Skip to content

g1t/apps/api/src/tools.rs

892 lines50,707 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step1//! The MCP server's tools: a few resource tools, each with an `action`.
2//!
3//! Every operation is one action of one tool. A call is dispatched to the
4//! operation it names, so permissions, the audit log, billing and outcomes
5//! are exactly those of the REST API. A token sees only the actions its
6//! scopes allow, and a tool none of whose actions it may use is not listed.
7//!
8//! The listed input schema is one flat object: `action`, then every field
9//! any of its actions takes. Which fields each action needs is in the
10//! `action` field's description and checked on every call. Claude's API,
11//! and so most MCP clients, refuse a tool whose input schema has `oneOf`
12//! at its top level, so the schema keyed by action, with each action's
13//! required fields, is [`discriminated`], published on the server's card
14//! and in the docs.
15
16use g1t_contracts::credentials::NEVER;
17use g1t_contracts::identity::AgentScope;
18use g1t_contracts::scopes::{Level, NO_SCOPE, TokenAccess, scope_for};
19use serde_json::{Map, Value, json};
20
21use crate::operations::Op;
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge22use crate::rules::RulesOp;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar23use crate::security::SecurityOp;
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step24
25pub struct Action {
26 pub name: &'static str,
27 pub op: Op,
28 /// One line, for the `action` field's description.
29 pub summary: &'static str,
30}
31
32pub struct Tool {
33 pub name: &'static str,
34 pub title: &'static str,
35 /// What it is for, in a sentence or two.
36 pub description: &'static str,
37 pub actions: &'static [Action],
38 /// The action a call without one runs.
39 pub default_action: Option<&'static str>,
40}
41
42const fn a(name: &'static str, op: Op, summary: &'static str) -> Action {
43 Action { name, op, summary }
44}
45
46pub const TOOLS: &[Tool] = &[
47 Tool {
48 name: "search",
49 title: "Search",
50 description: "Find things. `code` (the default) searches all of g1t you can see: repositories, code, issues, pull requests and people, with qualifiers like repo:owner/name, language:rust, is:issue. `context` searches one workspace's catalog, docs, issues and memory by meaning.",
51 default_action: Some("code"),
52 actions: &[
53 a("code", Op::Search, "Search all of g1t: repositories, code, issues, pull requests, people"),
54 a("context", Op::SearchContext, "Search a workspace's context hub by meaning"),
55 a("entity", Op::GetEntity, "One catalog entry and its relations"),
56 a("ticket", Op::GetContext, "A Jira, Linear or Sentry item the work refers to, as it is now"),
57 ],
58 },
59 Tool {
60 name: "repository",
61 title: "Repositories",
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge62 description: "Repositories: find, read and create them, change their settings and rulesets (what may happen to branches and tags, and what a pull request needs to merge), check their CODEOWNERS file, manage their labels and milestones, and see and dismiss their security alerts (secrets and vulnerable dependencies). Name one as \"owner/name\". Deleting, transferring and changing visibility need `confirm`.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step63 default_action: None,
64 actions: &[
65 a("list", Op::ListRepos, "Repositories you can see"),
66 a("get", Op::GetRepo, "One repository"),
67 a("create", Op::CreateRepo, "Create one, empty or copied from a public git URL"),
68 a("update", Op::UpdateRepo, "Change description, website, topics, default branch, protection"),
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge69 a("get_settings", Op::GetRepoSettings, "How pull requests merge, and the default branch's protection as its rules stack"),
70 a("update_settings", Op::UpdateRepoSettings, "Change how pull requests merge and the default branch protection ruleset"),
71 a("check_names", Op::ListCheckNames, "Check names reported lately, to require in a ruleset"),
72 a("list_rulesets", Op::Rules(RulesOp::ListRepoRulesets), "Its rulesets, and its workspace's that hold in it"),
73 a("get_ruleset", Op::Rules(RulesOp::GetRepoRuleset), "One ruleset"),
74 a("create_ruleset", Op::Rules(RulesOp::CreateRepoRuleset), "Create a ruleset for its branches or tags"),
75 a("update_ruleset", Op::Rules(RulesOp::UpdateRepoRuleset), "Change a ruleset"),
76 a("delete_ruleset", Op::Rules(RulesOp::DeleteRepoRuleset), "Delete a ruleset"),
77 a("branch_rules", Op::Rules(RulesOp::GetBranchRules), "Every rule that holds for a branch or tag, and where it comes from"),
78 a("rule_evaluations", Op::Rules(RulesOp::ListRuleEvaluations), "How its rules judged pushes and merges, with insights"),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar79 a("codeowners", Op::GetCodeownersErrors, "Problems in its CODEOWNERS file, by line"),
80 a("list_labels", Op::ListLabels, "Labels, with colors and how many issues and pull requests carry each"),
81 a("create_label", Op::CreateLabel, "Create a label"),
82 a("update_label", Op::UpdateLabel, "Rename a label or change its color or description"),
83 a("delete_label", Op::DeleteLabel, "Delete a label, from everything that carries it"),
84 a("add_default_labels", Op::AddDefaultLabels, "Add the default labels it is missing"),
85 a("list_milestones", Op::ListMilestones, "Milestones, with progress and due dates"),
86 a("get_milestone", Op::GetMilestone, "One milestone with its issues and pull requests"),
87 a("create_milestone", Op::CreateMilestone, "Create a milestone"),
88 a("update_milestone", Op::UpdateMilestone, "Change a milestone's title, description, due date or state"),
89 a("delete_milestone", Op::DeleteMilestone, "Delete a milestone"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step90 a("list_events", Op::ListEvents, "Timeline: pushes, issues, pull requests, comments"),
91 a("rename_branch", Op::RenameBranch, "Rename a branch"),
92 a("rename", Op::RenameRepo, "Rename it; old addresses redirect"),
93 a("transfer", Op::TransferRepo, "Move it to another workspace you own"),
94 a("archive", Op::ArchiveRepo, "Make it read-only"),
95 a("unarchive", Op::UnarchiveRepo, "Make it writable again"),
96 a("set_visibility", Op::SetRepoVisibility, "Make it public or private"),
97 a("delete", Op::DeleteRepo, "Delete it; restorable for 30 days"),
98 a("list_deleted", Op::ListDeletedRepos, "A workspace's deleted repositories"),
99 a("restore", Op::RestoreRepo, "Restore a deleted one"),
100 a("purge", Op::PurgeRepo, "Remove a deleted one for good"),
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily101 a("security_alerts", Op::ListSecurityAlerts, "Secret and dependency alerts, filtered by state"),
102 a("dismiss_alert", Op::DismissSecurityAlert, "Dismiss an alert with a reason"),
103 a("reopen_alert", Op::ReopenSecurityAlert, "Reopen a dismissed alert"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step104 ],
105 },
106 Tool {
107 name: "issue",
108 title: "Issues",
109 description: "Issues: what should change. Read one before working on it to see the pull requests already made for it. Issues and pull requests share numbers; `comment` works on either.",
110 default_action: None,
111 actions: &[
112 a("list", Op::ListIssues, "Issues on a repository, newest first"),
Fast pages, required checks on the branch, self-hosted runners, honest incidents113 a("get", Op::GetIssue, "One issue with comments and its pull requests"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step114 a("create", Op::CreateIssue, "Open an issue"),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar115 a("update", Op::UpdateIssue, "Change title, body, labels, milestone or assignees"),
116 a("labels", Op::ListIssueLabels, "The labels an issue or pull request carries"),
117 a("add_labels", Op::AddIssueLabels, "Add labels to an issue or pull request"),
118 a("set_labels", Op::SetIssueLabels, "Replace the labels of an issue or pull request"),
119 a("remove_labels", Op::RemoveIssueLabels, "Take labels off an issue or pull request"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step120 a("close", Op::CloseIssue, "Close it without a pull request"),
121 a("reopen", Op::ReopenIssue, "Reopen it"),
122 a("comment", Op::AddComment, "Comment on an issue or pull request; path and line for one line of a change"),
123 a("import", Op::ImportIssue, "Open an issue from a Jira, Linear or Sentry item"),
124 ],
125 },
126 Tool {
127 name: "pull_request",
128 title: "Pull requests",
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar129 description: "Pull requests: start a change for an issue, record your session, mark it ready, ask people and teams to review, review and merge. Read `overlaps` and `behind` on `get` before going far, and `code_owners` for whose approval it needs.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step130 default_action: None,
131 actions: &[
132 a("list", Op::ListPullRequests, "Pull requests on a repository, newest first"),
Fast pages, required checks on the branch, self-hosted runners, honest incidents133 a("get", Op::GetPullRequest, "Status, checks and required checks, reviews, overlaps, whether it is behind"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step134 a("changes", Op::GetPullRequestChanges, "Files and line-by-line diff"),
135 a("create", Op::CreatePullRequest, "Start a draft with its own fork to push to, or open one from a pushed branch"),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar136 a("update", Op::UpdatePullRequest, "Change its base branch, labels, milestone, assignees or reviewers"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step137 a("record_session", Op::RecordSession, "Append prompt, reasoning and tool entries to its session"),
138 a("read_session", Op::ReadSession, "Its recorded session"),
139 a("ready", Op::MarkPullRequestReady, "Mark a draft ready, with a summary"),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar140 a("request_reviewers", Op::RequestReviewers, "Ask people or teams to review it"),
141 a("remove_requested_reviewers", Op::RemoveRequestedReviewers, "Stop asking people or teams to review it"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step142 a("review", Op::ReviewPullRequest, "Approve or request changes"),
143 a("close", Op::ClosePullRequest, "Close without merging"),
144 a("merge", Op::MergePullRequest, "Land it, or join the merge queue"),
145 a("merge_queue", Op::GetMergeQueue, "The repository's merge queue"),
146 ],
147 },
148 Tool {
149 name: "agent",
150 title: "g1t agents",
151 description: "Put g1t's agent to work and talk to it. One agent per issue; to do more at once, use more issues. Starting an agent uses the workspace's money.",
152 default_action: None,
153 actions: &[
154 a("delegate", Op::Delegate, "Open an issue and put an agent on it in one step"),
155 a("assign", Op::AssignIssue, "Put an agent on an existing issue"),
156 a("message", Op::MessageAgent, "Tell the agent on a pull request something, or ask another agent"),
157 a("answer", Op::AnswerMessage, "Answer a question or handoff sent to you"),
158 a("take_messages", Op::TakeMessages, "For a g1t agent: messages not seen yet"),
159 ],
160 },
161 Tool {
162 name: "plan",
163 title: "Plans",
Fast pages, required checks on the branch, self-hosted runners, honest incidents164 description: "Turn an outcome into issues: an agent proposes them with what done means and their dependencies; nothing opens until you apply the plan.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step165 default_action: None,
166 actions: &[
167 a("create", Op::PlanWork, "Ask an agent for a plan; read it with get until ready"),
168 a("get", Op::GetPlan, "A plan and the issues it proposes"),
169 a("apply", Op::ApplyPlan, "Open its issues; with assign, agents start in dependency order"),
170 ],
171 },
172 Tool {
173 name: "memory",
174 title: "Memory",
175 description: "What the project and its workspace remember for the next agent: how to build, conventions, decisions, traps. Recall before you start; remember one short fact at a time, never a secret.",
176 default_action: None,
177 actions: &[
178 a("recall", Op::Recall, "Search memory, or list it all"),
179 a("remember", Op::Remember, "Save one fact"),
180 ],
181 },
182 Tool {
183 name: "workflow",
184 title: "Workflows",
Fast pages, required checks on the branch, self-hosted runners, honest incidents185 description: "GitHub Actions workflows from .g1t/workflows: their runs, jobs and logs, and running, cancelling or rerunning them. Also the self-hosted runners they run on: a workspace's (`workspace`) or a repository's own (`repo`), their groups, and where agent work runs.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step186 default_action: None,
187 actions: &[
188 a("list", Op::ListWorkflows, "Workflows on the default branch"),
189 a("list_runs", Op::ListWorkflowRuns, "Runs, newest first"),
190 a("get_run", Op::GetWorkflowRun, "One run with its jobs and steps"),
191 a("job_logs", Op::GetJobLogs, "A job's log after a sequence number"),
192 a("dispatch", Op::DispatchWorkflow, "Run a workflow_dispatch workflow"),
193 a("cancel", Op::CancelWorkflowRun, "Cancel a run"),
194 a("rerun", Op::RerunWorkflowRun, "Run a finished run again"),
195 a("update", Op::UpdateWorkflow, "Turn a workflow on or off"),
Fast pages, required checks on the branch, self-hosted runners, honest incidents196 a("list_runners", Op::ListRunners, "Self-hosted runners, with status, labels and what each is doing"),
197 a("create_runner_token", Op::CreateRunnerRegistrationToken, "A one-hour token for g1t-runner register"),
198 a("remove_runner", Op::RemoveRunner, "Remove a self-hosted runner"),
199 a("list_runner_groups", Op::ListRunnerGroups, "A workspace's runner groups"),
200 a("create_runner_group", Op::CreateRunnerGroup, "Make a group, for some repositories"),
201 a("update_runner_group", Op::UpdateRunnerGroup, "Rename a group or change its repositories"),
202 a("delete_runner_group", Op::DeleteRunnerGroup, "Delete a group; its runners join the default"),
203 a("get_runner_settings", Op::GetRunnerSettings, "Where agent work runs; whether forks may use runners"),
204 a("update_runner_settings", Op::UpdateRunnerSettings, "Change them"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step205 ],
206 },
207 Tool {
208 name: "secret",
209 title: "Secrets and variables",
210 description: "A repository's or workspace's secrets and variables, read by workflows and deployments. Secret values are never returned.",
211 default_action: None,
212 actions: &[
213 a("list_secrets", Op::ListActionsSecrets, "Secrets, without values"),
214 a("set_secret", Op::SetActionsSecret, "Add or change a secret"),
215 a("delete_secret", Op::DeleteActionsSecret, "Remove a secret"),
216 a("list_variables", Op::ListActionsVariables, "Variables, with values"),
217 a("set_variable", Op::SetActionsVariable, "Add or change a variable"),
218 a("delete_variable", Op::DeleteActionsVariable, "Remove a variable"),
219 ],
220 },
221 Tool {
222 name: "webhook",
223 title: "Webhooks",
224 description: "HTTPS addresses sent signed events as they happen, for a repository or a whole workspace.",
225 default_action: None,
226 actions: &[
227 a("list", Op::ListWebhooks, "Webhooks, without secrets"),
228 a("create", Op::CreateWebhook, "Register one; a ping is sent"),
229 a("update", Op::UpdateWebhook, "Change address, events or active"),
230 a("delete", Op::DeleteWebhook, "Remove one"),
231 a("ping", Op::PingWebhook, "Send a ping"),
232 a("list_deliveries", Op::ListWebhookDeliveries, "Latest deliveries"),
233 a("redeliver", Op::RedeliverWebhook, "Send a delivery again"),
234 ],
235 },
236 Tool {
237 name: "access",
238 title: "Who has access",
239 description: "Who has access to a repository and with which role (read, triage, write, maintain, admin), outside collaborators, and a workspace's base permission.",
240 default_action: None,
241 actions: &[
242 a("list_collaborators", Op::ListCollaborators, "Everyone with a role, and pending invitations"),
243 a("get_permission", Op::GetCollaboratorPermission, "One person's role and capabilities"),
244 a("add_collaborator", Op::AddCollaborator, "Give someone a role, by username or email"),
245 a("update_collaborator", Op::UpdateCollaborator, "Change a direct role"),
246 a("remove_collaborator", Op::RemoveCollaborator, "Take away a direct role"),
247 a("list_invitations", Op::ListRepoInvitations, "Pending invitations to a repository"),
248 a("revoke_invitation", Op::RevokeRepoInvitation, "Withdraw one"),
249 a("set_base_permission", Op::SetBasePermission, "What every member gets on each repository"),
250 a("list_outside_collaborators", Op::ListOutsideCollaborators, "People with roles who are not members"),
251 ],
252 },
253 Tool {
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar254 name: "team",
255 title: "Teams",
256 description: "Teams: groups of a workspace's members, given roles on repositories together, mentioned as @workspace/team and asked to review together. Name one by `workspace` and its slug (`team`). Any member may create a team; the workspace's owners and the team's maintainers manage it. A secret team is seen only by its people and the owners.",
257 default_action: None,
258 actions: &[
259 a("list", Op::ListTeams, "A workspace's teams you can see"),
260 a("get", Op::GetTeam, "One team"),
261 a("create", Op::CreateTeam, "Create a team; you become its maintainer"),
262 a("update", Op::UpdateTeam, "Change its name, slug, description, visibility, parent or notifications"),
263 a("delete", Op::DeleteTeam, "Delete it; its child teams move up"),
264 a("list_members", Op::ListTeamMembers, "Its people and their roles, child teams' with include_child_teams"),
265 a("set_member", Op::SetTeamMember, "Add a member of the workspace, or change their role"),
266 a("remove_member", Op::RemoveTeamMember, "Take someone out of it"),
267 a("list_child_teams", Op::ListChildTeams, "The teams nested under it"),
268 a("list_repos", Op::ListTeamRepos, "The repositories it has a role on"),
269 a("set_repo", Op::SetTeamRepo, "Give it a role on a repository"),
270 a("remove_repo", Op::RemoveTeamRepo, "Take its role on a repository away"),
271 a("set_review_assignment", Op::SetTeamReviewAssignment, "Whom it picks when asked to review"),
272 a("list_user_teams", Op::ListUserTeams, "The teams someone is in"),
273 ],
274 },
275 Tool {
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step276 name: "workspace",
277 title: "Workspaces",
Merge branch 'projects-kind-and-links'278 description: "Workspaces own repositories (g1t.sh/{workspace}/{repo}): create, update or delete one, invite members, connect integrations and model providers, set rulesets that hold across its repositories, read and change its projects (what each is, where it runs, its links), and keep your own pinned projects at the top of its sidebar.",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step279 default_action: None,
280 actions: &[
Merge branch 'worktree-agent-ad7c6d88d93adc817'281 a("get", Op::GetWorkspace, "A workspace's details and settings"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step282 a("create", Op::CreateWorkspace, "Create a workspace"),
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member283 a("delete", Op::DeleteWorkspace, "Delete a workspace and everything in it (support can restore it for 30 days)"),
Merge branch 'worktree-agent-ad7c6d88d93adc817'284 a("update", Op::UpdateWorkspace, "Change its name, description, base permission or who may create teams"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step285 a("list_invites", Op::ListWorkspaceInvites, "Its invites"),
286 a("invite_member", Op::InviteMember, "Invite an email address"),
287 a("revoke_invite", Op::RevokeWorkspaceInvite, "Revoke a pending invite"),
288 a("list_integrations", Op::ListIntegrations, "Model providers, alert sources, trackers"),
289 a("connect_integration", Op::ConnectIntegration, "Connect one"),
290 a("disconnect_integration", Op::DisconnectIntegration, "Remove one"),
291 a("test_integration", Op::TestIntegration, "Check its credentials"),
292 a("get_model_routes", Op::GetModelRoutes, "Where each kind of work's model requests go"),
293 a("set_model_routes", Op::SetModelRoutes, "Replace them"),
Merge branch 'projects-kind-and-links'294 a("list_projects", Op::ListProjects, "Its projects you can see: what each is, where it runs, its links"),
295 a("get_project", Op::GetProject, "One project"),
296 a("update_project", Op::UpdateProject, "Change a project's name, description, kind, where it runs or its links"),
API: pinned projects over REST and MCP297 a("list_pinned_projects", Op::ListPinnedProjects, "Your pinned projects in it, in your order"),
298 a("pin_project", Op::PinProject, "Pin a project, at a position or the end"),
299 a("unpin_project", Op::UnpinProject, "Unpin a project"),
300 a("reorder_pinned_projects", Op::ReorderPinnedProjects, "Put your pins in a new order"),
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge301 a("list_rulesets", Op::Rules(RulesOp::ListWorkspaceRulesets), "Its rulesets, which hold across its repositories"),
302 a("get_ruleset", Op::Rules(RulesOp::GetWorkspaceRuleset), "One of its rulesets"),
303 a("create_ruleset", Op::Rules(RulesOp::CreateWorkspaceRuleset), "Create a ruleset for some or all of its repositories"),
304 a("update_ruleset", Op::Rules(RulesOp::UpdateWorkspaceRuleset), "Change one of its rulesets"),
305 a("delete_ruleset", Op::Rules(RulesOp::DeleteWorkspaceRuleset), "Delete one of its rulesets"),
306 a("rule_evaluations", Op::Rules(RulesOp::ListWorkspaceRuleEvaluations), "How rules judged changes across its repositories"),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step307 ],
308 },
309 Tool {
Usage, Billing settings and prepaid AI credit; fixes from the UX audit310 name: "billing",
311 title: "Billing",
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens312 description: "A workspace's billing: its usage by product, project and day, its budget (the monthly spend limit, alerts and whether usage pauses at it), its AI credit, its invoices, and its AI Gateway requests. Amounts are whole millionths of a dollar (`_micros`), or cents (`_cents`) where named. Members read it; changing the budget and buying credit are for owners, as people, and never for g1t's agents.",
Usage, Billing settings and prepaid AI credit; fixes from the UX audit313 default_action: Some("usage"),
314 actions: &[
315 a("usage", Op::GetUsage, "Usage over a range of days, by product, meter, project and day, and what paid for it"),
316 a("budget", Op::GetBudget, "The monthly spend limit, what was spent, alerts and whether usage pauses at the limit"),
317 a("set_budget", Op::SetBudget, "Change the spend limit, alerts, pausing or the alert webhook"),
318 a("ai_credit", Op::GetAiCredit, "AI credit left, its grants, auto-reload and how to buy more"),
319 a("buy_ai_credit", Op::BuyAiCredit, "A payment page to buy AI credit, for a person to open"),
320 a("invoices", Op::ListInvoices, "Every invoice, the itemised usage invoices, and the next one so far"),
321 a("billing_details", Op::GetBillingDetails, "Who invoices are made out to and the payment method on file"),
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens322 a("gateway_requests", Op::ListGatewayRequests, "Recent AI Gateway requests: model, tokens, cost, status and token"),
Usage, Billing settings and prepaid AI credit; fixes from the UX audit323 ],
324 },
325 Tool {
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar326 name: "security",
327 title: "Security",
328 description: "A repository's security: secret scanning alerts and push protection bypasses, custom secret patterns, code scanning alerts and SARIF uploads, vulnerability alerts, the dependency graph and its SBOM, dependency review, settings, and a workspace's overview. Fix an alert with g1t. Findings are shown to those who can change the code only. Give `repo` (owner/name), or `workspace` for lists across one.",
329 default_action: Some("secret_alerts"),
330 actions: &[
331 a("secret_alerts", Op::Security(SecurityOp::ListSecretAlerts), "Secret scanning alerts; by state, secret_type, validity, bypassed"),
332 a("secret_alert", Op::Security(SecurityOp::GetSecretAlert), "One secret alert, with where it was found and its bypass requests"),
333 a("update_secret_alert", Op::Security(SecurityOp::UpdateSecretAlert), "Dismiss a secret alert with a reason, or reopen it"),
334 a("secret_locations", Op::Security(SecurityOp::ListSecretLocations), "Every file, line and commit a secret is in"),
335 a("bypass", Op::Security(SecurityOp::BypassPushProtection), "Push past push protection with a reason, or ask to"),
336 a("check_validity", Op::Security(SecurityOp::CheckSecretValidity), "Ask a secret's issuer whether it still works"),
337 a("bypass_requests", Op::Security(SecurityOp::ListBypassRequests), "A workspace's push protection bypass requests"),
338 a("review_bypass", Op::Security(SecurityOp::ReviewBypassRequest), "Approve, deny or cancel a bypass request"),
339 a("patterns", Op::Security(SecurityOp::ListCustomPatterns), "Custom secret patterns of a repository or workspace"),
340 a("create_pattern", Op::Security(SecurityOp::CreateCustomPattern), "Create a custom secret pattern, as a draft or published"),
341 a("update_pattern", Op::Security(SecurityOp::UpdateCustomPattern), "Change, publish or unpublish a custom pattern"),
342 a("delete_pattern", Op::Security(SecurityOp::DeleteCustomPattern), "Delete a custom pattern"),
343 a("dry_run_pattern", Op::Security(SecurityOp::DryRunCustomPattern), "Run a pattern over the default branch without saving it"),
344 a("code_alerts", Op::Security(SecurityOp::ListCodeAlerts), "Code scanning alerts; by state, severity, tool, rule_id"),
345 a("code_alert", Op::Security(SecurityOp::GetCodeAlert), "One code scanning alert by number"),
346 a("update_code_alert", Op::Security(SecurityOp::UpdateCodeAlert), "Dismiss a code scanning alert with a reason, or reopen it"),
347 a("analyses", Op::Security(SecurityOp::ListAnalyses), "Code scanning analyses, newest first"),
348 a("upload_sarif", Op::Security(SecurityOp::UploadSarif), "Upload a SARIF file, gzipped and base64-encoded"),
349 a("sarif_upload", Op::Security(SecurityOp::GetSarifUpload), "Whether a SARIF upload was read, and its analyses"),
350 a("vulnerability_alerts", Op::Security(SecurityOp::ListVulnerabilityAlerts), "Vulnerable dependencies; by state, severity, ecosystem, package"),
351 a("vulnerability_alert", Op::Security(SecurityOp::GetVulnerabilityAlert), "One vulnerability alert"),
352 a("update_vulnerability_alert", Op::Security(SecurityOp::UpdateVulnerabilityAlert), "Dismiss a vulnerability alert with a reason, or reopen it"),
353 a("fix", Op::Security(SecurityOp::FixAlert), "Put g1t on an issue to fix an alert"),
354 a("dependency_graph", Op::Security(SecurityOp::GetDependencyGraph), "Every package the lockfiles resolve, direct or transitive"),
355 a("sbom", Op::Security(SecurityOp::GetSbom), "The dependency graph as an SPDX 2.3 document"),
356 a("compare_dependencies", Op::Security(SecurityOp::CompareDependencies), "What changes in dependencies between base...head"),
357 a("settings", Op::Security(SecurityOp::GetSettings), "A repository's security settings"),
358 a("update_settings", Op::Security(SecurityOp::UpdateSettings), "Change when checks fail and dependency review's policy"),
359 a("workspace_settings", Op::Security(SecurityOp::GetWorkspaceSettings), "A workspace's delegated bypass and validity checks"),
360 a("update_workspace_settings", Op::Security(SecurityOp::UpdateWorkspaceSettings), "Turn delegated bypass or validity checks on or off"),
361 a("overview", Op::Security(SecurityOp::GetOverview), "A workspace's alerts, trends and coverage"),
362 ],
363 },
364 Tool {
API: notifications over REST and MCP, with notifications scopes365 name: "notifications",
366 title: "Notifications",
367 description: "Your inbox: what needs you, and what you follow. One thread per issue, pull request, workflow or deployment, with why you were told (`reason`): an agent waiting on you, a review asked of you, an assignment, a mention, your work's checks, or what you subscribe to and watch. Mark threads read or done once handled, and choose what you hear of with subscribe, unsubscribe and watch. Your own: a personal token.",
368 default_action: Some("list"),
369 actions: &[
370 a("list", Op::ListNotifications, "Unread threads, latest first; all, a view, a reason, a repository"),
371 a("get", Op::GetNotificationThread, "One thread with its recent activity and your subscription"),
372 a("mark_read", Op::MarkThreadRead, "Mark a thread read, or unread"),
373 a("mark_all_read", Op::MarkNotificationsRead, "Mark everything read up to a time, or one repository's"),
374 a("done", Op::MarkThreadDone, "Mark a thread done; new activity brings it back"),
375 a("save", Op::SaveThread, "Save a thread, or unsave it"),
376 a("snooze", Op::SnoozeThread, "Snooze a thread until a time, or bring it back"),
377 a("subscription", Op::GetThreadSubscription, "Your subscription to an issue or pull request"),
378 a("subscribe", Op::SetThreadSubscription, "Subscribe to an issue or pull request, or ignore it"),
379 a("unsubscribe", Op::DeleteThreadSubscription, "Unsubscribe until you comment or are mentioned"),
380 a("watching", Op::GetRepoSubscription, "How you watch a repository"),
381 a("watch", Op::SetRepoSubscription, "Watch a repository: participating, all, ignore or custom"),
382 a("unwatch", Op::DeleteRepoSubscription, "Stop watching a repository"),
383 a("watched", Op::ListWatchedRepos, "Repositories you watch other than the default way"),
384 ],
385 },
386 Tool {
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step387 name: "account",
388 title: "Your account",
389 description: "Who this token acts as and its workspaces (`whoami`), your email addresses, your invites, and invitations to repositories waiting for you.",
390 default_action: Some("whoami"),
391 actions: &[
392 a("whoami", Op::Whoami, "Who the token acts as, and its workspaces"),
393 a("list_emails", Op::ListEmails, "Your addresses"),
394 a("add_email", Op::AddEmail, "Add an address"),
395 a("remove_email", Op::RemoveEmail, "Remove an address"),
396 a("update_email_settings", Op::UpdateEmailSettings, "Primary, backup and privacy"),
397 a("list_invites", Op::ListInvites, "Your invites to g1t"),
398 a("create_invite", Op::CreateInvite, "Make an invite"),
399 a("revoke_invite", Op::RevokeInvite, "Revoke one"),
400 a("list_repository_invitations", Op::ListMyRepoInvitations, "Invitations to repositories for you"),
401 a("accept_repository_invitation", Op::AcceptRepoInvitation, "Accept one"),
402 a("decline_repository_invitation", Op::DeclineRepoInvitation, "Decline one"),
403 ],
404 },
405];
406
407/// Operations that cannot be undone, or reach beyond g1t's own records:
408/// clients ask before running a tool that has any of them.
409fn destructive(op: Op) -> bool {
410 matches!(
411 op,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar412 Op::Security(SecurityOp::DeleteCustomPattern | SecurityOp::BypassPushProtection)
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge413 | Op::Rules(RulesOp::DeleteRepoRuleset | RulesOp::DeleteWorkspaceRuleset)
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar414 | Op::DeleteWorkspace
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily415 | Op::UpdateWorkspace
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step416 | Op::DeleteRepo
417 | Op::PurgeRepo
418 | Op::TransferRepo
419 | Op::SetRepoVisibility
420 | Op::RemoveEmail
421 | Op::RemoveCollaborator
422 | Op::DisconnectIntegration
423 | Op::DeleteWebhook
424 | Op::DeleteActionsSecret
425 | Op::DeleteActionsVariable
426 | Op::SetActionsSecret
427 | Op::SetActionsVariable
428 | Op::SetModelRoutes
429 | Op::SetBasePermission
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar430 | Op::DeleteTeam
431 | Op::RemoveTeamRepo
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step432 | Op::MergePullRequest
Fast pages, required checks on the branch, self-hosted runners, honest incidents433 | Op::RemoveRunner
434 | Op::DeleteRunnerGroup
435 | Op::UpdateRunnerSettings
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step436 )
437}
438
439/// Whether an operation only reads.
440pub fn reads_only(op: Op) -> bool {
441 NO_SCOPE.contains(&op.name())
442 || scope_for(op.name()).is_some_and(|scope| scope.level() == Level::Read)
443}
444
445/// What decides which actions a caller sees.
446pub enum Gate<'a> {
447 /// No limit beyond the person's own role.
448 Everything,
449 /// A g1t agent's token: the operations its run lists.
450 Agent(&'a AgentScope),
451 /// An access token with scopes.
452 Token(&'a TokenAccess),
453}
454
455impl Gate<'_> {
456 pub fn allows(&self, op: Op) -> bool {
457 match self {
458 Gate::Everything => true,
459 Gate::Agent(scope) => op.allowed_by(scope) && !NEVER.contains(&op.name()),
460 Gate::Token(access) => {
461 if NO_SCOPE.contains(&op.name()) {
462 return true;
463 }
464 match scope_for(op.name()) {
465 Some(scope) => access.allows(scope),
466 None => access.scopes.is_none(),
467 }
468 }
469 }
470 }
471}
472
473impl Tool {
474 pub fn by_name(name: &str) -> Option<&'static Tool> {
475 TOOLS.iter().find(|tool| tool.name == name)
476 }
477
478 pub fn action(&self, name: &str) -> Option<&'static Action> {
479 // The tools are 'static; find through TOOLS to keep the lifetime.
480 TOOLS
481 .iter()
482 .find(|tool| tool.name == self.name)
483 .and_then(|tool| tool.actions.iter().find(|action| action.name == name))
484 }
485
486 pub fn visible(&self, gate: &Gate) -> Vec<&'static Action> {
487 TOOLS
488 .iter()
489 .find(|tool| tool.name == self.name)
490 .map(|tool| tool.actions.iter().filter(|action| gate.allows(action.op)).collect())
491 .unwrap_or_default()
492 }
493
494 /// The flat input schema of the actions given.
495 pub fn input_schema(&self, actions: &[&Action]) -> Value {
496 let mut properties = Map::new();
497 let lines: Vec<String> = actions
498 .iter()
499 .map(|action| {
500 let required: Vec<String> = action.op.required();
501 if required.is_empty() {
502 format!("{}: {}.", action.name, action.summary)
503 } else {
504 format!("{} ({}): {}.", action.name, required.join(", "), action.summary)
505 }
506 })
507 .collect();
508 let mut action_schema = json!({
509 "type": "string",
510 "enum": actions.iter().map(|action| action.name).collect::<Vec<_>>(),
511 "description": lines.join("\n"),
512 });
513 if let Some(default) = self.default_action.filter(|name| actions.iter().any(|action| action.name == *name)) {
514 action_schema["default"] = json!(default);
515 }
516 properties.insert("action".to_owned(), action_schema);
517 for action in actions {
518 for (name, schema) in action.op.properties() {
519 merge_property(&mut properties, name, schema);
520 }
521 }
522 let mut required = vec![];
523 if self.default_action.is_none() {
524 required.push("action");
525 }
526 let mut schema = json!({ "type": "object", "properties": properties });
527 if !required.is_empty() {
528 schema["required"] = json!(required);
529 }
530 schema
531 }
532
533 /// The input schema keyed by action: one `oneOf` branch per action,
534 /// each with its own fields and the ones it needs.
535 pub fn discriminated(&self, actions: &[&Action]) -> Value {
536 let branches: Vec<Value> = actions
537 .iter()
538 .map(|action| {
539 let mut properties = Map::new();
540 properties.insert("action".to_owned(), json!({ "const": action.name }));
541 properties.extend(action.op.properties());
542 let mut required = vec![Value::String("action".to_owned())];
543 // The default action may leave `action` out.
544 if self.default_action == Some(action.name) {
545 required.clear();
546 }
547 required.extend(action.op.required().into_iter().map(Value::String));
548 json!({
549 "title": action.name,
550 "description": action.summary,
551 "type": "object",
552 "properties": properties,
553 "required": required,
554 })
555 })
556 .collect();
557 json!({ "type": "object", "oneOf": branches })
558 }
559
560 /// MCP's hints about the actions given: whether the tool only reads,
561 /// whether it can destroy something, and whether calling it twice is
562 /// the same as once.
563 pub fn annotations(&self, actions: &[&Action]) -> Value {
564 let read_only = actions.iter().all(|action| reads_only(action.op));
565 json!({
566 "title": self.title,
567 "readOnlyHint": read_only,
568 "destructiveHint": !read_only && actions.iter().any(|action| destructive(action.op)),
569 "idempotentHint": read_only,
570 "openWorldHint": false,
571 })
572 }
573
574 /// The tool as `tools/list` gives it, for a caller behind `gate`, or
575 /// `None` when it may use none of its actions.
576 pub fn listed(&self, gate: &Gate) -> Option<Value> {
577 let actions = self.visible(gate);
578 if actions.is_empty() {
579 return None;
580 }
581 Some(json!({
582 "name": self.name,
583 "title": self.title,
584 "description": self.description,
585 "inputSchema": self.input_schema(&actions),
586 "annotations": self.annotations(&actions),
587 }))
588 }
589}
590
591/// Adds a property to a tool's flat schema. The first action to use a name
592/// describes it; a later one with other allowed values adds them.
593fn merge_property(properties: &mut Map<String, Value>, name: String, schema: Value) {
594 match properties.get_mut(&name) {
595 None => {
596 properties.insert(name, schema);
597 }
598 Some(existing) => {
599 if let (Some(Value::Array(had)), Some(Value::Array(more))) =
600 (existing.get("enum").cloned(), schema.get("enum"))
601 {
602 let mut merged = had;
603 for value in more {
604 if !merged.contains(value) {
605 merged.push(value.clone());
606 }
607 }
608 existing["enum"] = Value::Array(merged);
609 }
610 // Different kinds of value under one name: say less, accept both.
611 if existing.get("type") != schema.get("type")
612 && let Some(fields) = existing.as_object_mut()
613 {
614 fields.remove("type");
615 fields.remove("items");
616 }
617 }
618 }
619}
620
621/// What a call to a tool runs: the operation its action names, or why not.
622pub fn resolve(tool: &Tool, arguments: &Value) -> Result<Op, String> {
623 let names = || {
624 tool.actions
625 .iter()
626 .map(|action| action.name)
627 .collect::<Vec<_>>()
628 .join(", ")
629 };
630 let Some(name) = arguments["action"].as_str().or(tool.default_action) else {
631 return Err(format!("Give an action: one of {}.", names()));
632 };
633 let Some(action) = tool.action(name) else {
634 return Err(format!("{} has no action {name}. Its actions: {}.", tool.name, names()));
635 };
636 let missing: Vec<String> = action
637 .op
638 .required()
639 .into_iter()
640 .filter(|field| arguments.get(field).is_none_or(Value::is_null))
641 .collect();
642 if !missing.is_empty() {
643 return Err(format!("{}.{name} needs {}.", tool.name, missing.join(", ")));
644 }
645 Ok(action.op)
646}
647
648#[cfg(test)]
649mod tests {
650 use super::*;
651 use g1t_contracts::scopes::{Preset, Scope};
652
653 fn listed(gate: &Gate) -> Vec<Value> {
654 TOOLS.iter().filter_map(|tool| tool.listed(gate)).collect()
655 }
656
657 fn token(scopes: Option<Vec<Scope>>) -> TokenAccess {
658 TokenAccess {
659 token_id: "tok_1".to_owned(),
660 scopes: scopes.map(|scopes| scopes.iter().map(|scope| scope.as_str().to_owned()).collect()),
661 legacy: false,
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens662 name: None,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step663 }
664 }
665
666 #[test]
667 fn every_operation_is_exactly_one_action_of_one_tool() {
668 for op in Op::ALL {
669 let count = TOOLS
670 .iter()
671 .flat_map(|tool| tool.actions.iter())
672 .filter(|action| action.op == op)
673 .count();
674 assert_eq!(count, 1, "{} is {count} actions", op.name());
675 }
676 for tool in TOOLS {
677 let mut names = std::collections::HashSet::new();
678 for action in tool.actions {
679 assert!(names.insert(action.name), "{}.{} twice", tool.name, action.name);
680 }
681 if let Some(default) = tool.default_action {
682 assert!(tool.action(default).is_some(), "{}", tool.name);
683 }
684 }
Usage, Billing settings and prepaid AI credit; fixes from the UX audit685 assert!(TOOLS.len() <= 17, "{} tools", TOOLS.len());
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step686 }
687
688 #[test]
689 fn every_operation_needs_exactly_one_scope_or_none() {
690 use g1t_contracts::scopes::OPERATIONS;
691 for op in Op::ALL {
692 let mapped = OPERATIONS.iter().filter(|(name, _)| *name == op.name()).count();
693 let free = NO_SCOPE.contains(&op.name());
694 assert_eq!(mapped + usize::from(free), 1, "{}", op.name());
695 }
696 for (name, _) in OPERATIONS {
697 assert!(Op::by_name(name).is_some(), "{name} is not an operation");
698 }
699 }
700
701 #[test]
702 fn each_tool_schema_is_valid_with_one_branch_per_action() {
703 for tool in TOOLS {
704 let actions: Vec<&Action> = tool.actions.iter().collect();
705 let flat = tool.input_schema(&actions);
706 assert_eq!(flat["type"], "object");
707 assert!(flat.get("oneOf").is_none(), "no oneOf at the top level");
708 let listed: Vec<&str> = flat["properties"]["action"]["enum"]
709 .as_array()
710 .unwrap()
711 .iter()
712 .map(|name| name.as_str().unwrap())
713 .collect();
714 assert_eq!(listed, tool.actions.iter().map(|action| action.name).collect::<Vec<_>>());
715 for action in tool.actions {
716 for field in action.op.required() {
717 assert!(flat["properties"].get(&field).is_some(), "{}.{}: {field}", tool.name, action.name);
718 }
719 }
720 let keyed = tool.discriminated(&actions);
721 let branches = keyed["oneOf"].as_array().unwrap();
722 assert_eq!(branches.len(), tool.actions.len());
723 for (branch, action) in branches.iter().zip(tool.actions) {
724 assert_eq!(branch["properties"]["action"]["const"], action.name);
725 for field in branch["required"].as_array().unwrap() {
726 assert!(branch["properties"].get(field.as_str().unwrap()).is_some(), "{}.{}: {field}", tool.name, action.name);
727 }
728 }
729 // A well-formed JSON Schema object throughout.
730 let text = serde_json::to_string(&flat).unwrap();
731 assert!(serde_json::from_str::<Value>(&text).is_ok());
732 }
733 }
734
735 #[test]
736 fn a_read_only_token_sees_read_actions_only() {
737 let access = token(Preset::ReadOnly.scopes());
738 let gate = Gate::Token(&access);
739 for tool in TOOLS {
740 for action in tool.visible(&gate) {
741 assert!(reads_only(action.op), "{}.{}", tool.name, action.name);
742 }
743 }
744 let tools = listed(&gate);
745 for tool in &tools {
746 assert_eq!(tool["annotations"]["readOnlyHint"], true, "{}", tool["name"]);
747 assert_eq!(tool["annotations"]["destructiveHint"], false);
748 }
749 let issue = tools.iter().find(|tool| tool["name"] == "issue").unwrap();
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar750 assert_eq!(issue["inputSchema"]["properties"]["action"]["enum"], json!(["list", "get", "labels"]));
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step751 // Nothing of the agent tool is a read.
752 assert!(!tools.iter().any(|tool| tool["name"] == "agent"));
753 }
754
755 #[test]
756 fn a_narrow_token_sees_only_its_tools() {
757 let access = token(Some(vec![Scope::IssuesWrite]));
758 let names: Vec<Value> = listed(&Gate::Token(&access)).into_iter().map(|tool| tool["name"].clone()).collect();
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar759 // Labels and milestones are the repository's, managed with issues:write.
760 assert_eq!(names, vec![json!("repository"), json!("issue"), json!("plan"), json!("account")]);
API: notifications over REST and MCP, with notifications scopes761 // Notifications are a resource of their own: reading them lists
762 // only what reads.
763 let reader = token(Some(vec![Scope::NotificationsRead]));
764 let tools = listed(&Gate::Token(&reader));
765 let notifications = tools.iter().find(|tool| tool["name"] == "notifications").unwrap();
766 assert_eq!(
767 notifications["inputSchema"]["properties"]["action"]["enum"],
768 json!(["list", "get", "subscription", "watching", "watched"])
769 );
770 assert_eq!(notifications["annotations"]["readOnlyHint"], true);
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step771 let full = token(None);
772 assert_eq!(listed(&Gate::Token(&full)).len(), TOOLS.len());
773 assert_eq!(listed(&Gate::Everything).len(), TOOLS.len());
774 }
775
776 #[test]
777 fn a_tool_that_can_destroy_says_so() {
778 let tools = listed(&Gate::Everything);
779 let repository = tools.iter().find(|tool| tool["name"] == "repository").unwrap();
780 assert_eq!(repository["annotations"]["destructiveHint"], true);
781 assert_eq!(repository["annotations"]["readOnlyHint"], false);
782 let memory = tools.iter().find(|tool| tool["name"] == "memory").unwrap();
783 assert_eq!(memory["annotations"]["destructiveHint"], false);
784 }
785
786 #[test]
787 fn calls_resolve_to_their_operation_or_say_what_is_missing() {
788 let issue = Tool::by_name("issue").unwrap();
789 assert_eq!(resolve(issue, &json!({ "action": "get", "repo": "a/b", "number": 1 })), Ok(Op::GetIssue));
790 assert_eq!(resolve(issue, &json!({ "action": "get", "repo": "a/b" })), Err("issue.get needs number.".to_owned()));
791 assert!(resolve(issue, &json!({})).unwrap_err().starts_with("Give an action"));
792 assert!(resolve(issue, &json!({ "action": "explode" })).unwrap_err().contains("no action explode"));
793 let search = Tool::by_name("search").unwrap();
794 assert_eq!(resolve(search, &json!({ "query": "x" })), Ok(Op::Search));
795 let account = Tool::by_name("account").unwrap();
796 assert_eq!(resolve(account, &json!({})), Ok(Op::Whoami));
797 }
798
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar799 #[test]
800 fn teams_are_one_tool_and_a_workspace_reader_sees_only_its_reads() {
801 let team = Tool::by_name("team").unwrap();
802 let names: Vec<&str> = team.actions.iter().map(|action| action.name).collect();
803 assert_eq!(
804 names,
805 [
806 "list",
807 "get",
808 "create",
809 "update",
810 "delete",
811 "list_members",
812 "set_member",
813 "remove_member",
814 "list_child_teams",
815 "list_repos",
816 "set_repo",
817 "remove_repo",
818 "set_review_assignment",
819 "list_user_teams",
820 ]
821 );
822 let reader = token(Some(vec![Scope::WorkspaceRead]));
823 let tools = listed(&Gate::Token(&reader));
824 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
825 assert_eq!(
826 listed_team["inputSchema"]["properties"]["action"]["enum"],
827 json!(["list", "get", "list_members", "list_child_teams", "list_repos", "list_user_teams"])
828 );
829 assert_eq!(listed_team["annotations"]["readOnlyHint"], true);
830 // A team's role on a repository is who has access.
831 let admin = token(Some(vec![Scope::WorkspaceAdmin]));
832 let tools = listed(&Gate::Token(&admin));
833 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
834 let actions = listed_team["inputSchema"]["properties"]["action"]["enum"].as_array().unwrap();
835 assert!(actions.contains(&json!("set_review_assignment")) && !actions.contains(&json!("set_repo")));
836 let access = token(Some(vec![Scope::AccessAdmin]));
837 let tools = listed(&Gate::Token(&access));
838 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
839 assert_eq!(listed_team["inputSchema"]["properties"]["action"]["enum"], json!(["set_repo", "remove_repo"]));
840 // Both kinds of role a schema names are offered.
841 let roles = &listed(&Gate::Everything).into_iter().find(|tool| tool["name"] == "team").unwrap()["inputSchema"]
842 ["properties"]["role"]["enum"];
843 for role in ["member", "maintainer", "read", "admin"] {
844 assert!(roles.as_array().unwrap().contains(&json!(role)), "{role}");
845 }
846 assert_eq!(
847 resolve(team, &json!({ "action": "set_repo", "workspace": "acme", "team": "backend", "repo": "rocket" })),
848 Err("team.set_repo needs role.".to_owned())
849 );
850 }
851
852 #[test]
853 fn reviewers_and_code_owners_are_actions_of_their_tools() {
854 let pull = Tool::by_name("pull_request").unwrap();
855 assert_eq!(
856 resolve(pull, &json!({ "action": "request_reviewers", "repo": "a/b", "number": 1, "team_reviewers": ["backend"] })),
857 Ok(Op::RequestReviewers)
858 );
859 assert_eq!(pull.action("remove_requested_reviewers").map(|action| action.op), Some(Op::RemoveRequestedReviewers));
860 let repository = Tool::by_name("repository").unwrap();
861 assert_eq!(resolve(repository, &json!({ "action": "codeowners", "repo": "a/b" })), Ok(Op::GetCodeownersErrors));
862 assert!(reads_only(Op::GetCodeownersErrors));
863 assert!(!reads_only(Op::RequestReviewers));
864 }
865
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step866 /// How much smaller `tools/list` is than one tool per operation. Run
867 /// with `--nocapture` to see the numbers.
868 #[test]
869 fn the_tool_list_is_much_smaller_than_one_tool_per_operation() {
870 let before: Vec<Value> = Op::ALL
871 .into_iter()
872 .map(|op| json!({ "name": op.name(), "description": op.description(), "inputSchema": op.input() }))
873 .collect();
874 let after = listed(&Gate::Everything);
875 let before_bytes = serde_json::to_string(&json!({ "tools": before })).unwrap().len();
876 let after_bytes = serde_json::to_string(&json!({ "tools": after })).unwrap().len();
877 let agent = token(Preset::Agent.scopes());
878 let agent_bytes = serde_json::to_string(&json!({ "tools": listed(&Gate::Token(&agent)) })).unwrap().len();
879 let read = token(Preset::ReadOnly.scopes());
880 let read_bytes = serde_json::to_string(&json!({ "tools": listed(&Gate::Token(&read)) })).unwrap().len();
881 println!(
882 "tools/list: before {} tools, {before_bytes} bytes (~{} tokens); after {} tools, {after_bytes} bytes (~{} tokens); agent preset {agent_bytes} bytes (~{} tokens); read only {read_bytes} bytes (~{} tokens)",
883 before.len(),
884 before_bytes / 4,
885 after.len(),
886 after_bytes / 4,
887 agent_bytes / 4,
888 read_bytes / 4,
889 );
890 assert!(after_bytes * 2 < before_bytes, "{after_bytes} vs {before_bytes}");
891 }
892}

This file's history is long; its oldest lines are credited to the oldest commit read.