_string(&json!({ "tools": before })).unwrap().len();
886 let after_bytes = serde_json::to_string(&json!({ "tools": after })).unwrap().len();
887 let agent = token(Preset::Agent.scopes());
888 let agent_bytes = serde_json::to_string(&json!({ "tools": listed(&Gate::Token(&agent)) })).unwrap().len();
889 let read = token(Preset::ReadOnly.scopes());
890 let read_bytes = serde_json::to_string(&json!({ "tools": listed(&Gate::Token(&read)) })).unwrap().len();
891 println!(
892 "tools/list: before {} tools, {before_bytes} bytes (~{} tokens); after {} tools, {after_bytes} bytes (~{} tokens); agent preset {agent_bytes} bytes (~{} tokens); read only {read_bytes} bytes (~{} tokens)",
893 before.len(),
894 before_bytes / 4,
895 after.len(),
896 after_bytes / 4,
897 agent_bytes / 4,
898 read_bytes / 4,
899 );
900 assert!(after_bytes * 2 < before_bytes, "{after_bytes} vs {before_bytes}");
901 }
902}

This file's history is long; its oldest lines are credited to the oldest commit read.