Skip to content
947 linesCodeBlameRaw
1//! The MCP server's tools: a few resource tools, each with an `action`.
2//!
3//! Every operation is one action of one tool. A call is dispatched to the
4//! operation it names, so permissions, the audit log, billing and outcomes
5//! are exactly those of the REST API. A token sees only the actions its
6//! scopes allow, and a tool none of whose actions it may use is not listed.
7//!
8//! The listed input schema is one flat object: `action`, then every field
9//! any of its actions takes. Which fields each action needs is in the
10//! `action` field's description and checked on every call. Claude's API,
11//! and so most MCP clients, refuse a tool whose input schema has `oneOf`
12//! at its top level, so the schema keyed by action, with each action's
13//! required fields, is [`discriminated`], published on the server's card
14//! and in the docs.
15
16use g1t_contracts::credentials::NEVER;
17use g1t_contracts::identity::AgentScope;
18use g1t_contracts::scopes::{Level, NO_SCOPE, TokenAccess, scope_for};
19use serde_json::{Map, Value, json};
20
21use crate::about::AboutOp;
22use crate::artifacts::ArtifactsOp;
23use crate::deployments::DeploymentsOp;
24use crate::operations::Op;
25use crate::checks::ChecksOp;
26use crate::rules::RulesOp;
27use crate::security::SecurityOp;
28
29pub struct Action {
30 pub name: &'static str,
31 pub op: Op,
32 /// One line, for the `action` field's description.
33 pub summary: &'static str,
34}
35
36pub struct Tool {
37 pub name: &'static str,
38 pub title: &'static str,
39 /// What it is for, in a sentence or two.
40 pub description: &'static str,
41 pub actions: &'static [Action],
42 /// The action a call without one runs.
43 pub default_action: Option<&'static str>,
44}
45
46const fn a(name: &'static str, op: Op, summary: &'static str) -> Action {
47 Action { name, op, summary }
48}
49
50pub const TOOLS: &[Tool] = &[
51 Tool {
52 name: "search",
53 title: "Search",
54 description: "Find things. `code` (the default) searches all of g1t you can see: repositories, code, issues, pull requests and people, with qualifiers like repo:owner/name, language:rust, is:issue. `context` searches one workspace's catalog, docs, issues and memory by meaning.",
55 default_action: Some("code"),
56 actions: &[
57 a("code", Op::Search, "Search all of g1t: repositories, code, issues, pull requests, people"),
58 a("context", Op::SearchContext, "Search a workspace's context hub by meaning"),
59 a("entity", Op::GetEntity, "One catalog entry and its relations"),
60 a("ticket", Op::GetContext, "A Jira, Linear or Sentry item the work refers to, as it is now"),
61 ],
62 },
63 Tool {
64 name: "repository",
65 title: "Repositories",
66 description: "Repositories: find, read and create them, change their settings and rulesets (what may happen to branches and tags, and what a pull request needs to merge), check their CODEOWNERS file, manage their labels and milestones, see and dismiss their security alerts (secrets and vulnerable dependencies), read what their default branch says (languages, contributors, license), star them, and publish releases. Name one as \"owner/name\". Deleting, transferring and changing visibility need `confirm`.",
67 default_action: None,
68 actions: &[
69 a("list", Op::ListRepos, "Repositories you can see"),
70 a("get", Op::GetRepo, "One repository"),
71 a("create", Op::CreateRepo, "Create one, empty or copied from a public git URL"),
72 a("update", Op::UpdateRepo, "Change description, website, topics, default branch, protection"),
73 a("get_settings", Op::GetRepoSettings, "How pull requests merge, and the default branch's protection as its rules stack"),
74 a("update_settings", Op::UpdateRepoSettings, "Change how pull requests merge and the default branch protection ruleset"),
75 a("check_names", Op::ListCheckNames, "Check names reported lately, to require in a ruleset"),
76 a("list_rulesets", Op::Rules(RulesOp::ListRepoRulesets), "Its rulesets, and its workspace's that hold in it"),
77 a("get_ruleset", Op::Rules(RulesOp::GetRepoRuleset), "One ruleset"),
78 a("create_ruleset", Op::Rules(RulesOp::CreateRepoRuleset), "Create a ruleset for its branches or tags"),
79 a("update_ruleset", Op::Rules(RulesOp::UpdateRepoRuleset), "Change a ruleset"),
80 a("delete_ruleset", Op::Rules(RulesOp::DeleteRepoRuleset), "Delete a ruleset"),
81 a("branch_rules", Op::Rules(RulesOp::GetBranchRules), "Every rule that holds for a branch or tag, and where it comes from"),
82 a("rule_evaluations", Op::Rules(RulesOp::ListRuleEvaluations), "How its rules judged pushes and merges, with insights"),
83 a("codeowners", Op::GetCodeownersErrors, "Problems in its CODEOWNERS file, by line"),
84 a("list_labels", Op::ListLabels, "Labels, with colors and how many issues and pull requests carry each"),
85 a("create_label", Op::CreateLabel, "Create a label"),
86 a("update_label", Op::UpdateLabel, "Rename a label or change its color or description"),
87 a("delete_label", Op::DeleteLabel, "Delete a label, from everything that carries it"),
88 a("add_default_labels", Op::AddDefaultLabels, "Add the default labels it is missing"),
89 a("list_milestones", Op::ListMilestones, "Milestones, with progress and due dates"),
90 a("get_milestone", Op::GetMilestone, "One milestone with its issues and pull requests"),
91 a("create_milestone", Op::CreateMilestone, "Create a milestone"),
92 a("update_milestone", Op::UpdateMilestone, "Change a milestone's title, description, due date or state"),
93 a("delete_milestone", Op::DeleteMilestone, "Delete a milestone"),
94 a("list_events", Op::ListEvents, "Timeline: pushes, issues, pull requests, comments"),
95 a("languages", Op::About(AboutOp::GetLanguages), "Its languages by bytes, with colors and percentages"),
96 a("contributors", Op::About(AboutOp::ListContributors), "Who made it: commits per person, agent and author, by week"),
97 a("license", Op::About(AboutOp::GetLicense), "The license its LICENSE file holds"),
98 a("stargazers", Op::About(AboutOp::ListStargazers), "Who starred it"),
99 a("starred", Op::About(AboutOp::CheckStarred), "Whether you starred it, and how many have"),
100 a("star", Op::About(AboutOp::Star), "Star it"),
101 a("unstar", Op::About(AboutOp::Unstar), "Take your star back"),
102 a("list_starred", Op::About(AboutOp::ListStarred), "Repositories you starred"),
103 a("list_releases", Op::About(AboutOp::ListReleases), "Releases, newest first"),
104 a("latest_release", Op::About(AboutOp::GetLatestRelease), "The latest release"),
105 a("get_release", Op::About(AboutOp::GetRelease), "One release by id"),
106 a("get_release_by_tag", Op::About(AboutOp::GetReleaseByTag), "The release of a tag"),
107 a("create_release", Op::About(AboutOp::CreateRelease), "Publish a release of a tag, making the tag if needed"),
108 a("update_release", Op::About(AboutOp::UpdateRelease), "Change a release's title, notes, draft or prerelease"),
109 a("delete_release", Op::About(AboutOp::DeleteRelease), "Delete a release; its tag stays"),
110 a("rename_branch", Op::RenameBranch, "Rename a branch"),
111 a("rename", Op::RenameRepo, "Rename it; old addresses redirect"),
112 a("transfer", Op::TransferRepo, "Move it to another workspace you own"),
113 a("archive", Op::ArchiveRepo, "Make it read-only"),
114 a("unarchive", Op::UnarchiveRepo, "Make it writable again"),
115 a("set_visibility", Op::SetRepoVisibility, "Make it public or private"),
116 a("delete", Op::DeleteRepo, "Delete it; restorable for 30 days"),
117 a("list_deleted", Op::ListDeletedRepos, "A workspace's deleted repositories"),
118 a("restore", Op::RestoreRepo, "Restore a deleted one"),
119 a("purge", Op::PurgeRepo, "Remove a deleted one for good"),
120 a("security_alerts", Op::ListSecurityAlerts, "Secret and dependency alerts, filtered by state"),
121 a("dismiss_alert", Op::DismissSecurityAlert, "Dismiss an alert with a reason"),
122 a("reopen_alert", Op::ReopenSecurityAlert, "Reopen a dismissed alert"),
123 ],
124 },
125 Tool {
126 name: "issue",
127 title: "Issues",
128 description: "Issues: what should change. Read one before working on it to see the pull requests already made for it. Issues and pull requests share numbers; `comment` works on either.",
129 default_action: None,
130 actions: &[
131 a("list", Op::ListIssues, "Issues on a repository, newest first"),
132 a("get", Op::GetIssue, "One issue with comments and its pull requests"),
133 a("create", Op::CreateIssue, "Open an issue"),
134 a("update", Op::UpdateIssue, "Change title, body, labels, milestone or assignees"),
135 a("labels", Op::ListIssueLabels, "The labels an issue or pull request carries"),
136 a("add_labels", Op::AddIssueLabels, "Add labels to an issue or pull request"),
137 a("set_labels", Op::SetIssueLabels, "Replace the labels of an issue or pull request"),
138 a("remove_labels", Op::RemoveIssueLabels, "Take labels off an issue or pull request"),
139 a("close", Op::CloseIssue, "Close it without a pull request"),
140 a("reopen", Op::ReopenIssue, "Reopen it"),
141 a("comment", Op::AddComment, "Comment on an issue or pull request; path and line for one line of a change"),
142 a("import", Op::ImportIssue, "Open an issue from a Jira, Linear or Sentry item"),
143 ],
144 },
145 Tool {
146 name: "pull_request",
147 title: "Pull requests",
148 description: "Pull requests: start a change for an issue, record your session, mark it ready, ask people and teams to review, review and merge. Read `overlaps` and `behind` on `get` before going far, and `code_owners` for whose approval it needs.",
149 default_action: None,
150 actions: &[
151 a("list", Op::ListPullRequests, "Pull requests on a repository, newest first"),
152 a("get", Op::GetPullRequest, "Status, checks and required checks, reviews, overlaps, whether it is behind"),
153 a("changes", Op::GetPullRequestChanges, "Files and line-by-line diff"),
154 a("create", Op::CreatePullRequest, "Start a draft with its own fork to push to, or open one from a pushed branch"),
155 a("update", Op::UpdatePullRequest, "Change its base branch, labels, milestone, assignees or reviewers"),
156 a("record_session", Op::RecordSession, "Append prompt, reasoning and tool entries to its session"),
157 a("read_session", Op::ReadSession, "Its recorded session"),
158 a("ready", Op::MarkPullRequestReady, "Mark a draft ready, with a summary"),
159 a("request_reviewers", Op::RequestReviewers, "Ask people or teams to review it"),
160 a("remove_requested_reviewers", Op::RemoveRequestedReviewers, "Stop asking people or teams to review it"),
161 a("review", Op::ReviewPullRequest, "Approve or request changes"),
162 a("close", Op::ClosePullRequest, "Close without merging"),
163 a("merge", Op::MergePullRequest, "Land it, or join the merge queue"),
164 a("merge_queue", Op::GetMergeQueue, "The repository's merge queue"),
165 ],
166 },
167 Tool {
168 name: "agent",
169 title: "g1t agents",
170 description: "Put g1t's agent to work and talk to it. One agent per issue; to do more at once, use more issues. Starting an agent uses the workspace's money.",
171 default_action: None,
172 actions: &[
173 a("delegate", Op::Delegate, "Open an issue and put an agent on it in one step"),
174 a("assign", Op::AssignIssue, "Put an agent on an existing issue"),
175 a("message", Op::MessageAgent, "Tell the agent on a pull request something, or ask another agent"),
176 a("answer", Op::AnswerMessage, "Answer a question or handoff sent to you"),
177 a("take_messages", Op::TakeMessages, "For a g1t agent: messages not seen yet"),
178 ],
179 },
180 Tool {
181 name: "plan",
182 title: "Plans",
183 description: "Turn an outcome into issues: an agent proposes them with what done means and their dependencies; nothing opens until you apply the plan.",
184 default_action: None,
185 actions: &[
186 a("create", Op::PlanWork, "Ask an agent for a plan; read it with get until ready"),
187 a("get", Op::GetPlan, "A plan and the issues it proposes"),
188 a("apply", Op::ApplyPlan, "Open its issues; with assign, agents start in dependency order"),
189 ],
190 },
191 Tool {
192 name: "memory",
193 title: "Memory",
194 description: "What the project and its workspace remember for the next agent: how to build, conventions, decisions, traps. Recall before you start; remember one short fact at a time, never a secret.",
195 default_action: None,
196 actions: &[
197 a("recall", Op::Recall, "Search memory, or list it all"),
198 a("remember", Op::Remember, "Save one fact"),
199 ],
200 },
201 Tool {
202 name: "workflow",
203 title: "Workflows",
204 description: "GitHub Actions workflows from .g1t/workflows: their runs, jobs and logs, and running, cancelling or rerunning them. Runs' artifacts: listing, a download link, deleting, and how long they are kept. Deployments wherever they run (reported from any CI, made by jobs with an `environment:`, or built on g1t.page), their statuses and environments, and reporting your own. Checks on commits: statuses, check runs (a g1t Actions job is one) and check suites, to read where a commit stands or report on it from CI or an integration. Also the self-hosted runners they run on: a workspace's (`workspace`) or a repository's own (`repo`), their groups, and where agent work runs.",
205 default_action: None,
206 actions: &[
207 a("list", Op::ListWorkflows, "Workflows on the default branch"),
208 a("list_runs", Op::ListWorkflowRuns, "Runs, newest first"),
209 a("get_run", Op::GetWorkflowRun, "One run with its jobs and steps"),
210 a("job_logs", Op::GetJobLogs, "A job's log after a sequence number"),
211 a("dispatch", Op::DispatchWorkflow, "Run a workflow_dispatch workflow"),
212 a("cancel", Op::CancelWorkflowRun, "Cancel a run"),
213 a("rerun", Op::RerunWorkflowRun, "Run a finished run again"),
214 a("update", Op::UpdateWorkflow, "Turn a workflow on or off"),
215 a("list_artifacts", Op::Artifacts(ArtifactsOp::ListArtifacts), "A repository's artifacts, newest first; or a run's with run_artifacts"),
216 a("run_artifacts", Op::Artifacts(ArtifactsOp::ListRunArtifacts), "One run's artifacts"),
217 a("get_artifact", Op::Artifacts(ArtifactsOp::GetArtifact), "One artifact: size, digest, expiry, run"),
218 a("download_artifact", Op::Artifacts(ArtifactsOp::DownloadArtifact), "A 10-minute link to an artifact's zip"),
219 a("delete_artifact", Op::Artifacts(ArtifactsOp::DeleteArtifact), "Delete an artifact before it expires"),
220 a("artifact_retention", Op::Artifacts(ArtifactsOp::GetArtifactRetention), "Days the repository keeps artifacts"),
221 a("set_artifact_retention", Op::Artifacts(ArtifactsOp::SetArtifactRetention), "Change the days the repository keeps artifacts"),
222 a("combined_status", Op::Checks(ChecksOp::GetCombinedStatus), "A commit's statuses and the state they add up to"),
223 a("list_statuses", Op::Checks(ChecksOp::ListCommitStatuses), "A commit's statuses, newest first"),
224 a("set_status", Op::Checks(ChecksOp::CreateCommitStatus), "Set a status on a commit"),
225 a("list_check_runs", Op::Checks(ChecksOp::ListCheckRunsForRef), "A commit's check runs, g1t Actions jobs included"),
226 a("get_check_run", Op::Checks(ChecksOp::GetCheckRun), "One check run with its report"),
227 a("check_run_annotations", Op::Checks(ChecksOp::ListCheckRunAnnotations), "What a check run says about lines of files"),
228 a("create_check_run", Op::Checks(ChecksOp::CreateCheckRun), "Report a check run on a commit"),
229 a("update_check_run", Op::Checks(ChecksOp::UpdateCheckRun), "Move a check run on, complete it, add annotations"),
230 a("rerequest_check_run", Op::Checks(ChecksOp::RerequestCheckRun), "Ask for a check run to run again"),
231 a("list_check_suites", Op::Checks(ChecksOp::ListCheckSuitesForRef), "A commit's check suites, one per reporter or workflow run"),
232 a("get_check_suite", Op::Checks(ChecksOp::GetCheckSuite), "One check suite"),
233 a("rerequest_check_suite", Op::Checks(ChecksOp::RerequestCheckSuite), "Ask for a check suite to run again"),
234 a("list_deployments", Op::Deployments(DeploymentsOp::ListDeployments), "Deployments wherever they run, newest first, filtered"),
235 a("get_deployment", Op::Deployments(DeploymentsOp::GetDeployment), "One deployment with every status it has had"),
236 a("create_deployment", Op::Deployments(DeploymentsOp::CreateDeployment), "Report a deployment of a ref to an environment"),
237 a("deployment_statuses", Op::Deployments(DeploymentsOp::ListDeploymentStatuses), "A deployment's statuses, newest first"),
238 a("create_deployment_status", Op::Deployments(DeploymentsOp::CreateDeploymentStatus), "Report where a deployment is: in_progress, success, failure"),
239 a("list_environments", Op::Deployments(DeploymentsOp::ListEnvironments), "Environments with their current and latest deployments"),
240 a("get_environment", Op::Deployments(DeploymentsOp::GetEnvironment), "One environment by name"),
241 a("list_runners", Op::ListRunners, "Self-hosted runners, with status, labels and what each is doing"),
242 a("create_runner_token", Op::CreateRunnerRegistrationToken, "A one-hour token for g1t-runner register"),
243 a("remove_runner", Op::RemoveRunner, "Remove a self-hosted runner"),
244 a("list_runner_groups", Op::ListRunnerGroups, "A workspace's runner groups"),
245 a("create_runner_group", Op::CreateRunnerGroup, "Make a group, for some repositories"),
246 a("update_runner_group", Op::UpdateRunnerGroup, "Rename a group or change its repositories"),
247 a("delete_runner_group", Op::DeleteRunnerGroup, "Delete a group; its runners join the default"),
248 a("get_runner_settings", Op::GetRunnerSettings, "Where agent work runs; whether forks may use runners"),
249 a("update_runner_settings", Op::UpdateRunnerSettings, "Change them"),
250 ],
251 },
252 Tool {
253 name: "secret",
254 title: "Secrets and variables",
255 description: "A repository's or workspace's secrets and variables, read by workflows and deployments. Secret values are never returned.",
256 default_action: None,
257 actions: &[
258 a("list_secrets", Op::ListActionsSecrets, "Secrets, without values"),
259 a("set_secret", Op::SetActionsSecret, "Add or change a secret"),
260 a("delete_secret", Op::DeleteActionsSecret, "Remove a secret"),
261 a("list_variables", Op::ListActionsVariables, "Variables, with values"),
262 a("set_variable", Op::SetActionsVariable, "Add or change a variable"),
263 a("delete_variable", Op::DeleteActionsVariable, "Remove a variable"),
264 ],
265 },
266 Tool {
267 name: "webhook",
268 title: "Webhooks",
269 description: "HTTPS addresses sent signed events as they happen, for a repository or a whole workspace.",
270 default_action: None,
271 actions: &[
272 a("list", Op::ListWebhooks, "Webhooks, without secrets"),
273 a("create", Op::CreateWebhook, "Register one; a ping is sent"),
274 a("update", Op::UpdateWebhook, "Change address, events or active"),
275 a("delete", Op::DeleteWebhook, "Remove one"),
276 a("ping", Op::PingWebhook, "Send a ping"),
277 a("list_deliveries", Op::ListWebhookDeliveries, "Latest deliveries"),
278 a("redeliver", Op::RedeliverWebhook, "Send a delivery again"),
279 ],
280 },
281 Tool {
282 name: "access",
283 title: "Who has access",
284 description: "Who has access to a repository and with which role (read, triage, write, maintain, admin), outside collaborators, and a workspace's base permission.",
285 default_action: None,
286 actions: &[
287 a("list_collaborators", Op::ListCollaborators, "Everyone with a role, and pending invitations"),
288 a("get_permission", Op::GetCollaboratorPermission, "One person's role and capabilities"),
289 a("add_collaborator", Op::AddCollaborator, "Give someone a role, by username or email"),
290 a("update_collaborator", Op::UpdateCollaborator, "Change a direct role"),
291 a("remove_collaborator", Op::RemoveCollaborator, "Take away a direct role"),
292 a("list_invitations", Op::ListRepoInvitations, "Pending invitations to a repository"),
293 a("revoke_invitation", Op::RevokeRepoInvitation, "Withdraw one"),
294 a("set_base_permission", Op::SetBasePermission, "What every member gets on each repository"),
295 a("list_outside_collaborators", Op::ListOutsideCollaborators, "People with roles who are not members"),
296 ],
297 },
298 Tool {
299 name: "team",
300 title: "Teams",
301 description: "Teams: groups of a workspace's members, given roles on repositories together, mentioned as @workspace/team and asked to review together. Name one by `workspace` and its slug (`team`). Any member may create a team; the workspace's owners and the team's maintainers manage it. A secret team is seen only by its people and the owners.",
302 default_action: None,
303 actions: &[
304 a("list", Op::ListTeams, "A workspace's teams you can see"),
305 a("get", Op::GetTeam, "One team"),
306 a("create", Op::CreateTeam, "Create a team; you become its maintainer"),
307 a("update", Op::UpdateTeam, "Change its name, slug, description, visibility, parent or notifications"),
308 a("delete", Op::DeleteTeam, "Delete it; its child teams move up"),
309 a("list_members", Op::ListTeamMembers, "Its people and their roles, child teams' with include_child_teams"),
310 a("set_member", Op::SetTeamMember, "Add a member of the workspace, or change their role"),
311 a("remove_member", Op::RemoveTeamMember, "Take someone out of it"),
312 a("list_child_teams", Op::ListChildTeams, "The teams nested under it"),
313 a("list_repos", Op::ListTeamRepos, "The repositories it has a role on"),
314 a("set_repo", Op::SetTeamRepo, "Give it a role on a repository"),
315 a("remove_repo", Op::RemoveTeamRepo, "Take its role on a repository away"),
316 a("set_review_assignment", Op::SetTeamReviewAssignment, "Whom it picks when asked to review"),
317 a("list_user_teams", Op::ListUserTeams, "The teams someone is in"),
318 ],
319 },
320 Tool {
321 name: "workspace",
322 title: "Workspaces",
323 description: "Workspaces own repositories (g1t.sh/{workspace}/{repo}): create, update or delete one, invite members, connect integrations and model providers, set rulesets that hold across its repositories, read and change its projects (what each is, where it runs, its links), and keep your own pinned projects at the top of its sidebar.",
324 default_action: None,
325 actions: &[
326 a("get", Op::GetWorkspace, "A workspace's details and settings"),
327 a("create", Op::CreateWorkspace, "Create a workspace"),
328 a("delete", Op::DeleteWorkspace, "Delete a workspace and everything in it (support can restore it for 30 days)"),
329 a("update", Op::UpdateWorkspace, "Change its name, description, base permission, who may create teams, member privileges or the two-factor requirement"),
330 a("list_members", Op::ListMembers, "Its members, owners first, with their roles"),
331 a("update_member", Op::UpdateMember, "Make someone an owner or a member, billing manager or security manager"),
332 a("remove_member", Op::RemoveMember, "Remove someone from it"),
333 a("transfer_ownership", Op::TransferOwnership, "Hand it to another member: they become an owner, you a member"),
334 a("leave", Op::LeaveWorkspace, "Leave it yourself"),
335 a("list_invites", Op::ListWorkspaceInvites, "Its invites"),
336 a("invite_member", Op::InviteMember, "Invite an email address"),
337 a("revoke_invite", Op::RevokeWorkspaceInvite, "Revoke a pending invite"),
338 a("list_integrations", Op::ListIntegrations, "Model providers, alert sources, trackers"),
339 a("connect_integration", Op::ConnectIntegration, "Connect one"),
340 a("update_integration", Op::UpdateIntegration, "Change one: rotate its key, choose its AI Gateway models"),
341 a("disconnect_integration", Op::DisconnectIntegration, "Remove one"),
342 a("test_integration", Op::TestIntegration, "Check its credentials"),
343 a("get_model_routes", Op::GetModelRoutes, "Where each kind of work's model requests go"),
344 a("set_model_routes", Op::SetModelRoutes, "Replace them"),
345 a("list_projects", Op::ListProjects, "Its projects you can see: what each is, where it runs, its links"),
346 a("get_project", Op::GetProject, "One project"),
347 a("update_project", Op::UpdateProject, "Change a project's name, description, kind, where it runs or its links"),
348 a("list_pinned_projects", Op::ListPinnedProjects, "Your pinned projects in it, in your order"),
349 a("pin_project", Op::PinProject, "Pin a project, at a position or the end"),
350 a("unpin_project", Op::UnpinProject, "Unpin a project"),
351 a("reorder_pinned_projects", Op::ReorderPinnedProjects, "Put your pins in a new order"),
352 a("list_rulesets", Op::Rules(RulesOp::ListWorkspaceRulesets), "Its rulesets, which hold across its repositories"),
353 a("get_ruleset", Op::Rules(RulesOp::GetWorkspaceRuleset), "One of its rulesets"),
354 a("create_ruleset", Op::Rules(RulesOp::CreateWorkspaceRuleset), "Create a ruleset for some or all of its repositories"),
355 a("update_ruleset", Op::Rules(RulesOp::UpdateWorkspaceRuleset), "Change one of its rulesets"),
356 a("delete_ruleset", Op::Rules(RulesOp::DeleteWorkspaceRuleset), "Delete one of its rulesets"),
357 a("rule_evaluations", Op::Rules(RulesOp::ListWorkspaceRuleEvaluations), "How rules judged changes across its repositories"),
358 ],
359 },
360 Tool {
361 name: "billing",
362 title: "Billing",
363 description: "A workspace's billing: its usage by product, project and day, its budget (the monthly spend limit, alerts and whether usage pauses at it), its AI credit, its invoices, and its AI Gateway requests. Amounts are whole millionths of a dollar (`_micros`), or cents (`_cents`) where named. Members read it; changing the budget and buying credit are for owners, as people, and never for g1t's agents.",
364 default_action: Some("usage"),
365 actions: &[
366 a("usage", Op::GetUsage, "Usage over a range of days, by product, meter, project and day, and what paid for it"),
367 a("budget", Op::GetBudget, "The monthly spend limit, what was spent, alerts and whether usage pauses at the limit"),
368 a("set_budget", Op::SetBudget, "Change the spend limit, alerts, pausing or the alert webhook"),
369 a("ai_credit", Op::GetAiCredit, "AI credit left, its grants, auto-reload and how to buy more"),
370 a("buy_ai_credit", Op::BuyAiCredit, "A payment page to buy AI credit, for a person to open"),
371 a("invoices", Op::ListInvoices, "Every invoice, the itemised usage invoices, and the next one so far"),
372 a("billing_details", Op::GetBillingDetails, "Who invoices are made out to and the payment method on file"),
373 a("gateway_requests", Op::ListGatewayRequests, "Recent AI Gateway requests: model, tokens, cost, status and token"),
374 ],
375 },
376 Tool {
377 name: "security",
378 title: "Security",
379 description: "A repository's security: secret scanning alerts and push protection bypasses, custom secret patterns, code scanning alerts and SARIF uploads, vulnerability alerts, the dependency graph and its SBOM, dependency review, settings, and a workspace's overview. Fix an alert with g1t. Findings are shown to those who can change the code only. Give `repo` (owner/name), or `workspace` for lists across one.",
380 default_action: Some("secret_alerts"),
381 actions: &[
382 a("secret_alerts", Op::Security(SecurityOp::ListSecretAlerts), "Secret scanning alerts; by state, secret_type, validity, bypassed"),
383 a("secret_alert", Op::Security(SecurityOp::GetSecretAlert), "One secret alert, with where it was found and its bypass requests"),
384 a("update_secret_alert", Op::Security(SecurityOp::UpdateSecretAlert), "Dismiss a secret alert with a reason, or reopen it"),
385 a("secret_locations", Op::Security(SecurityOp::ListSecretLocations), "Every file, line and commit a secret is in"),
386 a("bypass", Op::Security(SecurityOp::BypassPushProtection), "Push past push protection with a reason, or ask to"),
387 a("check_validity", Op::Security(SecurityOp::CheckSecretValidity), "Ask a secret's issuer whether it still works"),
388 a("bypass_requests", Op::Security(SecurityOp::ListBypassRequests), "A workspace's push protection bypass requests"),
389 a("review_bypass", Op::Security(SecurityOp::ReviewBypassRequest), "Approve, deny or cancel a bypass request"),
390 a("patterns", Op::Security(SecurityOp::ListCustomPatterns), "Custom secret patterns of a repository or workspace"),
391 a("create_pattern", Op::Security(SecurityOp::CreateCustomPattern), "Create a custom secret pattern, as a draft or published"),
392 a("update_pattern", Op::Security(SecurityOp::UpdateCustomPattern), "Change, publish or unpublish a custom pattern"),
393 a("delete_pattern", Op::Security(SecurityOp::DeleteCustomPattern), "Delete a custom pattern"),
394 a("dry_run_pattern", Op::Security(SecurityOp::DryRunCustomPattern), "Run a pattern over the default branch without saving it"),
395 a("code_alerts", Op::Security(SecurityOp::ListCodeAlerts), "Code scanning alerts; by state, severity, tool, rule_id"),
396 a("code_alert", Op::Security(SecurityOp::GetCodeAlert), "One code scanning alert by number"),
397 a("update_code_alert", Op::Security(SecurityOp::UpdateCodeAlert), "Dismiss a code scanning alert with a reason, or reopen it"),
398 a("analyses", Op::Security(SecurityOp::ListAnalyses), "Code scanning analyses, newest first"),
399 a("upload_sarif", Op::Security(SecurityOp::UploadSarif), "Upload a SARIF file, gzipped and base64-encoded"),
400 a("sarif_upload", Op::Security(SecurityOp::GetSarifUpload), "Whether a SARIF upload was read, and its analyses"),
401 a("vulnerability_alerts", Op::Security(SecurityOp::ListVulnerabilityAlerts), "Vulnerable dependencies; by state, severity, ecosystem, package"),
402 a("vulnerability_alert", Op::Security(SecurityOp::GetVulnerabilityAlert), "One vulnerability alert"),
403 a("update_vulnerability_alert", Op::Security(SecurityOp::UpdateVulnerabilityAlert), "Dismiss a vulnerability alert with a reason, or reopen it"),
404 a("fix", Op::Security(SecurityOp::FixAlert), "Put g1t on an issue to fix an alert"),
405 a("dependency_graph", Op::Security(SecurityOp::GetDependencyGraph), "Every package the lockfiles resolve, direct or transitive"),
406 a("sbom", Op::Security(SecurityOp::GetSbom), "The dependency graph as an SPDX 2.3 document"),
407 a("compare_dependencies", Op::Security(SecurityOp::CompareDependencies), "What changes in dependencies between base...head"),
408 a("settings", Op::Security(SecurityOp::GetSettings), "A repository's security settings"),
409 a("update_settings", Op::Security(SecurityOp::UpdateSettings), "Change when checks fail and dependency review's policy"),
410 a("workspace_settings", Op::Security(SecurityOp::GetWorkspaceSettings), "A workspace's delegated bypass and validity checks"),
411 a("update_workspace_settings", Op::Security(SecurityOp::UpdateWorkspaceSettings), "Turn delegated bypass or validity checks on or off"),
412 a("overview", Op::Security(SecurityOp::GetOverview), "A workspace's alerts, trends and coverage"),
413 ],
414 },
415 Tool {
416 name: "notifications",
417 title: "Notifications",
418 description: "Your inbox: what needs you, and what you follow. One thread per issue, pull request, workflow or deployment, with why you were told (`reason`): an agent waiting on you, a review asked of you, an assignment, a mention, your work's checks, or what you subscribe to and watch. Mark threads read or done once handled, and choose what you hear of with subscribe, unsubscribe and watch. Your own: a personal token.",
419 default_action: Some("list"),
420 actions: &[
421 a("list", Op::ListNotifications, "Unread threads, latest first; all, a view, a reason, a repository"),
422 a("get", Op::GetNotificationThread, "One thread with its recent activity and your subscription"),
423 a("mark_read", Op::MarkThreadRead, "Mark a thread read, or unread"),
424 a("mark_all_read", Op::MarkNotificationsRead, "Mark everything read up to a time, or one repository's"),
425 a("done", Op::MarkThreadDone, "Mark a thread done; new activity brings it back"),
426 a("save", Op::SaveThread, "Save a thread, or unsave it"),
427 a("snooze", Op::SnoozeThread, "Snooze a thread until a time, or bring it back"),
428 a("subscription", Op::GetThreadSubscription, "Your subscription to an issue or pull request"),
429 a("subscribe", Op::SetThreadSubscription, "Subscribe to an issue or pull request, or ignore it"),
430 a("unsubscribe", Op::DeleteThreadSubscription, "Unsubscribe until you comment or are mentioned"),
431 a("watching", Op::GetRepoSubscription, "How you watch a repository"),
432 a("watch", Op::SetRepoSubscription, "Watch a repository: participating, all, ignore or custom"),
433 a("unwatch", Op::DeleteRepoSubscription, "Stop watching a repository"),
434 a("watched", Op::ListWatchedRepos, "Repositories you watch other than the default way"),
435 ],
436 },
437 Tool {
438 name: "account",
439 title: "Your account",
440 description: "Who this token acts as and its workspaces (`whoami`), your email addresses, your invites, and invitations to repositories waiting for you.",
441 default_action: Some("whoami"),
442 actions: &[
443 a("whoami", Op::Whoami, "Who the token acts as, and its workspaces"),
444 a("list_emails", Op::ListEmails, "Your addresses"),
445 a("add_email", Op::AddEmail, "Add an address"),
446 a("remove_email", Op::RemoveEmail, "Remove an address"),
447 a("update_email_settings", Op::UpdateEmailSettings, "Primary, backup and privacy"),
448 a("list_invites", Op::ListInvites, "Your invites to g1t"),
449 a("create_invite", Op::CreateInvite, "Make an invite"),
450 a("revoke_invite", Op::RevokeInvite, "Revoke one"),
451 a("list_repository_invitations", Op::ListMyRepoInvitations, "Invitations to repositories for you"),
452 a("accept_repository_invitation", Op::AcceptRepoInvitation, "Accept one"),
453 a("decline_repository_invitation", Op::DeclineRepoInvitation, "Decline one"),
454 ],
455 },
456];
457
458/// Operations that cannot be undone, or reach beyond g1t's own records:
459/// clients ask before running a tool that has any of them.
460fn destructive(op: Op) -> bool {
461 matches!(
462 op,
463 Op::Security(SecurityOp::DeleteCustomPattern | SecurityOp::BypassPushProtection)
464 | Op::Rules(RulesOp::DeleteRepoRuleset | RulesOp::DeleteWorkspaceRuleset)
465 | Op::DeleteWorkspace
466 | Op::UpdateWorkspace
467 | Op::RemoveMember
468 | Op::TransferOwnership
469 | Op::LeaveWorkspace
470 | Op::DeleteRepo
471 | Op::PurgeRepo
472 | Op::TransferRepo
473 | Op::SetRepoVisibility
474 | Op::RemoveEmail
475 | Op::RemoveCollaborator
476 | Op::DisconnectIntegration
477 | Op::UpdateIntegration
478 | Op::DeleteWebhook
479 | Op::DeleteActionsSecret
480 | Op::DeleteActionsVariable
481 | Op::SetActionsSecret
482 | Op::SetActionsVariable
483 | Op::SetModelRoutes
484 | Op::SetBasePermission
485 | Op::DeleteTeam
486 | Op::RemoveTeamRepo
487 | Op::MergePullRequest
488 | Op::RemoveRunner
489 | Op::DeleteRunnerGroup
490 | Op::UpdateRunnerSettings
491 )
492}
493
494/// Whether an operation only reads.
495pub fn reads_only(op: Op) -> bool {
496 NO_SCOPE.contains(&op.name())
497 || scope_for(op.name()).is_some_and(|scope| scope.level() == Level::Read)
498}
499
500/// What decides which actions a caller sees.
501pub enum Gate<'a> {
502 /// No limit beyond the person's own role.
503 Everything,
504 /// A g1t agent's token: the operations its run lists.
505 Agent(&'a AgentScope),
506 /// An access token with scopes.
507 Token(&'a TokenAccess),
508}
509
510impl Gate<'_> {
511 pub fn allows(&self, op: Op) -> bool {
512 match self {
513 Gate::Everything => true,
514 Gate::Agent(scope) => op.allowed_by(scope) && !NEVER.contains(&op.name()),
515 Gate::Token(access) => {
516 if NO_SCOPE.contains(&op.name()) {
517 return true;
518 }
519 match scope_for(op.name()) {
520 Some(scope) => access.allows(scope),
521 None => access.scopes.is_none(),
522 }
523 }
524 }
525 }
526}
527
528impl Tool {
529 pub fn by_name(name: &str) -> Option<&'static Tool> {
530 TOOLS.iter().find(|tool| tool.name == name)
531 }
532
533 pub fn action(&self, name: &str) -> Option<&'static Action> {
534 // The tools are 'static; find through TOOLS to keep the lifetime.
535 TOOLS
536 .iter()
537 .find(|tool| tool.name == self.name)
538 .and_then(|tool| tool.actions.iter().find(|action| action.name == name))
539 }
540
541 pub fn visible(&self, gate: &Gate) -> Vec<&'static Action> {
542 TOOLS
543 .iter()
544 .find(|tool| tool.name == self.name)
545 .map(|tool| tool.actions.iter().filter(|action| gate.allows(action.op)).collect())
546 .unwrap_or_default()
547 }
548
549 /// The flat input schema of the actions given.
550 pub fn input_schema(&self, actions: &[&Action]) -> Value {
551 let mut properties = Map::new();
552 let lines: Vec<String> = actions
553 .iter()
554 .map(|action| {
555 let required: Vec<String> = action.op.required();
556 if required.is_empty() {
557 format!("{}: {}.", action.name, action.summary)
558 } else {
559 format!("{} ({}): {}.", action.name, required.join(", "), action.summary)
560 }
561 })
562 .collect();
563 let mut action_schema = json!({
564 "type": "string",
565 "enum": actions.iter().map(|action| action.name).collect::<Vec<_>>(),
566 "description": lines.join("\n"),
567 });
568 if let Some(default) = self.default_action.filter(|name| actions.iter().any(|action| action.name == *name)) {
569 action_schema["default"] = json!(default);
570 }
571 properties.insert("action".to_owned(), action_schema);
572 for action in actions {
573 for (name, schema) in action.op.properties() {
574 merge_property(&mut properties, name, schema);
575 }
576 }
577 let mut required = vec![];
578 if self.default_action.is_none() {
579 required.push("action");
580 }
581 let mut schema = json!({ "type": "object", "properties": properties });
582 if !required.is_empty() {
583 schema["required"] = json!(required);
584 }
585 schema
586 }
587
588 /// The input schema keyed by action: one `oneOf` branch per action,
589 /// each with its own fields and the ones it needs.
590 pub fn discriminated(&self, actions: &[&Action]) -> Value {
591 let branches: Vec<Value> = actions
592 .iter()
593 .map(|action| {
594 let mut properties = Map::new();
595 properties.insert("action".to_owned(), json!({ "const": action.name }));
596 properties.extend(action.op.properties());
597 let mut required = vec![Value::String("action".to_owned())];
598 // The default action may leave `action` out.
599 if self.default_action == Some(action.name) {
600 required.clear();
601 }
602 required.extend(action.op.required().into_iter().map(Value::String));
603 json!({
604 "title": action.name,
605 "description": action.summary,
606 "type": "object",
607 "properties": properties,
608 "required": required,
609 })
610 })
611 .collect();
612 json!({ "type": "object", "oneOf": branches })
613 }
614
615 /// MCP's hints about the actions given: whether the tool only reads,
616 /// whether it can destroy something, and whether calling it twice is
617 /// the same as once.
618 pub fn annotations(&self, actions: &[&Action]) -> Value {
619 let read_only = actions.iter().all(|action| reads_only(action.op));
620 json!({
621 "title": self.title,
622 "readOnlyHint": read_only,
623 "destructiveHint": !read_only && actions.iter().any(|action| destructive(action.op)),
624 "idempotentHint": read_only,
625 "openWorldHint": false,
626 })
627 }
628
629 /// The tool as `tools/list` gives it, for a caller behind `gate`, or
630 /// `None` when it may use none of its actions.
631 pub fn listed(&self, gate: &Gate) -> Option<Value> {
632 let actions = self.visible(gate);
633 if actions.is_empty() {
634 return None;
635 }
636 Some(json!({
637 "name": self.name,
638 "title": self.title,
639 "description": self.description,
640 "inputSchema": self.input_schema(&actions),
641 "annotations": self.annotations(&actions),
642 }))
643 }
644}
645
646/// Adds a property to a tool's flat schema. The first action to use a name
647/// describes it; a later one with other allowed values adds them.
648fn merge_property(properties: &mut Map<String, Value>, name: String, schema: Value) {
649 match properties.get_mut(&name) {
650 None => {
651 properties.insert(name, schema);
652 }
653 Some(existing) => {
654 if let (Some(Value::Array(had)), Some(Value::Array(more))) =
655 (existing.get("enum").cloned(), schema.get("enum"))
656 {
657 let mut merged = had;
658 for value in more {
659 if !merged.contains(value) {
660 merged.push(value.clone());
661 }
662 }
663 existing["enum"] = Value::Array(merged);
664 }
665 // Different kinds of value under one name: say less, accept both.
666 if existing.get("type") != schema.get("type")
667 && let Some(fields) = existing.as_object_mut()
668 {
669 fields.remove("type");
670 fields.remove("items");
671 }
672 }
673 }
674}
675
676/// What a call to a tool runs: the operation its action names, or why not.
677pub fn resolve(tool: &Tool, arguments: &Value) -> Result<Op, String> {
678 let names = || {
679 tool.actions
680 .iter()
681 .map(|action| action.name)
682 .collect::<Vec<_>>()
683 .join(", ")
684 };
685 let Some(name) = arguments["action"].as_str().or(tool.default_action) else {
686 return Err(format!("Give an action: one of {}.", names()));
687 };
688 let Some(action) = tool.action(name) else {
689 return Err(format!("{} has no action {name}. Its actions: {}.", tool.name, names()));
690 };
691 let missing: Vec<String> = action
692 .op
693 .required()
694 .into_iter()
695 .filter(|field| arguments.get(field).is_none_or(Value::is_null))
696 .collect();
697 if !missing.is_empty() {
698 return Err(format!("{}.{name} needs {}.", tool.name, missing.join(", ")));
699 }
700 Ok(action.op)
701}
702
703#[cfg(test)]
704mod tests {
705 use super::*;
706 use g1t_contracts::scopes::{Preset, Scope};
707
708 fn listed(gate: &Gate) -> Vec<Value> {
709 TOOLS.iter().filter_map(|tool| tool.listed(gate)).collect()
710 }
711
712 fn token(scopes: Option<Vec<Scope>>) -> TokenAccess {
713 TokenAccess {
714 token_id: "tok_1".to_owned(),
715 scopes: scopes.map(|scopes| scopes.iter().map(|scope| scope.as_str().to_owned()).collect()),
716 legacy: false,
717 name: None,
718 }
719 }
720
721 #[test]
722 fn every_operation_is_exactly_one_action_of_one_tool() {
723 for op in Op::ALL {
724 let count = TOOLS
725 .iter()
726 .flat_map(|tool| tool.actions.iter())
727 .filter(|action| action.op == op)
728 .count();
729 assert_eq!(count, 1, "{} is {count} actions", op.name());
730 }
731 for tool in TOOLS {
732 let mut names = std::collections::HashSet::new();
733 for action in tool.actions {
734 assert!(names.insert(action.name), "{}.{} twice", tool.name, action.name);
735 }
736 if let Some(default) = tool.default_action {
737 assert!(tool.action(default).is_some(), "{}", tool.name);
738 }
739 }
740 assert!(TOOLS.len() <= 17, "{} tools", TOOLS.len());
741 }
742
743 #[test]
744 fn every_operation_needs_exactly_one_scope_or_none() {
745 use g1t_contracts::scopes::OPERATIONS;
746 for op in Op::ALL {
747 let mapped = OPERATIONS.iter().filter(|(name, _)| *name == op.name()).count();
748 let free = NO_SCOPE.contains(&op.name());
749 assert_eq!(mapped + usize::from(free), 1, "{}", op.name());
750 }
751 for (name, _) in OPERATIONS {
752 assert!(Op::by_name(name).is_some(), "{name} is not an operation");
753 }
754 }
755
756 #[test]
757 fn each_tool_schema_is_valid_with_one_branch_per_action() {
758 for tool in TOOLS {
759 let actions: Vec<&Action> = tool.actions.iter().collect();
760 let flat = tool.input_schema(&actions);
761 assert_eq!(flat["type"], "object");
762 assert!(flat.get("oneOf").is_none(), "no oneOf at the top level");
763 let listed: Vec<&str> = flat["properties"]["action"]["enum"]
764 .as_array()
765 .unwrap()
766 .iter()
767 .map(|name| name.as_str().unwrap())
768 .collect();
769 assert_eq!(listed, tool.actions.iter().map(|action| action.name).collect::<Vec<_>>());
770 for action in tool.actions {
771 for field in action.op.required() {
772 assert!(flat["properties"].get(&field).is_some(), "{}.{}: {field}", tool.name, action.name);
773 }
774 }
775 let keyed = tool.discriminated(&actions);
776 let branches = keyed["oneOf"].as_array().unwrap();
777 assert_eq!(branches.len(), tool.actions.len());
778 for (branch, action) in branches.iter().zip(tool.actions) {
779 assert_eq!(branch["properties"]["action"]["const"], action.name);
780 for field in branch["required"].as_array().unwrap() {
781 assert!(branch["properties"].get(field.as_str().unwrap()).is_some(), "{}.{}: {field}", tool.name, action.name);
782 }
783 }
784 // A well-formed JSON Schema object throughout.
785 let text = serde_json::to_string(&flat).unwrap();
786 assert!(serde_json::from_str::<Value>(&text).is_ok());
787 }
788 }
789
790 #[test]
791 fn a_read_only_token_sees_read_actions_only() {
792 let access = token(Preset::ReadOnly.scopes());
793 let gate = Gate::Token(&access);
794 for tool in TOOLS {
795 for action in tool.visible(&gate) {
796 assert!(reads_only(action.op), "{}.{}", tool.name, action.name);
797 }
798 }
799 let tools = listed(&gate);
800 for tool in &tools {
801 assert_eq!(tool["annotations"]["readOnlyHint"], true, "{}", tool["name"]);
802 assert_eq!(tool["annotations"]["destructiveHint"], false);
803 }
804 let issue = tools.iter().find(|tool| tool["name"] == "issue").unwrap();
805 assert_eq!(issue["inputSchema"]["properties"]["action"]["enum"], json!(["list", "get", "labels"]));
806 // Nothing of the agent tool is a read.
807 assert!(!tools.iter().any(|tool| tool["name"] == "agent"));
808 }
809
810 #[test]
811 fn a_narrow_token_sees_only_its_tools() {
812 let access = token(Some(vec![Scope::IssuesWrite]));
813 let names: Vec<Value> = listed(&Gate::Token(&access)).into_iter().map(|tool| tool["name"].clone()).collect();
814 // Labels and milestones are the repository's, managed with issues:write.
815 assert_eq!(names, vec![json!("repository"), json!("issue"), json!("plan"), json!("account")]);
816 // Notifications are a resource of their own: reading them lists
817 // only what reads.
818 let reader = token(Some(vec![Scope::NotificationsRead]));
819 let tools = listed(&Gate::Token(&reader));
820 let notifications = tools.iter().find(|tool| tool["name"] == "notifications").unwrap();
821 assert_eq!(
822 notifications["inputSchema"]["properties"]["action"]["enum"],
823 json!(["list", "get", "subscription", "watching", "watched"])
824 );
825 assert_eq!(notifications["annotations"]["readOnlyHint"], true);
826 let full = token(None);
827 assert_eq!(listed(&Gate::Token(&full)).len(), TOOLS.len());
828 assert_eq!(listed(&Gate::Everything).len(), TOOLS.len());
829 }
830
831 #[test]
832 fn a_tool_that_can_destroy_says_so() {
833 let tools = listed(&Gate::Everything);
834 let repository = tools.iter().find(|tool| tool["name"] == "repository").unwrap();
835 assert_eq!(repository["annotations"]["destructiveHint"], true);
836 assert_eq!(repository["annotations"]["readOnlyHint"], false);
837 let memory = tools.iter().find(|tool| tool["name"] == "memory").unwrap();
838 assert_eq!(memory["annotations"]["destructiveHint"], false);
839 }
840
841 #[test]
842 fn calls_resolve_to_their_operation_or_say_what_is_missing() {
843 let issue = Tool::by_name("issue").unwrap();
844 assert_eq!(resolve(issue, &json!({ "action": "get", "repo": "a/b", "number": 1 })), Ok(Op::GetIssue));
845 assert_eq!(resolve(issue, &json!({ "action": "get", "repo": "a/b" })), Err("issue.get needs number.".to_owned()));
846 assert!(resolve(issue, &json!({})).unwrap_err().starts_with("Give an action"));
847 assert!(resolve(issue, &json!({ "action": "explode" })).unwrap_err().contains("no action explode"));
848 let search = Tool::by_name("search").unwrap();
849 assert_eq!(resolve(search, &json!({ "query": "x" })), Ok(Op::Search));
850 let account = Tool::by_name("account").unwrap();
851 assert_eq!(resolve(account, &json!({})), Ok(Op::Whoami));
852 }
853
854 #[test]
855 fn teams_are_one_tool_and_a_workspace_reader_sees_only_its_reads() {
856 let team = Tool::by_name("team").unwrap();
857 let names: Vec<&str> = team.actions.iter().map(|action| action.name).collect();
858 assert_eq!(
859 names,
860 [
861 "list",
862 "get",
863 "create",
864 "update",
865 "delete",
866 "list_members",
867 "set_member",
868 "remove_member",
869 "list_child_teams",
870 "list_repos",
871 "set_repo",
872 "remove_repo",
873 "set_review_assignment",
874 "list_user_teams",
875 ]
876 );
877 let reader = token(Some(vec![Scope::WorkspaceRead]));
878 let tools = listed(&Gate::Token(&reader));
879 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
880 assert_eq!(
881 listed_team["inputSchema"]["properties"]["action"]["enum"],
882 json!(["list", "get", "list_members", "list_child_teams", "list_repos", "list_user_teams"])
883 );
884 assert_eq!(listed_team["annotations"]["readOnlyHint"], true);
885 // A team's role on a repository is who has access.
886 let admin = token(Some(vec![Scope::WorkspaceAdmin]));
887 let tools = listed(&Gate::Token(&admin));
888 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
889 let actions = listed_team["inputSchema"]["properties"]["action"]["enum"].as_array().unwrap();
890 assert!(actions.contains(&json!("set_review_assignment")) && !actions.contains(&json!("set_repo")));
891 let access = token(Some(vec![Scope::AccessAdmin]));
892 let tools = listed(&Gate::Token(&access));
893 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
894 assert_eq!(listed_team["inputSchema"]["properties"]["action"]["enum"], json!(["set_repo", "remove_repo"]));
895 // Both kinds of role a schema names are offered.
896 let roles = &listed(&Gate::Everything).into_iter().find(|tool| tool["name"] == "team").unwrap()["inputSchema"]
897 ["properties"]["role"]["enum"];
898 for role in ["member", "maintainer", "read", "admin"] {
899 assert!(roles.as_array().unwrap().contains(&json!(role)), "{role}");
900 }
901 assert_eq!(
902 resolve(team, &json!({ "action": "set_repo", "workspace": "acme", "team": "backend", "repo": "rocket" })),
903 Err("team.set_repo needs role.".to_owned())
904 );
905 }
906
907 #[test]
908 fn reviewers_and_code_owners_are_actions_of_their_tools() {
909 let pull = Tool::by_name("pull_request").unwrap();
910 assert_eq!(
911 resolve(pull, &json!({ "action": "request_reviewers", "repo": "a/b", "number": 1, "team_reviewers": ["backend"] })),
912 Ok(Op::RequestReviewers)
913 );
914 assert_eq!(pull.action("remove_requested_reviewers").map(|action| action.op), Some(Op::RemoveRequestedReviewers));
915 let repository = Tool::by_name("repository").unwrap();
916 assert_eq!(resolve(repository, &json!({ "action": "codeowners", "repo": "a/b" })), Ok(Op::GetCodeownersErrors));
917 assert!(reads_only(Op::GetCodeownersErrors));
918 assert!(!reads_only(Op::RequestReviewers));
919 }
920
921 /// How much smaller `tools/list` is than one tool per operation. Run
922 /// with `--nocapture` to see the numbers.
923 #[test]
924 fn the_tool_list_is_much_smaller_than_one_tool_per_operation() {
925 let before: Vec<Value> = Op::ALL
926 .into_iter()
927 .map(|op| json!({ "name": op.name(), "description": op.description(), "inputSchema": op.input() }))
928 .collect();
929 let after = listed(&Gate::Everything);
930 let before_bytes = serde_json::to_string(&json!({ "tools": before })).unwrap().len();
931 let after_bytes = serde_json::to_string(&json!({ "tools": after })).unwrap().len();
932 let agent = token(Preset::Agent.scopes());
933 let agent_bytes = serde_json::to_string(&json!({ "tools": listed(&Gate::Token(&agent)) })).unwrap().len();
934 let read = token(Preset::ReadOnly.scopes());
935 let read_bytes = serde_json::to_string(&json!({ "tools": listed(&Gate::Token(&read)) })).unwrap().len();
936 println!(
937 "tools/list: before {} tools, {before_bytes} bytes (~{} tokens); after {} tools, {after_bytes} bytes (~{} tokens); agent preset {agent_bytes} bytes (~{} tokens); read only {read_bytes} bytes (~{} tokens)",
938 before.len(),
939 before_bytes / 4,
940 after.len(),
941 after_bytes / 4,
942 agent_bytes / 4,
943 read_bytes / 4,
944 );
945 assert!(after_bytes * 2 < before_bytes, "{after_bytes} vs {before_bytes}");
946 }
947}