Skip to content

g1t/apps/api/src/tools.rs

872 lines48,400 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step1//! The MCP server's tools: a few resource tools, each with an `action`.
2//!
3//! Every operation is one action of one tool. A call is dispatched to the
4//! operation it names, so permissions, the audit log, billing and outcomes
5//! are exactly those of the REST API. A token sees only the actions its
6//! scopes allow, and a tool none of whose actions it may use is not listed.
7//!
8//! The listed input schema is one flat object: `action`, then every field
9//! any of its actions takes. Which fields each action needs is in the
10//! `action` field's description and checked on every call. Claude's API,
11//! and so most MCP clients, refuse a tool whose input schema has `oneOf`
12//! at its top level, so the schema keyed by action, with each action's
13//! required fields, is [`discriminated`], published on the server's card
14//! and in the docs.
15
16use g1t_contracts::credentials::NEVER;
17use g1t_contracts::identity::AgentScope;
18use g1t_contracts::scopes::{Level, NO_SCOPE, TokenAccess, scope_for};
19use serde_json::{Map, Value, json};
20
21use crate::operations::Op;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar22use crate::security::SecurityOp;
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step23
24pub struct Action {
25 pub name: &'static str,
26 pub op: Op,
27 /// One line, for the `action` field's description.
28 pub summary: &'static str,
29}
30
31pub struct Tool {
32 pub name: &'static str,
33 pub title: &'static str,
34 /// What it is for, in a sentence or two.
35 pub description: &'static str,
36 pub actions: &'static [Action],
37 /// The action a call without one runs.
38 pub default_action: Option<&'static str>,
39}
40
41const fn a(name: &'static str, op: Op, summary: &'static str) -> Action {
42 Action { name, op, summary }
43}
44
45pub const TOOLS: &[Tool] = &[
46 Tool {
47 name: "search",
48 title: "Search",
49 description: "Find things. `code` (the default) searches all of g1t you can see: repositories, code, issues, pull requests and people, with qualifiers like repo:owner/name, language:rust, is:issue. `context` searches one workspace's catalog, docs, issues and memory by meaning.",
50 default_action: Some("code"),
51 actions: &[
52 a("code", Op::Search, "Search all of g1t: repositories, code, issues, pull requests, people"),
53 a("context", Op::SearchContext, "Search a workspace's context hub by meaning"),
54 a("entity", Op::GetEntity, "One catalog entry and its relations"),
55 a("ticket", Op::GetContext, "A Jira, Linear or Sentry item the work refers to, as it is now"),
56 ],
57 },
58 Tool {
59 name: "repository",
60 title: "Repositories",
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar61 description: "Repositories: find, read and create them, change their settings, check their CODEOWNERS file, manage their labels and milestones, and see and dismiss their security alerts (secrets and vulnerable dependencies). Name one as \"owner/name\". Deleting, transferring and changing visibility need `confirm`.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step62 default_action: None,
63 actions: &[
64 a("list", Op::ListRepos, "Repositories you can see"),
65 a("get", Op::GetRepo, "One repository"),
66 a("create", Op::CreateRepo, "Create one, empty or copied from a public git URL"),
67 a("update", Op::UpdateRepo, "Change description, website, topics, default branch, protection"),
Fast pages, required checks on the branch, self-hosted runners, honest incidents68 a("get_settings", Op::GetRepoSettings, "Branch protection: required checks, approvals, how pull requests merge"),
69 a("update_settings", Op::UpdateRepoSettings, "Change branch protection and how pull requests merge"),
70 a("check_names", Op::ListCheckNames, "Check names reported lately, to require on the default branch"),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar71 a("codeowners", Op::GetCodeownersErrors, "Problems in its CODEOWNERS file, by line"),
72 a("list_labels", Op::ListLabels, "Labels, with colors and how many issues and pull requests carry each"),
73 a("create_label", Op::CreateLabel, "Create a label"),
74 a("update_label", Op::UpdateLabel, "Rename a label or change its color or description"),
75 a("delete_label", Op::DeleteLabel, "Delete a label, from everything that carries it"),
76 a("add_default_labels", Op::AddDefaultLabels, "Add the default labels it is missing"),
77 a("list_milestones", Op::ListMilestones, "Milestones, with progress and due dates"),
78 a("get_milestone", Op::GetMilestone, "One milestone with its issues and pull requests"),
79 a("create_milestone", Op::CreateMilestone, "Create a milestone"),
80 a("update_milestone", Op::UpdateMilestone, "Change a milestone's title, description, due date or state"),
81 a("delete_milestone", Op::DeleteMilestone, "Delete a milestone"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step82 a("list_events", Op::ListEvents, "Timeline: pushes, issues, pull requests, comments"),
83 a("rename_branch", Op::RenameBranch, "Rename a branch"),
84 a("rename", Op::RenameRepo, "Rename it; old addresses redirect"),
85 a("transfer", Op::TransferRepo, "Move it to another workspace you own"),
86 a("archive", Op::ArchiveRepo, "Make it read-only"),
87 a("unarchive", Op::UnarchiveRepo, "Make it writable again"),
88 a("set_visibility", Op::SetRepoVisibility, "Make it public or private"),
89 a("delete", Op::DeleteRepo, "Delete it; restorable for 30 days"),
90 a("list_deleted", Op::ListDeletedRepos, "A workspace's deleted repositories"),
91 a("restore", Op::RestoreRepo, "Restore a deleted one"),
92 a("purge", Op::PurgeRepo, "Remove a deleted one for good"),
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily93 a("security_alerts", Op::ListSecurityAlerts, "Secret and dependency alerts, filtered by state"),
94 a("dismiss_alert", Op::DismissSecurityAlert, "Dismiss an alert with a reason"),
95 a("reopen_alert", Op::ReopenSecurityAlert, "Reopen a dismissed alert"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step96 ],
97 },
98 Tool {
99 name: "issue",
100 title: "Issues",
101 description: "Issues: what should change. Read one before working on it to see the pull requests already made for it. Issues and pull requests share numbers; `comment` works on either.",
102 default_action: None,
103 actions: &[
104 a("list", Op::ListIssues, "Issues on a repository, newest first"),
Fast pages, required checks on the branch, self-hosted runners, honest incidents105 a("get", Op::GetIssue, "One issue with comments and its pull requests"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step106 a("create", Op::CreateIssue, "Open an issue"),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar107 a("update", Op::UpdateIssue, "Change title, body, labels, milestone or assignees"),
108 a("labels", Op::ListIssueLabels, "The labels an issue or pull request carries"),
109 a("add_labels", Op::AddIssueLabels, "Add labels to an issue or pull request"),
110 a("set_labels", Op::SetIssueLabels, "Replace the labels of an issue or pull request"),
111 a("remove_labels", Op::RemoveIssueLabels, "Take labels off an issue or pull request"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step112 a("close", Op::CloseIssue, "Close it without a pull request"),
113 a("reopen", Op::ReopenIssue, "Reopen it"),
114 a("comment", Op::AddComment, "Comment on an issue or pull request; path and line for one line of a change"),
115 a("import", Op::ImportIssue, "Open an issue from a Jira, Linear or Sentry item"),
116 ],
117 },
118 Tool {
119 name: "pull_request",
120 title: "Pull requests",
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar121 description: "Pull requests: start a change for an issue, record your session, mark it ready, ask people and teams to review, review and merge. Read `overlaps` and `behind` on `get` before going far, and `code_owners` for whose approval it needs.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step122 default_action: None,
123 actions: &[
124 a("list", Op::ListPullRequests, "Pull requests on a repository, newest first"),
Fast pages, required checks on the branch, self-hosted runners, honest incidents125 a("get", Op::GetPullRequest, "Status, checks and required checks, reviews, overlaps, whether it is behind"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step126 a("changes", Op::GetPullRequestChanges, "Files and line-by-line diff"),
127 a("create", Op::CreatePullRequest, "Start a draft with its own fork to push to, or open one from a pushed branch"),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar128 a("update", Op::UpdatePullRequest, "Change its base branch, labels, milestone, assignees or reviewers"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step129 a("record_session", Op::RecordSession, "Append prompt, reasoning and tool entries to its session"),
130 a("read_session", Op::ReadSession, "Its recorded session"),
131 a("ready", Op::MarkPullRequestReady, "Mark a draft ready, with a summary"),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar132 a("request_reviewers", Op::RequestReviewers, "Ask people or teams to review it"),
133 a("remove_requested_reviewers", Op::RemoveRequestedReviewers, "Stop asking people or teams to review it"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step134 a("review", Op::ReviewPullRequest, "Approve or request changes"),
135 a("close", Op::ClosePullRequest, "Close without merging"),
136 a("merge", Op::MergePullRequest, "Land it, or join the merge queue"),
137 a("merge_queue", Op::GetMergeQueue, "The repository's merge queue"),
138 ],
139 },
140 Tool {
141 name: "agent",
142 title: "g1t agents",
143 description: "Put g1t's agent to work and talk to it. One agent per issue; to do more at once, use more issues. Starting an agent uses the workspace's money.",
144 default_action: None,
145 actions: &[
146 a("delegate", Op::Delegate, "Open an issue and put an agent on it in one step"),
147 a("assign", Op::AssignIssue, "Put an agent on an existing issue"),
148 a("message", Op::MessageAgent, "Tell the agent on a pull request something, or ask another agent"),
149 a("answer", Op::AnswerMessage, "Answer a question or handoff sent to you"),
150 a("take_messages", Op::TakeMessages, "For a g1t agent: messages not seen yet"),
151 ],
152 },
153 Tool {
154 name: "plan",
155 title: "Plans",
Fast pages, required checks on the branch, self-hosted runners, honest incidents156 description: "Turn an outcome into issues: an agent proposes them with what done means and their dependencies; nothing opens until you apply the plan.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step157 default_action: None,
158 actions: &[
159 a("create", Op::PlanWork, "Ask an agent for a plan; read it with get until ready"),
160 a("get", Op::GetPlan, "A plan and the issues it proposes"),
161 a("apply", Op::ApplyPlan, "Open its issues; with assign, agents start in dependency order"),
162 ],
163 },
164 Tool {
165 name: "memory",
166 title: "Memory",
167 description: "What the project and its workspace remember for the next agent: how to build, conventions, decisions, traps. Recall before you start; remember one short fact at a time, never a secret.",
168 default_action: None,
169 actions: &[
170 a("recall", Op::Recall, "Search memory, or list it all"),
171 a("remember", Op::Remember, "Save one fact"),
172 ],
173 },
174 Tool {
175 name: "workflow",
176 title: "Workflows",
Fast pages, required checks on the branch, self-hosted runners, honest incidents177 description: "GitHub Actions workflows from .g1t/workflows: their runs, jobs and logs, and running, cancelling or rerunning them. Also the self-hosted runners they run on: a workspace's (`workspace`) or a repository's own (`repo`), their groups, and where agent work runs.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step178 default_action: None,
179 actions: &[
180 a("list", Op::ListWorkflows, "Workflows on the default branch"),
181 a("list_runs", Op::ListWorkflowRuns, "Runs, newest first"),
182 a("get_run", Op::GetWorkflowRun, "One run with its jobs and steps"),
183 a("job_logs", Op::GetJobLogs, "A job's log after a sequence number"),
184 a("dispatch", Op::DispatchWorkflow, "Run a workflow_dispatch workflow"),
185 a("cancel", Op::CancelWorkflowRun, "Cancel a run"),
186 a("rerun", Op::RerunWorkflowRun, "Run a finished run again"),
187 a("update", Op::UpdateWorkflow, "Turn a workflow on or off"),
Fast pages, required checks on the branch, self-hosted runners, honest incidents188 a("list_runners", Op::ListRunners, "Self-hosted runners, with status, labels and what each is doing"),
189 a("create_runner_token", Op::CreateRunnerRegistrationToken, "A one-hour token for g1t-runner register"),
190 a("remove_runner", Op::RemoveRunner, "Remove a self-hosted runner"),
191 a("list_runner_groups", Op::ListRunnerGroups, "A workspace's runner groups"),
192 a("create_runner_group", Op::CreateRunnerGroup, "Make a group, for some repositories"),
193 a("update_runner_group", Op::UpdateRunnerGroup, "Rename a group or change its repositories"),
194 a("delete_runner_group", Op::DeleteRunnerGroup, "Delete a group; its runners join the default"),
195 a("get_runner_settings", Op::GetRunnerSettings, "Where agent work runs; whether forks may use runners"),
196 a("update_runner_settings", Op::UpdateRunnerSettings, "Change them"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step197 ],
198 },
199 Tool {
200 name: "secret",
201 title: "Secrets and variables",
202 description: "A repository's or workspace's secrets and variables, read by workflows and deployments. Secret values are never returned.",
203 default_action: None,
204 actions: &[
205 a("list_secrets", Op::ListActionsSecrets, "Secrets, without values"),
206 a("set_secret", Op::SetActionsSecret, "Add or change a secret"),
207 a("delete_secret", Op::DeleteActionsSecret, "Remove a secret"),
208 a("list_variables", Op::ListActionsVariables, "Variables, with values"),
209 a("set_variable", Op::SetActionsVariable, "Add or change a variable"),
210 a("delete_variable", Op::DeleteActionsVariable, "Remove a variable"),
211 ],
212 },
213 Tool {
214 name: "webhook",
215 title: "Webhooks",
216 description: "HTTPS addresses sent signed events as they happen, for a repository or a whole workspace.",
217 default_action: None,
218 actions: &[
219 a("list", Op::ListWebhooks, "Webhooks, without secrets"),
220 a("create", Op::CreateWebhook, "Register one; a ping is sent"),
221 a("update", Op::UpdateWebhook, "Change address, events or active"),
222 a("delete", Op::DeleteWebhook, "Remove one"),
223 a("ping", Op::PingWebhook, "Send a ping"),
224 a("list_deliveries", Op::ListWebhookDeliveries, "Latest deliveries"),
225 a("redeliver", Op::RedeliverWebhook, "Send a delivery again"),
226 ],
227 },
228 Tool {
229 name: "access",
230 title: "Who has access",
231 description: "Who has access to a repository and with which role (read, triage, write, maintain, admin), outside collaborators, and a workspace's base permission.",
232 default_action: None,
233 actions: &[
234 a("list_collaborators", Op::ListCollaborators, "Everyone with a role, and pending invitations"),
235 a("get_permission", Op::GetCollaboratorPermission, "One person's role and capabilities"),
236 a("add_collaborator", Op::AddCollaborator, "Give someone a role, by username or email"),
237 a("update_collaborator", Op::UpdateCollaborator, "Change a direct role"),
238 a("remove_collaborator", Op::RemoveCollaborator, "Take away a direct role"),
239 a("list_invitations", Op::ListRepoInvitations, "Pending invitations to a repository"),
240 a("revoke_invitation", Op::RevokeRepoInvitation, "Withdraw one"),
241 a("set_base_permission", Op::SetBasePermission, "What every member gets on each repository"),
242 a("list_outside_collaborators", Op::ListOutsideCollaborators, "People with roles who are not members"),
243 ],
244 },
245 Tool {
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar246 name: "team",
247 title: "Teams",
248 description: "Teams: groups of a workspace's members, given roles on repositories together, mentioned as @workspace/team and asked to review together. Name one by `workspace` and its slug (`team`). Any member may create a team; the workspace's owners and the team's maintainers manage it. A secret team is seen only by its people and the owners.",
249 default_action: None,
250 actions: &[
251 a("list", Op::ListTeams, "A workspace's teams you can see"),
252 a("get", Op::GetTeam, "One team"),
253 a("create", Op::CreateTeam, "Create a team; you become its maintainer"),
254 a("update", Op::UpdateTeam, "Change its name, slug, description, visibility, parent or notifications"),
255 a("delete", Op::DeleteTeam, "Delete it; its child teams move up"),
256 a("list_members", Op::ListTeamMembers, "Its people and their roles, child teams' with include_child_teams"),
257 a("set_member", Op::SetTeamMember, "Add a member of the workspace, or change their role"),
258 a("remove_member", Op::RemoveTeamMember, "Take someone out of it"),
259 a("list_child_teams", Op::ListChildTeams, "The teams nested under it"),
260 a("list_repos", Op::ListTeamRepos, "The repositories it has a role on"),
261 a("set_repo", Op::SetTeamRepo, "Give it a role on a repository"),
262 a("remove_repo", Op::RemoveTeamRepo, "Take its role on a repository away"),
263 a("set_review_assignment", Op::SetTeamReviewAssignment, "Whom it picks when asked to review"),
264 a("list_user_teams", Op::ListUserTeams, "The teams someone is in"),
265 ],
266 },
267 Tool {
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step268 name: "workspace",
269 title: "Workspaces",
API: pinned projects over REST and MCP270 description: "Workspaces own repositories (g1t.sh/{workspace}/{repo}): create, update or delete one, invite members, connect integrations and model providers, and keep your own pinned projects at the top of its sidebar.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step271 default_action: None,
272 actions: &[
Merge branch 'worktree-agent-ad7c6d88d93adc817'273 a("get", Op::GetWorkspace, "A workspace's details and settings"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step274 a("create", Op::CreateWorkspace, "Create a workspace"),
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member275 a("delete", Op::DeleteWorkspace, "Delete a workspace and everything in it (support can restore it for 30 days)"),
Merge branch 'worktree-agent-ad7c6d88d93adc817'276 a("update", Op::UpdateWorkspace, "Change its name, description, base permission or who may create teams"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step277 a("list_invites", Op::ListWorkspaceInvites, "Its invites"),
278 a("invite_member", Op::InviteMember, "Invite an email address"),
279 a("revoke_invite", Op::RevokeWorkspaceInvite, "Revoke a pending invite"),
280 a("list_integrations", Op::ListIntegrations, "Model providers, alert sources, trackers"),
281 a("connect_integration", Op::ConnectIntegration, "Connect one"),
282 a("disconnect_integration", Op::DisconnectIntegration, "Remove one"),
283 a("test_integration", Op::TestIntegration, "Check its credentials"),
284 a("get_model_routes", Op::GetModelRoutes, "Where each kind of work's model requests go"),
285 a("set_model_routes", Op::SetModelRoutes, "Replace them"),
API: pinned projects over REST and MCP286 a("list_pinned_projects", Op::ListPinnedProjects, "Your pinned projects in it, in your order"),
287 a("pin_project", Op::PinProject, "Pin a project, at a position or the end"),
288 a("unpin_project", Op::UnpinProject, "Unpin a project"),
289 a("reorder_pinned_projects", Op::ReorderPinnedProjects, "Put your pins in a new order"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step290 ],
291 },
292 Tool {
Usage, Billing settings and prepaid AI credit; fixes from the UX audit293 name: "billing",
294 title: "Billing",
295 description: "A workspace's billing: its usage by product, project and day, its budget (the monthly spend limit, alerts and whether usage pauses at it), its AI credit, and its invoices. Amounts are whole millionths of a dollar (`_micros`), or cents (`_cents`) where named. Members read it; changing the budget and buying credit are for owners, as people, and never for g1t's agents.",
296 default_action: Some("usage"),
297 actions: &[
298 a("usage", Op::GetUsage, "Usage over a range of days, by product, meter, project and day, and what paid for it"),
299 a("budget", Op::GetBudget, "The monthly spend limit, what was spent, alerts and whether usage pauses at the limit"),
300 a("set_budget", Op::SetBudget, "Change the spend limit, alerts, pausing or the alert webhook"),
301 a("ai_credit", Op::GetAiCredit, "AI credit left, its grants, auto-reload and how to buy more"),
302 a("buy_ai_credit", Op::BuyAiCredit, "A payment page to buy AI credit, for a person to open"),
303 a("invoices", Op::ListInvoices, "Every invoice, the itemised usage invoices, and the next one so far"),
304 a("billing_details", Op::GetBillingDetails, "Who invoices are made out to and the payment method on file"),
305 ],
306 },
307 Tool {
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar308 name: "security",
309 title: "Security",
310 description: "A repository's security: secret scanning alerts and push protection bypasses, custom secret patterns, code scanning alerts and SARIF uploads, vulnerability alerts, the dependency graph and its SBOM, dependency review, settings, and a workspace's overview. Fix an alert with g1t. Findings are shown to those who can change the code only. Give `repo` (owner/name), or `workspace` for lists across one.",
311 default_action: Some("secret_alerts"),
312 actions: &[
313 a("secret_alerts", Op::Security(SecurityOp::ListSecretAlerts), "Secret scanning alerts; by state, secret_type, validity, bypassed"),
314 a("secret_alert", Op::Security(SecurityOp::GetSecretAlert), "One secret alert, with where it was found and its bypass requests"),
315 a("update_secret_alert", Op::Security(SecurityOp::UpdateSecretAlert), "Dismiss a secret alert with a reason, or reopen it"),
316 a("secret_locations", Op::Security(SecurityOp::ListSecretLocations), "Every file, line and commit a secret is in"),
317 a("bypass", Op::Security(SecurityOp::BypassPushProtection), "Push past push protection with a reason, or ask to"),
318 a("check_validity", Op::Security(SecurityOp::CheckSecretValidity), "Ask a secret's issuer whether it still works"),
319 a("bypass_requests", Op::Security(SecurityOp::ListBypassRequests), "A workspace's push protection bypass requests"),
320 a("review_bypass", Op::Security(SecurityOp::ReviewBypassRequest), "Approve, deny or cancel a bypass request"),
321 a("patterns", Op::Security(SecurityOp::ListCustomPatterns), "Custom secret patterns of a repository or workspace"),
322 a("create_pattern", Op::Security(SecurityOp::CreateCustomPattern), "Create a custom secret pattern, as a draft or published"),
323 a("update_pattern", Op::Security(SecurityOp::UpdateCustomPattern), "Change, publish or unpublish a custom pattern"),
324 a("delete_pattern", Op::Security(SecurityOp::DeleteCustomPattern), "Delete a custom pattern"),
325 a("dry_run_pattern", Op::Security(SecurityOp::DryRunCustomPattern), "Run a pattern over the default branch without saving it"),
326 a("code_alerts", Op::Security(SecurityOp::ListCodeAlerts), "Code scanning alerts; by state, severity, tool, rule_id"),
327 a("code_alert", Op::Security(SecurityOp::GetCodeAlert), "One code scanning alert by number"),
328 a("update_code_alert", Op::Security(SecurityOp::UpdateCodeAlert), "Dismiss a code scanning alert with a reason, or reopen it"),
329 a("analyses", Op::Security(SecurityOp::ListAnalyses), "Code scanning analyses, newest first"),
330 a("upload_sarif", Op::Security(SecurityOp::UploadSarif), "Upload a SARIF file, gzipped and base64-encoded"),
331 a("sarif_upload", Op::Security(SecurityOp::GetSarifUpload), "Whether a SARIF upload was read, and its analyses"),
332 a("vulnerability_alerts", Op::Security(SecurityOp::ListVulnerabilityAlerts), "Vulnerable dependencies; by state, severity, ecosystem, package"),
333 a("vulnerability_alert", Op::Security(SecurityOp::GetVulnerabilityAlert), "One vulnerability alert"),
334 a("update_vulnerability_alert", Op::Security(SecurityOp::UpdateVulnerabilityAlert), "Dismiss a vulnerability alert with a reason, or reopen it"),
335 a("fix", Op::Security(SecurityOp::FixAlert), "Put g1t on an issue to fix an alert"),
336 a("dependency_graph", Op::Security(SecurityOp::GetDependencyGraph), "Every package the lockfiles resolve, direct or transitive"),
337 a("sbom", Op::Security(SecurityOp::GetSbom), "The dependency graph as an SPDX 2.3 document"),
338 a("compare_dependencies", Op::Security(SecurityOp::CompareDependencies), "What changes in dependencies between base...head"),
339 a("settings", Op::Security(SecurityOp::GetSettings), "A repository's security settings"),
340 a("update_settings", Op::Security(SecurityOp::UpdateSettings), "Change when checks fail and dependency review's policy"),
341 a("workspace_settings", Op::Security(SecurityOp::GetWorkspaceSettings), "A workspace's delegated bypass and validity checks"),
342 a("update_workspace_settings", Op::Security(SecurityOp::UpdateWorkspaceSettings), "Turn delegated bypass or validity checks on or off"),
343 a("overview", Op::Security(SecurityOp::GetOverview), "A workspace's alerts, trends and coverage"),
344 ],
345 },
346 Tool {
API: notifications over REST and MCP, with notifications scopes347 name: "notifications",
348 title: "Notifications",
349 description: "Your inbox: what needs you, and what you follow. One thread per issue, pull request, workflow or deployment, with why you were told (`reason`): an agent waiting on you, a review asked of you, an assignment, a mention, your work's checks, or what you subscribe to and watch. Mark threads read or done once handled, and choose what you hear of with subscribe, unsubscribe and watch. Your own: a personal token.",
350 default_action: Some("list"),
351 actions: &[
352 a("list", Op::ListNotifications, "Unread threads, latest first; all, a view, a reason, a repository"),
353 a("get", Op::GetNotificationThread, "One thread with its recent activity and your subscription"),
354 a("mark_read", Op::MarkThreadRead, "Mark a thread read, or unread"),
355 a("mark_all_read", Op::MarkNotificationsRead, "Mark everything read up to a time, or one repository's"),
356 a("done", Op::MarkThreadDone, "Mark a thread done; new activity brings it back"),
357 a("save", Op::SaveThread, "Save a thread, or unsave it"),
358 a("snooze", Op::SnoozeThread, "Snooze a thread until a time, or bring it back"),
359 a("subscription", Op::GetThreadSubscription, "Your subscription to an issue or pull request"),
360 a("subscribe", Op::SetThreadSubscription, "Subscribe to an issue or pull request, or ignore it"),
361 a("unsubscribe", Op::DeleteThreadSubscription, "Unsubscribe until you comment or are mentioned"),
362 a("watching", Op::GetRepoSubscription, "How you watch a repository"),
363 a("watch", Op::SetRepoSubscription, "Watch a repository: participating, all, ignore or custom"),
364 a("unwatch", Op::DeleteRepoSubscription, "Stop watching a repository"),
365 a("watched", Op::ListWatchedRepos, "Repositories you watch other than the default way"),
366 ],
367 },
368 Tool {
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step369 name: "account",
370 title: "Your account",
371 description: "Who this token acts as and its workspaces (`whoami`), your email addresses, your invites, and invitations to repositories waiting for you.",
372 default_action: Some("whoami"),
373 actions: &[
374 a("whoami", Op::Whoami, "Who the token acts as, and its workspaces"),
375 a("list_emails", Op::ListEmails, "Your addresses"),
376 a("add_email", Op::AddEmail, "Add an address"),
377 a("remove_email", Op::RemoveEmail, "Remove an address"),
378 a("update_email_settings", Op::UpdateEmailSettings, "Primary, backup and privacy"),
379 a("list_invites", Op::ListInvites, "Your invites to g1t"),
380 a("create_invite", Op::CreateInvite, "Make an invite"),
381 a("revoke_invite", Op::RevokeInvite, "Revoke one"),
382 a("list_repository_invitations", Op::ListMyRepoInvitations, "Invitations to repositories for you"),
383 a("accept_repository_invitation", Op::AcceptRepoInvitation, "Accept one"),
384 a("decline_repository_invitation", Op::DeclineRepoInvitation, "Decline one"),
385 ],
386 },
387];
388
389/// Operations that cannot be undone, or reach beyond g1t's own records:
390/// clients ask before running a tool that has any of them.
391fn destructive(op: Op) -> bool {
392 matches!(
393 op,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar394 Op::Security(SecurityOp::DeleteCustomPattern | SecurityOp::BypassPushProtection)
395 | Op::DeleteWorkspace
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily396 | Op::UpdateWorkspace
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step397 | Op::DeleteRepo
398 | Op::PurgeRepo
399 | Op::TransferRepo
400 | Op::SetRepoVisibility
401 | Op::RemoveEmail
402 | Op::RemoveCollaborator
403 | Op::DisconnectIntegration
404 | Op::DeleteWebhook
405 | Op::DeleteActionsSecret
406 | Op::DeleteActionsVariable
407 | Op::SetActionsSecret
408 | Op::SetActionsVariable
409 | Op::SetModelRoutes
410 | Op::SetBasePermission
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar411 | Op::DeleteTeam
412 | Op::RemoveTeamRepo
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step413 | Op::MergePullRequest
Fast pages, required checks on the branch, self-hosted runners, honest incidents414 | Op::RemoveRunner
415 | Op::DeleteRunnerGroup
416 | Op::UpdateRunnerSettings
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step417 )
418}
419
420/// Whether an operation only reads.
421pub fn reads_only(op: Op) -> bool {
422 NO_SCOPE.contains(&op.name())
423 || scope_for(op.name()).is_some_and(|scope| scope.level() == Level::Read)
424}
425
426/// What decides which actions a caller sees.
427pub enum Gate<'a> {
428 /// No limit beyond the person's own role.
429 Everything,
430 /// A g1t agent's token: the operations its run lists.
431 Agent(&'a AgentScope),
432 /// An access token with scopes.
433 Token(&'a TokenAccess),
434}
435
436impl Gate<'_> {
437 pub fn allows(&self, op: Op) -> bool {
438 match self {
439 Gate::Everything => true,
440 Gate::Agent(scope) => op.allowed_by(scope) && !NEVER.contains(&op.name()),
441 Gate::Token(access) => {
442 if NO_SCOPE.contains(&op.name()) {
443 return true;
444 }
445 match scope_for(op.name()) {
446 Some(scope) => access.allows(scope),
447 None => access.scopes.is_none(),
448 }
449 }
450 }
451 }
452}
453
454impl Tool {
455 pub fn by_name(name: &str) -> Option<&'static Tool> {
456 TOOLS.iter().find(|tool| tool.name == name)
457 }
458
459 pub fn action(&self, name: &str) -> Option<&'static Action> {
460 // The tools are 'static; find through TOOLS to keep the lifetime.
461 TOOLS
462 .iter()
463 .find(|tool| tool.name == self.name)
464 .and_then(|tool| tool.actions.iter().find(|action| action.name == name))
465 }
466
467 pub fn visible(&self, gate: &Gate) -> Vec<&'static Action> {
468 TOOLS
469 .iter()
470 .find(|tool| tool.name == self.name)
471 .map(|tool| tool.actions.iter().filter(|action| gate.allows(action.op)).collect())
472 .unwrap_or_default()
473 }
474
475 /// The flat input schema of the actions given.
476 pub fn input_schema(&self, actions: &[&Action]) -> Value {
477 let mut properties = Map::new();
478 let lines: Vec<String> = actions
479 .iter()
480 .map(|action| {
481 let required: Vec<String> = action.op.required();
482 if required.is_empty() {
483 format!("{}: {}.", action.name, action.summary)
484 } else {
485 format!("{} ({}): {}.", action.name, required.join(", "), action.summary)
486 }
487 })
488 .collect();
489 let mut action_schema = json!({
490 "type": "string",
491 "enum": actions.iter().map(|action| action.name).collect::<Vec<_>>(),
492 "description": lines.join("\n"),
493 });
494 if let Some(default) = self.default_action.filter(|name| actions.iter().any(|action| action.name == *name)) {
495 action_schema["default"] = json!(default);
496 }
497 properties.insert("action".to_owned(), action_schema);
498 for action in actions {
499 for (name, schema) in action.op.properties() {
500 merge_property(&mut properties, name, schema);
501 }
502 }
503 let mut required = vec![];
504 if self.default_action.is_none() {
505 required.push("action");
506 }
507 let mut schema = json!({ "type": "object", "properties": properties });
508 if !required.is_empty() {
509 schema["required"] = json!(required);
510 }
511 schema
512 }
513
514 /// The input schema keyed by action: one `oneOf` branch per action,
515 /// each with its own fields and the ones it needs.
516 pub fn discriminated(&self, actions: &[&Action]) -> Value {
517 let branches: Vec<Value> = actions
518 .iter()
519 .map(|action| {
520 let mut properties = Map::new();
521 properties.insert("action".to_owned(), json!({ "const": action.name }));
522 properties.extend(action.op.properties());
523 let mut required = vec![Value::String("action".to_owned())];
524 // The default action may leave `action` out.
525 if self.default_action == Some(action.name) {
526 required.clear();
527 }
528 required.extend(action.op.required().into_iter().map(Value::String));
529 json!({
530 "title": action.name,
531 "description": action.summary,
532 "type": "object",
533 "properties": properties,
534 "required": required,
535 })
536 })
537 .collect();
538 json!({ "type": "object", "oneOf": branches })
539 }
540
541 /// MCP's hints about the actions given: whether the tool only reads,
542 /// whether it can destroy something, and whether calling it twice is
543 /// the same as once.
544 pub fn annotations(&self, actions: &[&Action]) -> Value {
545 let read_only = actions.iter().all(|action| reads_only(action.op));
546 json!({
547 "title": self.title,
548 "readOnlyHint": read_only,
549 "destructiveHint": !read_only && actions.iter().any(|action| destructive(action.op)),
550 "idempotentHint": read_only,
551 "openWorldHint": false,
552 })
553 }
554
555 /// The tool as `tools/list` gives it, for a caller behind `gate`, or
556 /// `None` when it may use none of its actions.
557 pub fn listed(&self, gate: &Gate) -> Option<Value> {
558 let actions = self.visible(gate);
559 if actions.is_empty() {
560 return None;
561 }
562 Some(json!({
563 "name": self.name,
564 "title": self.title,
565 "description": self.description,
566 "inputSchema": self.input_schema(&actions),
567 "annotations": self.annotations(&actions),
568 }))
569 }
570}
571
572/// Adds a property to a tool's flat schema. The first action to use a name
573/// describes it; a later one with other allowed values adds them.
574fn merge_property(properties: &mut Map<String, Value>, name: String, schema: Value) {
575 match properties.get_mut(&name) {
576 None => {
577 properties.insert(name, schema);
578 }
579 Some(existing) => {
580 if let (Some(Value::Array(had)), Some(Value::Array(more))) =
581 (existing.get("enum").cloned(), schema.get("enum"))
582 {
583 let mut merged = had;
584 for value in more {
585 if !merged.contains(value) {
586 merged.push(value.clone());
587 }
588 }
589 existing["enum"] = Value::Array(merged);
590 }
591 // Different kinds of value under one name: say less, accept both.
592 if existing.get("type") != schema.get("type")
593 && let Some(fields) = existing.as_object_mut()
594 {
595 fields.remove("type");
596 fields.remove("items");
597 }
598 }
599 }
600}
601
602/// What a call to a tool runs: the operation its action names, or why not.
603pub fn resolve(tool: &Tool, arguments: &Value) -> Result<Op, String> {
604 let names = || {
605 tool.actions
606 .iter()
607 .map(|action| action.name)
608 .collect::<Vec<_>>()
609 .join(", ")
610 };
611 let Some(name) = arguments["action"].as_str().or(tool.default_action) else {
612 return Err(format!("Give an action: one of {}.", names()));
613 };
614 let Some(action) = tool.action(name) else {
615 return Err(format!("{} has no action {name}. Its actions: {}.", tool.name, names()));
616 };
617 let missing: Vec<String> = action
618 .op
619 .required()
620 .into_iter()
621 .filter(|field| arguments.get(field).is_none_or(Value::is_null))
622 .collect();
623 if !missing.is_empty() {
624 return Err(format!("{}.{name} needs {}.", tool.name, missing.join(", ")));
625 }
626 Ok(action.op)
627}
628
629#[cfg(test)]
630mod tests {
631 use super::*;
632 use g1t_contracts::scopes::{Preset, Scope};
633
634 fn listed(gate: &Gate) -> Vec<Value> {
635 TOOLS.iter().filter_map(|tool| tool.listed(gate)).collect()
636 }
637
638 fn token(scopes: Option<Vec<Scope>>) -> TokenAccess {
639 TokenAccess {
640 token_id: "tok_1".to_owned(),
641 scopes: scopes.map(|scopes| scopes.iter().map(|scope| scope.as_str().to_owned()).collect()),
642 legacy: false,
643 }
644 }
645
646 #[test]
647 fn every_operation_is_exactly_one_action_of_one_tool() {
648 for op in Op::ALL {
649 let count = TOOLS
650 .iter()
651 .flat_map(|tool| tool.actions.iter())
652 .filter(|action| action.op == op)
653 .count();
654 assert_eq!(count, 1, "{} is {count} actions", op.name());
655 }
656 for tool in TOOLS {
657 let mut names = std::collections::HashSet::new();
658 for action in tool.actions {
659 assert!(names.insert(action.name), "{}.{} twice", tool.name, action.name);
660 }
661 if let Some(default) = tool.default_action {
662 assert!(tool.action(default).is_some(), "{}", tool.name);
663 }
664 }
Usage, Billing settings and prepaid AI credit; fixes from the UX audit665 assert!(TOOLS.len() <= 17, "{} tools", TOOLS.len());
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step666 }
667
668 #[test]
669 fn every_operation_needs_exactly_one_scope_or_none() {
670 use g1t_contracts::scopes::OPERATIONS;
671 for op in Op::ALL {
672 let mapped = OPERATIONS.iter().filter(|(name, _)| *name == op.name()).count();
673 let free = NO_SCOPE.contains(&op.name());
674 assert_eq!(mapped + usize::from(free), 1, "{}", op.name());
675 }
676 for (name, _) in OPERATIONS {
677 assert!(Op::by_name(name).is_some(), "{name} is not an operation");
678 }
679 }
680
681 #[test]
682 fn each_tool_schema_is_valid_with_one_branch_per_action() {
683 for tool in TOOLS {
684 let actions: Vec<&Action> = tool.actions.iter().collect();
685 let flat = tool.input_schema(&actions);
686 assert_eq!(flat["type"], "object");
687 assert!(flat.get("oneOf").is_none(), "no oneOf at the top level");
688 let listed: Vec<&str> = flat["properties"]["action"]["enum"]
689 .as_array()
690 .unwrap()
691 .iter()
692 .map(|name| name.as_str().unwrap())
693 .collect();
694 assert_eq!(listed, tool.actions.iter().map(|action| action.name).collect::<Vec<_>>());
695 for action in tool.actions {
696 for field in action.op.required() {
697 assert!(flat["properties"].get(&field).is_some(), "{}.{}: {field}", tool.name, action.name);
698 }
699 }
700 let keyed = tool.discriminated(&actions);
701 let branches = keyed["oneOf"].as_array().unwrap();
702 assert_eq!(branches.len(), tool.actions.len());
703 for (branch, action) in branches.iter().zip(tool.actions) {
704 assert_eq!(branch["properties"]["action"]["const"], action.name);
705 for field in branch["required"].as_array().unwrap() {
706 assert!(branch["properties"].get(field.as_str().unwrap()).is_some(), "{}.{}: {field}", tool.name, action.name);
707 }
708 }
709 // A well-formed JSON Schema object throughout.
710 let text = serde_json::to_string(&flat).unwrap();
711 assert!(serde_json::from_str::<Value>(&text).is_ok());
712 }
713 }
714
715 #[test]
716 fn a_read_only_token_sees_read_actions_only() {
717 let access = token(Preset::ReadOnly.scopes());
718 let gate = Gate::Token(&access);
719 for tool in TOOLS {
720 for action in tool.visible(&gate) {
721 assert!(reads_only(action.op), "{}.{}", tool.name, action.name);
722 }
723 }
724 let tools = listed(&gate);
725 for tool in &tools {
726 assert_eq!(tool["annotations"]["readOnlyHint"], true, "{}", tool["name"]);
727 assert_eq!(tool["annotations"]["destructiveHint"], false);
728 }
729 let issue = tools.iter().find(|tool| tool["name"] == "issue").unwrap();
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar730 assert_eq!(issue["inputSchema"]["properties"]["action"]["enum"], json!(["list", "get", "labels"]));
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step731 // Nothing of the agent tool is a read.
732 assert!(!tools.iter().any(|tool| tool["name"] == "agent"));
733 }
734
735 #[test]
736 fn a_narrow_token_sees_only_its_tools() {
737 let access = token(Some(vec![Scope::IssuesWrite]));
738 let names: Vec<Value> = listed(&Gate::Token(&access)).into_iter().map(|tool| tool["name"].clone()).collect();
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar739 // Labels and milestones are the repository's, managed with issues:write.
740 assert_eq!(names, vec![json!("repository"), json!("issue"), json!("plan"), json!("account")]);
API: notifications over REST and MCP, with notifications scopes741 // Notifications are a resource of their own: reading them lists
742 // only what reads.
743 let reader = token(Some(vec![Scope::NotificationsRead]));
744 let tools = listed(&Gate::Token(&reader));
745 let notifications = tools.iter().find(|tool| tool["name"] == "notifications").unwrap();
746 assert_eq!(
747 notifications["inputSchema"]["properties"]["action"]["enum"],
748 json!(["list", "get", "subscription", "watching", "watched"])
749 );
750 assert_eq!(notifications["annotations"]["readOnlyHint"], true);
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step751 let full = token(None);
752 assert_eq!(listed(&Gate::Token(&full)).len(), TOOLS.len());
753 assert_eq!(listed(&Gate::Everything).len(), TOOLS.len());
754 }
755
756 #[test]
757 fn a_tool_that_can_destroy_says_so() {
758 let tools = listed(&Gate::Everything);
759 let repository = tools.iter().find(|tool| tool["name"] == "repository").unwrap();
760 assert_eq!(repository["annotations"]["destructiveHint"], true);
761 assert_eq!(repository["annotations"]["readOnlyHint"], false);
762 let memory = tools.iter().find(|tool| tool["name"] == "memory").unwrap();
763 assert_eq!(memory["annotations"]["destructiveHint"], false);
764 }
765
766 #[test]
767 fn calls_resolve_to_their_operation_or_say_what_is_missing() {
768 let issue = Tool::by_name("issue").unwrap();
769 assert_eq!(resolve(issue, &json!({ "action": "get", "repo": "a/b", "number": 1 })), Ok(Op::GetIssue));
770 assert_eq!(resolve(issue, &json!({ "action": "get", "repo": "a/b" })), Err("issue.get needs number.".to_owned()));
771 assert!(resolve(issue, &json!({})).unwrap_err().starts_with("Give an action"));
772 assert!(resolve(issue, &json!({ "action": "explode" })).unwrap_err().contains("no action explode"));
773 let search = Tool::by_name("search").unwrap();
774 assert_eq!(resolve(search, &json!({ "query": "x" })), Ok(Op::Search));
775 let account = Tool::by_name("account").unwrap();
776 assert_eq!(resolve(account, &json!({})), Ok(Op::Whoami));
777 }
778
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar779 #[test]
780 fn teams_are_one_tool_and_a_workspace_reader_sees_only_its_reads() {
781 let team = Tool::by_name("team").unwrap();
782 let names: Vec<&str> = team.actions.iter().map(|action| action.name).collect();
783 assert_eq!(
784 names,
785 [
786 "list",
787 "get",
788 "create",
789 "update",
790 "delete",
791 "list_members",
792 "set_member",
793 "remove_member",
794 "list_child_teams",
795 "list_repos",
796 "set_repo",
797 "remove_repo",
798 "set_review_assignment",
799 "list_user_teams",
800 ]
801 );
802 let reader = token(Some(vec![Scope::WorkspaceRead]));
803 let tools = listed(&Gate::Token(&reader));
804 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
805 assert_eq!(
806 listed_team["inputSchema"]["properties"]["action"]["enum"],
807 json!(["list", "get", "list_members", "list_child_teams", "list_repos", "list_user_teams"])
808 );
809 assert_eq!(listed_team["annotations"]["readOnlyHint"], true);
810 // A team's role on a repository is who has access.
811 let admin = token(Some(vec![Scope::WorkspaceAdmin]));
812 let tools = listed(&Gate::Token(&admin));
813 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
814 let actions = listed_team["inputSchema"]["properties"]["action"]["enum"].as_array().unwrap();
815 assert!(actions.contains(&json!("set_review_assignment")) && !actions.contains(&json!("set_repo")));
816 let access = token(Some(vec![Scope::AccessAdmin]));
817 let tools = listed(&Gate::Token(&access));
818 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
819 assert_eq!(listed_team["inputSchema"]["properties"]["action"]["enum"], json!(["set_repo", "remove_repo"]));
820 // Both kinds of role a schema names are offered.
821 let roles = &listed(&Gate::Everything).into_iter().find(|tool| tool["name"] == "team").unwrap()["inputSchema"]
822 ["properties"]["role"]["enum"];
823 for role in ["member", "maintainer", "read", "admin"] {
824 assert!(roles.as_array().unwrap().contains(&json!(role)), "{role}");
825 }
826 assert_eq!(
827 resolve(team, &json!({ "action": "set_repo", "workspace": "acme", "team": "backend", "repo": "rocket" })),
828 Err("team.set_repo needs role.".to_owned())
829 );
830 }
831
832 #[test]
833 fn reviewers_and_code_owners_are_actions_of_their_tools() {
834 let pull = Tool::by_name("pull_request").unwrap();
835 assert_eq!(
836 resolve(pull, &json!({ "action": "request_reviewers", "repo": "a/b", "number": 1, "team_reviewers": ["backend"] })),
837 Ok(Op::RequestReviewers)
838 );
839 assert_eq!(pull.action("remove_requested_reviewers").map(|action| action.op), Some(Op::RemoveRequestedReviewers));
840 let repository = Tool::by_name("repository").unwrap();
841 assert_eq!(resolve(repository, &json!({ "action": "codeowners", "repo": "a/b" })), Ok(Op::GetCodeownersErrors));
842 assert!(reads_only(Op::GetCodeownersErrors));
843 assert!(!reads_only(Op::RequestReviewers));
844 }
845
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step846 /// How much smaller `tools/list` is than one tool per operation. Run
847 /// with `--nocapture` to see the numbers.
848 #[test]
849 fn the_tool_list_is_much_smaller_than_one_tool_per_operation() {
850 let before: Vec<Value> = Op::ALL
851 .into_iter()
852 .map(|op| json!({ "name": op.name(), "description": op.description(), "inputSchema": op.input() }))
853 .collect();
854 let after = listed(&Gate::Everything);
855 let before_bytes = serde_json::to_string(&json!({ "tools": before })).unwrap().len();
856 let after_bytes = serde_json::to_string(&json!({ "tools": after })).unwrap().len();
857 let agent = token(Preset::Agent.scopes());
858 let agent_bytes = serde_json::to_string(&json!({ "tools": listed(&Gate::Token(&agent)) })).unwrap().len();
859 let read = token(Preset::ReadOnly.scopes());
860 let read_bytes = serde_json::to_string(&json!({ "tools": listed(&Gate::Token(&read)) })).unwrap().len();
861 println!(
862 "tools/list: before {} tools, {before_bytes} bytes (~{} tokens); after {} tools, {after_bytes} bytes (~{} tokens); agent preset {agent_bytes} bytes (~{} tokens); read only {read_bytes} bytes (~{} tokens)",
863 before.len(),
864 before_bytes / 4,
865 after.len(),
866 after_bytes / 4,
867 agent_bytes / 4,
868 read_bytes / 4,
869 );
870 assert!(after_bytes * 2 < before_bytes, "{after_bytes} vs {before_bytes}");
871 }
872}

This file's history is long; its oldest lines are credited to the oldest commit read.