Skip to content
1,092 linesCodeBlameRaw
1//! The MCP server's tools: a few resource tools, each with an `action`.
2//!
3//! Every operation is one action of one tool. A call is dispatched to the
4//! operation it names, so permissions, the audit log, billing and outcomes
5//! are exactly those of the REST API. A token sees only the actions its
6//! scopes allow, and a tool none of whose actions it may use is not listed.
7//!
8//! The listed input schema is one flat object: `action`, then every field
9//! any of its actions takes. Which fields each action needs is in the
10//! `action` field's description and checked on every call. Claude's API,
11//! and so most MCP clients, refuse a tool whose input schema has `oneOf`
12//! at its top level, so the schema keyed by action, with each action's
13//! required fields, is [`discriminated`], published on the server's card
14//! and in the docs.
15
16use g1t_contracts::credentials::NEVER;
17use g1t_contracts::identity::AgentScope;
18use g1t_contracts::scopes::{Level, NO_SCOPE, TokenAccess, scope_for};
19use serde_json::{Map, Value, json};
20
21use crate::about::AboutOp;
22use crate::artifacts::ArtifactsOp;
23use crate::deploy_keys::DeployKeysOp;
24use crate::mirrors::MirrorsOp;
25use crate::deployments::DeploymentsOp;
26use crate::packages::PackagesOp;
27use crate::folios::FoliosOp;
28use crate::protection::ProtectionOp;
29use crate::token_policy::TokenOp;
30use crate::operations::Op;
31use crate::checks::ChecksOp;
32use crate::rules::RulesOp;
33use crate::security::SecurityOp;
34
35pub struct Action {
36 pub name: &'static str,
37 pub op: Op,
38 /// One line, for the `action` field's description.
39 pub summary: &'static str,
40}
41
42pub struct Tool {
43 pub name: &'static str,
44 pub title: &'static str,
45 /// What it is for, in a sentence or two.
46 pub description: &'static str,
47 pub actions: &'static [Action],
48 /// The action a call without one runs.
49 pub default_action: Option<&'static str>,
50}
51
52const fn a(name: &'static str, op: Op, summary: &'static str) -> Action {
53 Action { name, op, summary }
54}
55
56pub const TOOLS: &[Tool] = &[
57 Tool {
58 name: "search",
59 title: "Search",
60 description: "Find things. `code` (the default) searches all of g1t you can see: repositories, code, issues, pull requests and people, with qualifiers like repo:owner/name, language:rust, is:issue. `context` searches one workspace's catalog, docs, issues and memory by meaning.",
61 default_action: Some("code"),
62 actions: &[
63 a("code", Op::Search, "Search all of g1t: repositories, code, issues, pull requests, people"),
64 a("context", Op::SearchContext, "Search a workspace's context hub by meaning"),
65 a("entity", Op::GetEntity, "One catalog entry and its relations"),
66 a("ticket", Op::GetContext, "A Jira, Linear or Sentry item the work refers to, as it is now"),
67 ],
68 },
69 Tool {
70 name: "repository",
71 title: "Repositories",
72 description: "Repositories: find, read and create them, change their settings and rulesets (what may happen to branches and tags, and what a pull request needs to merge), check their CODEOWNERS file, manage their labels and milestones, see and dismiss their security alerts (secrets and vulnerable dependencies), read what their default branch says (languages, contributors, license), star them, publish releases, and look after their mirroring (take a mirror over, hand it back, or move it to g1t for good). Name one as \"owner/name\". Deleting, transferring and changing visibility need `confirm`.",
73 default_action: None,
74 actions: &[
75 a("list", Op::ListRepos, "Repositories you can see"),
76 a("get", Op::GetRepo, "One repository"),
77 a("create", Op::CreateRepo, "Create one, empty or copied from a public git URL"),
78 a("update", Op::UpdateRepo, "Change description, website, topics, default branch, protection"),
79 a("get_settings", Op::GetRepoSettings, "How pull requests merge, and the default branch's protection as its rules stack"),
80 a("update_settings", Op::UpdateRepoSettings, "Change how pull requests merge and the default branch protection ruleset"),
81 a("check_names", Op::ListCheckNames, "Check names reported lately, to require in a ruleset"),
82 a("list_rulesets", Op::Rules(RulesOp::ListRepoRulesets), "Its rulesets, and its workspace's that hold in it"),
83 a("get_ruleset", Op::Rules(RulesOp::GetRepoRuleset), "One ruleset"),
84 a("create_ruleset", Op::Rules(RulesOp::CreateRepoRuleset), "Create a ruleset for its branches or tags"),
85 a("update_ruleset", Op::Rules(RulesOp::UpdateRepoRuleset), "Change a ruleset"),
86 a("delete_ruleset", Op::Rules(RulesOp::DeleteRepoRuleset), "Delete a ruleset"),
87 a("branch_rules", Op::Rules(RulesOp::GetBranchRules), "Every rule that holds for a branch or tag, and where it comes from"),
88 a("rule_evaluations", Op::Rules(RulesOp::ListRuleEvaluations), "How its rules judged pushes and merges, with insights"),
89 a("codeowners", Op::GetCodeownersErrors, "Problems in its CODEOWNERS file, by line"),
90 a("list_labels", Op::ListLabels, "Labels, with colors and how many issues and pull requests carry each"),
91 a("create_label", Op::CreateLabel, "Create a label"),
92 a("update_label", Op::UpdateLabel, "Rename a label or change its color or description"),
93 a("delete_label", Op::DeleteLabel, "Delete a label, from everything that carries it"),
94 a("add_default_labels", Op::AddDefaultLabels, "Add the default labels it is missing"),
95 a("list_milestones", Op::ListMilestones, "Milestones, with progress and due dates"),
96 a("get_milestone", Op::GetMilestone, "One milestone with its issues and pull requests"),
97 a("create_milestone", Op::CreateMilestone, "Create a milestone"),
98 a("update_milestone", Op::UpdateMilestone, "Change a milestone's title, description, due date or state"),
99 a("delete_milestone", Op::DeleteMilestone, "Delete a milestone"),
100 a("list_events", Op::ListEvents, "Timeline: pushes, issues, pull requests, comments"),
101 a("languages", Op::About(AboutOp::GetLanguages), "Its languages by bytes, with colors and percentages"),
102 a("contributors", Op::About(AboutOp::ListContributors), "Who made it: commits per person, agent and author, by week"),
103 a("license", Op::About(AboutOp::GetLicense), "The license its LICENSE file holds"),
104 a("stargazers", Op::About(AboutOp::ListStargazers), "Who starred it"),
105 a("starred", Op::About(AboutOp::CheckStarred), "Whether you starred it, and how many have"),
106 a("star", Op::About(AboutOp::Star), "Star it"),
107 a("unstar", Op::About(AboutOp::Unstar), "Take your star back"),
108 a("list_starred", Op::About(AboutOp::ListStarred), "Repositories you starred"),
109 a("list_releases", Op::About(AboutOp::ListReleases), "Releases, newest first"),
110 a("latest_release", Op::About(AboutOp::GetLatestRelease), "The latest release"),
111 a("get_release", Op::About(AboutOp::GetRelease), "One release by id"),
112 a("get_release_by_tag", Op::About(AboutOp::GetReleaseByTag), "The release of a tag"),
113 a("create_release", Op::About(AboutOp::CreateRelease), "Publish a release of a tag, making the tag if needed"),
114 a("update_release", Op::About(AboutOp::UpdateRelease), "Change a release's title, notes, draft or prerelease"),
115 a("delete_release", Op::About(AboutOp::DeleteRelease), "Delete a release; its tag stays"),
116 a("rename_branch", Op::RenameBranch, "Rename a branch"),
117 a("rename", Op::RenameRepo, "Rename it; old addresses redirect"),
118 a("transfer", Op::TransferRepo, "Move it to another workspace you own"),
119 a("mirror", Op::Mirrors(MirrorsOp::GetMirror), "Its remotes: what it mirrors or is mirrored to"),
120 a("mirror_hand_back_plan", Op::Mirrors(MirrorsOp::GetHandBackPlan), "What handing a takeover back would do, ref by ref"),
121 a("mirror_take_over", Op::Mirrors(MirrorsOp::TakeOver), "Make g1t lead a mirror for now"),
122 a("mirror_ci", Op::Mirrors(MirrorsOp::SetCiFailover), "Run a mirror's workflows on g1t (on), or stop (off)"),
123 a("mirror_hand_back", Op::Mirrors(MirrorsOp::HandBack), "Send a takeover back, deciding diverged refs"),
124 a("mirror_move_to_g1t", Op::Mirrors(MirrorsOp::MoveToG1t), "Stop tracking the remote; g1t leads for good"),
125 a("mirror_sync", Op::Mirrors(MirrorsOp::SyncMirror), "Bring its remotes in step now"),
126 a("mirror_add_remote", Op::Mirrors(MirrorsOp::AddRemote), "Link another g1t or git host"),
127 a("mirror_update_remote", Op::Mirrors(MirrorsOp::UpdateRemote), "Change a remote's settings"),
128 a("mirror_remove_remote", Op::Mirrors(MirrorsOp::RemoveRemote), "Unlink a remote"),
129 a("archive", Op::ArchiveRepo, "Make it read-only"),
130 a("unarchive", Op::UnarchiveRepo, "Make it writable again"),
131 a("set_visibility", Op::SetRepoVisibility, "Make it public or private"),
132 a("delete", Op::DeleteRepo, "Delete it; restorable for 30 days"),
133 a("list_deleted", Op::ListDeletedRepos, "A workspace's deleted repositories"),
134 a("restore", Op::RestoreRepo, "Restore a deleted one"),
135 a("purge", Op::PurgeRepo, "Remove a deleted one for good"),
136 a("security_alerts", Op::ListSecurityAlerts, "Secret and dependency alerts, filtered by state"),
137 a("dismiss_alert", Op::DismissSecurityAlert, "Dismiss an alert with a reason"),
138 a("reopen_alert", Op::ReopenSecurityAlert, "Reopen a dismissed alert"),
139 ],
140 },
141 Tool {
142 name: "issue",
143 title: "Issues",
144 description: "Issues: what should change. Read one before working on it to see the pull requests already made for it. Issues and pull requests share numbers; `comment` works on either.",
145 default_action: None,
146 actions: &[
147 a("list", Op::ListIssues, "Issues on a repository, newest first"),
148 a("get", Op::GetIssue, "One issue with comments and its pull requests"),
149 a("create", Op::CreateIssue, "Open an issue"),
150 a("update", Op::UpdateIssue, "Change title, body, labels, milestone or assignees"),
151 a("labels", Op::ListIssueLabels, "The labels an issue or pull request carries"),
152 a("add_labels", Op::AddIssueLabels, "Add labels to an issue or pull request"),
153 a("set_labels", Op::SetIssueLabels, "Replace the labels of an issue or pull request"),
154 a("remove_labels", Op::RemoveIssueLabels, "Take labels off an issue or pull request"),
155 a("close", Op::CloseIssue, "Close it without a pull request"),
156 a("reopen", Op::ReopenIssue, "Reopen it"),
157 a("comment", Op::AddComment, "Comment on an issue or pull request; path and line for one line of a change"),
158 a("edit_comment", Op::EditComment, "Change a comment's text: your own, or any with the Maintain role"),
159 a("delete_comment", Op::DeleteComment, "Delete a comment: your own, or any with the Maintain role"),
160 a("import", Op::ImportIssue, "Open an issue from a Jira, Linear or Sentry item"),
161 ],
162 },
163 Tool {
164 name: "pull_request",
165 title: "Pull requests",
166 description: "Pull requests: start a change for an issue, record your session, mark it ready, ask people and teams to review, review and merge. Read `overlaps` and `behind` on `get` before going far, and `code_owners` for whose approval it needs.",
167 default_action: None,
168 actions: &[
169 a("list", Op::ListPullRequests, "Pull requests on a repository, newest first"),
170 a("get", Op::GetPullRequest, "Status, checks and required checks, reviews, overlaps, whether it is behind"),
171 a("changes", Op::GetPullRequestChanges, "Files and line-by-line diff"),
172 a("create", Op::CreatePullRequest, "Start a draft with its own fork to push to, or open one from a pushed branch"),
173 a("update", Op::UpdatePullRequest, "Change its base branch, labels, milestone, assignees or reviewers"),
174 a("record_session", Op::RecordSession, "Append prompt, reasoning and tool entries to its session"),
175 a("read_session", Op::ReadSession, "Its recorded session"),
176 a("ready", Op::MarkPullRequestReady, "Mark a draft ready, with a summary"),
177 a("draft", Op::ConvertPullRequestToDraft, "Turn it back into a draft"),
178 a("request_reviewers", Op::RequestReviewers, "Ask people or teams to review it"),
179 a("remove_requested_reviewers", Op::RemoveRequestedReviewers, "Stop asking people or teams to review it"),
180 a("review", Op::ReviewPullRequest, "Approve or request changes"),
181 a("close", Op::ClosePullRequest, "Close without merging"),
182 a("reopen", Op::ReopenPullRequest, "Reopen a closed one"),
183 a("merge", Op::MergePullRequest, "Land it, or join the merge queue"),
184 a("merge_queue", Op::GetMergeQueue, "The repository's merge queue"),
185 ],
186 },
187 Tool {
188 name: "agent",
189 title: "g1t agents",
190 description: "Put g1t's agent to work and talk to it. One agent per issue; to do more at once, use more issues. Starting an agent uses the workspace's money.",
191 default_action: None,
192 actions: &[
193 a("delegate", Op::Delegate, "Open an issue and put an agent on it in one step"),
194 a("assign", Op::AssignIssue, "Put an agent on an existing issue"),
195 a("message", Op::MessageAgent, "Tell the agent on a pull request something, or ask another agent"),
196 a("answer", Op::AnswerMessage, "Answer a question or handoff sent to you"),
197 a("take_messages", Op::TakeMessages, "For a g1t agent: messages not seen yet"),
198 ],
199 },
200 Tool {
201 name: "plan",
202 title: "Plans",
203 description: "Turn an outcome into issues: an agent proposes them with what done means and their dependencies; nothing opens until you apply the plan.",
204 default_action: None,
205 actions: &[
206 a("create", Op::PlanWork, "Ask an agent for a plan; read it with get until ready"),
207 a("get", Op::GetPlan, "A plan and the issues it proposes"),
208 a("apply", Op::ApplyPlan, "Open its issues; with assign, agents start in dependency order"),
209 ],
210 },
211 Tool {
212 name: "memory",
213 title: "Memory",
214 description: "What the project and its workspace remember for the next agent: how to build, conventions, decisions, traps. Recall before you start; remember one short fact at a time, never a secret.",
215 default_action: None,
216 actions: &[
217 a("recall", Op::Recall, "Search memory, or list it all"),
218 a("remember", Op::Remember, "Save one fact"),
219 ],
220 },
221 Tool {
222 name: "workflow",
223 title: "Workflows",
224 description: "GitHub Actions workflows from .g1t/workflows: their runs, jobs and logs, and running, cancelling or rerunning them. Runs' artifacts: listing, a download link, deleting, and how long they are kept. Deployments wherever they run (reported from any CI, made by jobs with an `environment:`, or built on g1t.page), their statuses and environments, and reporting your own; environments' protection rules, approving or rejecting the jobs they hold, approving a pull request's run from outside, the token's default permissions and repository dispatch. Checks on commits: statuses, check runs (a g1t Actions job is one) and check suites, to read where a commit stands or report on it from CI or an integration. Also the self-hosted runners they run on: a workspace's (`workspace`) or a repository's own (`repo`), their groups, and where agent work runs.",
225 default_action: None,
226 actions: &[
227 a("list", Op::ListWorkflows, "Workflows on the default branch"),
228 a("list_runs", Op::ListWorkflowRuns, "Runs, newest first"),
229 a("get_run", Op::GetWorkflowRun, "One run with its jobs and steps; an earlier attempt with attempt"),
230 a("job_logs", Op::GetJobLogs, "A job's log after a sequence number"),
231 a("dispatch", Op::DispatchWorkflow, "Run a workflow_dispatch workflow"),
232 a("cancel", Op::CancelWorkflowRun, "Cancel a run, letting its jobs clean up; force stops them outright"),
233 a("rerun", Op::RerunWorkflowRun, "Run a finished run again: all, failed_only, or one job; debug for debug logging"),
234 a("update", Op::UpdateWorkflow, "Turn a workflow on or off"),
235 a("list_artifacts", Op::Artifacts(ArtifactsOp::ListArtifacts), "A repository's artifacts, newest first; or a run's with run_artifacts"),
236 a("run_artifacts", Op::Artifacts(ArtifactsOp::ListRunArtifacts), "One run's artifacts"),
237 a("get_artifact", Op::Artifacts(ArtifactsOp::GetArtifact), "One artifact: size, digest, expiry, run"),
238 a("download_artifact", Op::Artifacts(ArtifactsOp::DownloadArtifact), "A 10-minute link to an artifact's zip"),
239 a("delete_artifact", Op::Artifacts(ArtifactsOp::DeleteArtifact), "Delete an artifact before it expires"),
240 a("artifact_retention", Op::Artifacts(ArtifactsOp::GetArtifactRetention), "Days the repository keeps artifacts"),
241 a("set_artifact_retention", Op::Artifacts(ArtifactsOp::SetArtifactRetention), "Change the days the repository keeps artifacts"),
242 a("combined_status", Op::Checks(ChecksOp::GetCombinedStatus), "A commit's statuses and the state they add up to"),
243 a("list_statuses", Op::Checks(ChecksOp::ListCommitStatuses), "A commit's statuses, newest first"),
244 a("set_status", Op::Checks(ChecksOp::CreateCommitStatus), "Set a status on a commit"),
245 a("list_check_runs", Op::Checks(ChecksOp::ListCheckRunsForRef), "A commit's check runs, g1t Actions jobs included"),
246 a("get_check_run", Op::Checks(ChecksOp::GetCheckRun), "One check run with its report"),
247 a("check_run_annotations", Op::Checks(ChecksOp::ListCheckRunAnnotations), "What a check run says about lines of files"),
248 a("create_check_run", Op::Checks(ChecksOp::CreateCheckRun), "Report a check run on a commit"),
249 a("update_check_run", Op::Checks(ChecksOp::UpdateCheckRun), "Move a check run on, complete it, add annotations"),
250 a("rerequest_check_run", Op::Checks(ChecksOp::RerequestCheckRun), "Ask for a check run to run again"),
251 a("list_check_suites", Op::Checks(ChecksOp::ListCheckSuitesForRef), "A commit's check suites, one per reporter or workflow run"),
252 a("get_check_suite", Op::Checks(ChecksOp::GetCheckSuite), "One check suite"),
253 a("rerequest_check_suite", Op::Checks(ChecksOp::RerequestCheckSuite), "Ask for a check suite to run again"),
254 a("list_deployments", Op::Deployments(DeploymentsOp::ListDeployments), "Deployments wherever they run, newest first, filtered"),
255 a("get_deployment", Op::Deployments(DeploymentsOp::GetDeployment), "One deployment with every status it has had"),
256 a("create_deployment", Op::Deployments(DeploymentsOp::CreateDeployment), "Report a deployment of a ref to an environment"),
257 a("deployment_statuses", Op::Deployments(DeploymentsOp::ListDeploymentStatuses), "A deployment's statuses, newest first"),
258 a("create_deployment_status", Op::Deployments(DeploymentsOp::CreateDeploymentStatus), "Report where a deployment is: in_progress, success, failure"),
259 a("list_environments", Op::Deployments(DeploymentsOp::ListEnvironments), "Environments with their current and latest deployments"),
260 a("get_environment", Op::Deployments(DeploymentsOp::GetEnvironment), "One environment by name, with its protection rules"),
261 a("update_environment", Op::Protection(ProtectionOp::UpdateEnvironment), "Set an environment's reviewers, wait timer and branches"),
262 a("delete_environment", Op::Protection(ProtectionOp::DeleteEnvironment), "Remove an environment's protection rules"),
263 a("pending_deployments", Op::Protection(ProtectionOp::GetPendingDeployments), "The environments holding a run's jobs"),
264 a("review_deployments", Op::Protection(ProtectionOp::ReviewPendingDeployments), "Approve or reject a run's jobs for its environments"),
265 a("approve_run", Op::Protection(ProtectionOp::ApproveWorkflowRun), "Let a run of a pull request from outside start"),
266 a("get_permissions", Op::Protection(ProtectionOp::GetWorkflowPermissions), "What a job's token gets without `permissions:`"),
267 a("set_permissions", Op::Protection(ProtectionOp::SetWorkflowPermissions), "Set it: read or write"),
268 a("get_approval_policy", Op::Protection(ProtectionOp::GetForkPrApproval), "Which pull requests' runs wait for approval"),
269 a("set_approval_policy", Op::Protection(ProtectionOp::SetForkPrApproval), "Set which pull requests' runs wait for approval"),
270 a("get_access", Op::Protection(ProtectionOp::GetActionsAccess), "Which repositories may use this one's actions and workflows"),
271 a("set_access", Op::Protection(ProtectionOp::SetActionsAccess), "Let the workspace's private repositories use them, or not"),
272 a("repository_dispatch", Op::Protection(ProtectionOp::CreateRepositoryDispatch), "Start repository_dispatch workflows with an event"),
273 a("get_workspace_permissions", Op::Protection(ProtectionOp::GetWorkspaceWorkflowPermissions), "A workspace's default and maximum token permissions"),
274 a("set_workspace_permissions", Op::Protection(ProtectionOp::SetWorkspaceWorkflowPermissions), "Set them, and whether jobs may open pull requests"),
275 a("list_runners", Op::ListRunners, "Self-hosted runners, with status, labels and what each is doing"),
276 a("create_runner_token", Op::CreateRunnerRegistrationToken, "A one-hour token for g1t-runner register"),
277 a("remove_runner", Op::RemoveRunner, "Remove a self-hosted runner"),
278 a("list_runner_groups", Op::ListRunnerGroups, "A workspace's runner groups"),
279 a("create_runner_group", Op::CreateRunnerGroup, "Make a group, for some repositories"),
280 a("update_runner_group", Op::UpdateRunnerGroup, "Rename a group or change its repositories"),
281 a("delete_runner_group", Op::DeleteRunnerGroup, "Delete a group; its runners join the default"),
282 a("get_runner_settings", Op::GetRunnerSettings, "Where agent work runs; whether forks may use runners"),
283 a("update_runner_settings", Op::UpdateRunnerSettings, "Change them"),
284 ],
285 },
286 Tool {
287 name: "package",
288 title: "Packages",
289 description: "A workspace's packages in every registry (container images, npm, Cargo, Maven, NuGet, RubyGems, Composer): their versions and downloads, deleting and restoring them within 30 days, their visibility and repository, who has a role on them, and which repositories' workflows may use them (Manage Actions access). Name one by workspace, package_type and package_name.",
290 default_action: None,
291 actions: &[
292 a("list", Op::Packages(PackagesOp::ListPackages), "A workspace's packages; state deleted for restorable ones"),
293 a("get", Op::Packages(PackagesOp::GetPackage), "One package: address, visibility, repository, downloads"),
294 a("versions", Op::Packages(PackagesOp::ListVersions), "Its versions with tags and downloads; state deleted too"),
295 a("get_version", Op::Packages(PackagesOp::GetVersion), "One version by id, version, digest or tag"),
296 a("update", Op::Packages(PackagesOp::UpdatePackage), "Set visibility, or inherit_access for a linked one"),
297 a("link", Op::Packages(PackagesOp::LinkPackage), "Link it to a repository of its workspace"),
298 a("unlink", Op::Packages(PackagesOp::UnlinkPackage), "Unlink it: the workspace's, private"),
299 a("access", Op::Packages(PackagesOp::ListAccess), "People and teams with a role on it"),
300 a("set_access", Op::Packages(PackagesOp::SetAccess), "Give a person or team read, write or admin"),
301 a("remove_access", Op::Packages(PackagesOp::RemoveAccess), "Take a person's or team's role away"),
302 a("actions_access", Op::Packages(PackagesOp::ListActionsAccess), "Repositories whose workflows may use it"),
303 a("set_actions_access", Op::Packages(PackagesOp::SetActionsAccess), "Let a repository's workflows read or write it"),
304 a("remove_actions_access", Op::Packages(PackagesOp::RemoveActionsAccess), "Stop a repository's workflows using it"),
305 a("delete", Op::Packages(PackagesOp::DeletePackage), "Delete it; restorable for 30 days"),
306 a("restore", Op::Packages(PackagesOp::RestorePackage), "Restore a deleted package"),
307 a("delete_version", Op::Packages(PackagesOp::DeleteVersion), "Delete a version; restorable for 30 days"),
308 a("restore_version", Op::Packages(PackagesOp::RestoreVersion), "Restore a deleted version"),
309 ],
310 },
311 Tool {
312 name: "secret",
313 title: "Secrets and variables",
314 description: "A repository's or workspace's secrets and variables, read by workflows and deployments. Secret values are never returned.",
315 default_action: None,
316 actions: &[
317 a("list_secrets", Op::ListActionsSecrets, "Secrets, without values"),
318 a("set_secret", Op::SetActionsSecret, "Add or change a secret"),
319 a("delete_secret", Op::DeleteActionsSecret, "Remove a secret"),
320 a("list_variables", Op::ListActionsVariables, "Variables, with values"),
321 a("set_variable", Op::SetActionsVariable, "Add or change a variable"),
322 a("delete_variable", Op::DeleteActionsVariable, "Remove a variable"),
323 ],
324 },
325 Tool {
326 name: "webhook",
327 title: "Webhooks",
328 description: "HTTPS addresses sent signed events as they happen, for a repository or a whole workspace.",
329 default_action: None,
330 actions: &[
331 a("list", Op::ListWebhooks, "Webhooks, without secrets"),
332 a("create", Op::CreateWebhook, "Register one; a ping is sent"),
333 a("update", Op::UpdateWebhook, "Change address, events or active"),
334 a("delete", Op::DeleteWebhook, "Remove one"),
335 a("ping", Op::PingWebhook, "Send a ping"),
336 a("list_deliveries", Op::ListWebhookDeliveries, "Latest deliveries"),
337 a("redeliver", Op::RedeliverWebhook, "Send a delivery again"),
338 ],
339 },
340 Tool {
341 name: "access",
342 title: "Who has access",
343 description: "Who has access to a repository and with which role (read, triage, write, maintain, admin), outside collaborators, a workspace's base permission, and a repository's deploy keys.",
344 default_action: None,
345 actions: &[
346 a("list_collaborators", Op::ListCollaborators, "Everyone with a role, and pending invitations"),
347 a("get_permission", Op::GetCollaboratorPermission, "One person's role and capabilities"),
348 a("add_collaborator", Op::AddCollaborator, "Give someone a role, by username or email"),
349 a("update_collaborator", Op::UpdateCollaborator, "Change a direct role"),
350 a("remove_collaborator", Op::RemoveCollaborator, "Take away a direct role"),
351 a("list_invitations", Op::ListRepoInvitations, "Pending invitations to a repository"),
352 a("revoke_invitation", Op::RevokeRepoInvitation, "Withdraw one"),
353 a("set_base_permission", Op::SetBasePermission, "What every member gets on each repository"),
354 a("list_outside_collaborators", Op::ListOutsideCollaborators, "People with roles who are not members"),
355 a("list_deploy_keys", Op::DeployKeys(DeployKeysOp::ListDeployKeys), "SSH keys that reach this one repository"),
356 a("get_deploy_key", Op::DeployKeys(DeployKeysOp::GetDeployKey), "One deploy key, by id"),
357 a("add_deploy_key", Op::DeployKeys(DeployKeysOp::CreateDeployKey), "Add one; read-only unless read_only is false"),
358 a("remove_deploy_key", Op::DeployKeys(DeployKeysOp::DeleteDeployKey), "Delete one"),
359 ],
360 },
361 Tool {
362 name: "team",
363 title: "Teams",
364 description: "Teams: groups of a workspace's members, given roles on repositories together, mentioned as @workspace/team and asked to review together. Name one by `workspace` and its slug (`team`). Any member may create a team; the workspace's owners and the team's maintainers manage it. A secret team is seen only by its people and the owners.",
365 default_action: None,
366 actions: &[
367 a("list", Op::ListTeams, "A workspace's teams you can see"),
368 a("get", Op::GetTeam, "One team"),
369 a("create", Op::CreateTeam, "Create a team; you become its maintainer"),
370 a("update", Op::UpdateTeam, "Change its name, slug, description, visibility, parent or notifications"),
371 a("delete", Op::DeleteTeam, "Delete it; its child teams move up"),
372 a("list_members", Op::ListTeamMembers, "Its people and their roles, child teams' with include_child_teams"),
373 a("set_member", Op::SetTeamMember, "Add a member of the workspace, or change their role"),
374 a("remove_member", Op::RemoveTeamMember, "Take someone out of it"),
375 a("list_child_teams", Op::ListChildTeams, "The teams nested under it"),
376 a("list_repos", Op::ListTeamRepos, "The repositories it has a role on"),
377 a("set_repo", Op::SetTeamRepo, "Give it a role on a repository"),
378 a("remove_repo", Op::RemoveTeamRepo, "Take its role on a repository away"),
379 a("set_review_assignment", Op::SetTeamReviewAssignment, "Whom it picks when asked to review"),
380 a("list_user_teams", Op::ListUserTeams, "The teams someone is in"),
381 ],
382 },
383 Tool {
384 name: "workspace",
385 title: "Workspaces",
386 description: "Workspaces own repositories (g1t.sh/{workspace}/{repo}): create, update or delete one, invite members, connect integrations and model providers, set rulesets that hold across its repositories, read and change its projects (what each is, where it runs, its links), and keep your own pinned projects at the top of its sidebar.",
387 default_action: None,
388 actions: &[
389 a("get", Op::GetWorkspace, "A workspace's details and settings"),
390 a("create", Op::CreateWorkspace, "Create a workspace"),
391 a("delete", Op::DeleteWorkspace, "Delete a workspace and everything in it (support can restore it for 30 days)"),
392 a("update", Op::UpdateWorkspace, "Change its name, description, base permission, who may create teams, member privileges or the two-factor requirement"),
393 a("list_members", Op::ListMembers, "Its members, owners first, with their roles"),
394 a("update_member", Op::UpdateMember, "Make someone an owner or a member, billing manager or security manager"),
395 a("remove_member", Op::RemoveMember, "Remove someone from it"),
396 a("transfer_ownership", Op::TransferOwnership, "Hand it to another member: they become an owner, you a member"),
397 a("leave", Op::LeaveWorkspace, "Leave it yourself"),
398 a("list_invites", Op::ListWorkspaceInvites, "Its invites"),
399 a("invite_member", Op::InviteMember, "Invite someone by username or email address"),
400 a("revoke_invite", Op::RevokeWorkspaceInvite, "Revoke a pending invite"),
401 a("list_integrations", Op::ListIntegrations, "Model providers, alert sources, trackers"),
402 a("connect_integration", Op::ConnectIntegration, "Connect one"),
403 a("update_integration", Op::UpdateIntegration, "Change one: rotate its key, choose its AI Gateway models"),
404 a("disconnect_integration", Op::DisconnectIntegration, "Remove one"),
405 a("test_integration", Op::TestIntegration, "Check its credentials"),
406 a("get_model_routes", Op::GetModelRoutes, "Where each kind of work's model requests go"),
407 a("set_model_routes", Op::SetModelRoutes, "Replace them"),
408 a("list_projects", Op::ListProjects, "Its projects you can see: what each is, where it runs, its links"),
409 a("get_project", Op::GetProject, "One project"),
410 a("update_project", Op::UpdateProject, "Change a project's name, description, kind, where it runs or its links"),
411 a("list_pinned_projects", Op::ListPinnedProjects, "Your pinned projects in it, in your order"),
412 a("pin_project", Op::PinProject, "Pin a project, at a position or the end"),
413 a("unpin_project", Op::UnpinProject, "Unpin a project"),
414 a("reorder_pinned_projects", Op::ReorderPinnedProjects, "Put your pins in a new order"),
415 a("list_rulesets", Op::Rules(RulesOp::ListWorkspaceRulesets), "Its rulesets, which hold across its repositories"),
416 a("get_ruleset", Op::Rules(RulesOp::GetWorkspaceRuleset), "One of its rulesets"),
417 a("create_ruleset", Op::Rules(RulesOp::CreateWorkspaceRuleset), "Create a ruleset for some or all of its repositories"),
418 a("update_ruleset", Op::Rules(RulesOp::UpdateWorkspaceRuleset), "Change one of its rulesets"),
419 a("delete_ruleset", Op::Rules(RulesOp::DeleteWorkspaceRuleset), "Delete one of its rulesets"),
420 a("rule_evaluations", Op::Rules(RulesOp::ListWorkspaceRuleEvaluations), "How rules judged changes across its repositories"),
421 a("get_token_policy", Op::Tokens(TokenOp::GetTokenPolicy), "Its rules for personal access tokens"),
422 a("set_token_policy", Op::Tokens(TokenOp::SetTokenPolicy), "Change them: which tokens reach it, approval, lifetime"),
423 a("list_member_tokens", Op::Tokens(TokenOp::ListMemberTokens), "Members' personal access tokens that reach it"),
424 a("list_token_requests", Op::Tokens(TokenOp::ListTokenRequests), "Tokens waiting for approval"),
425 a("review_token_request", Op::Tokens(TokenOp::ReviewTokenRequest), "Approve or deny one"),
426 a("revoke_member_token", Op::Tokens(TokenOp::RevokeMemberToken), "Revoke a member's token in it"),
427 ],
428 },
429 Tool {
430 name: "billing",
431 title: "Billing",
432 description: "A workspace's billing: its usage by product, project and day, its budget (the monthly spend limit, alerts and whether usage pauses at it), its AI credit, its invoices, and its AI Gateway requests. Amounts are whole millionths of a dollar (`_micros`), or cents (`_cents`) where named. Members read it; changing the budget and buying credit are for owners, as people, and never for g1t's agents.",
433 default_action: Some("usage"),
434 actions: &[
435 a("usage", Op::GetUsage, "Usage over a range of days, by product, meter, project and day, and what paid for it"),
436 a("budget", Op::GetBudget, "The monthly spend limit, what was spent, alerts and whether usage pauses at the limit"),
437 a("set_budget", Op::SetBudget, "Change the spend limit, alerts, pausing or the alert webhook"),
438 a("ai_credit", Op::GetAiCredit, "AI credit left, its grants, auto-reload and how to buy more"),
439 a("buy_ai_credit", Op::BuyAiCredit, "A payment page to buy AI credit, for a person to open"),
440 a("invoices", Op::ListInvoices, "Every invoice, the itemised usage invoices, and the next one so far"),
441 a("billing_details", Op::GetBillingDetails, "Who invoices are made out to and the payment method on file"),
442 a("gateway_requests", Op::ListGatewayRequests, "Recent AI Gateway requests: model, tokens, cost, status and token"),
443 ],
444 },
445 Tool {
446 name: "security",
447 title: "Security",
448 description: "A repository's security: secret scanning alerts and push protection bypasses, custom secret patterns, code scanning alerts and SARIF uploads, vulnerability alerts, the dependency graph and its SBOM, dependency review, settings, and a workspace's overview. Fix an alert with g1t. Findings are shown to those who can change the code only. Give `repo` (owner/name), or `workspace` for lists across one.",
449 default_action: Some("secret_alerts"),
450 actions: &[
451 a("secret_alerts", Op::Security(SecurityOp::ListSecretAlerts), "Secret scanning alerts; by state, secret_type, validity, bypassed"),
452 a("secret_alert", Op::Security(SecurityOp::GetSecretAlert), "One secret alert, with where it was found and its bypass requests"),
453 a("update_secret_alert", Op::Security(SecurityOp::UpdateSecretAlert), "Dismiss a secret alert with a reason, or reopen it"),
454 a("secret_locations", Op::Security(SecurityOp::ListSecretLocations), "Every file, line and commit a secret is in"),
455 a("bypass", Op::Security(SecurityOp::BypassPushProtection), "Push past push protection with a reason, or ask to"),
456 a("check_validity", Op::Security(SecurityOp::CheckSecretValidity), "Ask a secret's issuer whether it still works"),
457 a("bypass_requests", Op::Security(SecurityOp::ListBypassRequests), "A workspace's push protection bypass requests"),
458 a("review_bypass", Op::Security(SecurityOp::ReviewBypassRequest), "Approve, deny or cancel a bypass request"),
459 a("patterns", Op::Security(SecurityOp::ListCustomPatterns), "Custom secret patterns of a repository or workspace"),
460 a("create_pattern", Op::Security(SecurityOp::CreateCustomPattern), "Create a custom secret pattern, as a draft or published"),
461 a("update_pattern", Op::Security(SecurityOp::UpdateCustomPattern), "Change, publish or unpublish a custom pattern"),
462 a("delete_pattern", Op::Security(SecurityOp::DeleteCustomPattern), "Delete a custom pattern"),
463 a("dry_run_pattern", Op::Security(SecurityOp::DryRunCustomPattern), "Run a pattern over the default branch without saving it"),
464 a("code_alerts", Op::Security(SecurityOp::ListCodeAlerts), "Code scanning alerts; by state, severity, tool, rule_id"),
465 a("code_alert", Op::Security(SecurityOp::GetCodeAlert), "One code scanning alert by number"),
466 a("update_code_alert", Op::Security(SecurityOp::UpdateCodeAlert), "Dismiss a code scanning alert with a reason, or reopen it"),
467 a("analyses", Op::Security(SecurityOp::ListAnalyses), "Code scanning analyses, newest first"),
468 a("upload_sarif", Op::Security(SecurityOp::UploadSarif), "Upload a SARIF file, gzipped and base64-encoded"),
469 a("sarif_upload", Op::Security(SecurityOp::GetSarifUpload), "Whether a SARIF upload was read, and its analyses"),
470 a("vulnerability_alerts", Op::Security(SecurityOp::ListVulnerabilityAlerts), "Vulnerable dependencies; by state, severity, ecosystem, package"),
471 a("vulnerability_alert", Op::Security(SecurityOp::GetVulnerabilityAlert), "One vulnerability alert"),
472 a("update_vulnerability_alert", Op::Security(SecurityOp::UpdateVulnerabilityAlert), "Dismiss a vulnerability alert with a reason, or reopen it"),
473 a("fix", Op::Security(SecurityOp::FixAlert), "Put g1t on an issue to fix an alert"),
474 a("dependency_graph", Op::Security(SecurityOp::GetDependencyGraph), "Every package the lockfiles resolve, direct or transitive"),
475 a("sbom", Op::Security(SecurityOp::GetSbom), "The dependency graph as an SPDX 2.3 document"),
476 a("compare_dependencies", Op::Security(SecurityOp::CompareDependencies), "What changes in dependencies between base...head"),
477 a("settings", Op::Security(SecurityOp::GetSettings), "A repository's security settings"),
478 a("update_settings", Op::Security(SecurityOp::UpdateSettings), "Change when checks fail and dependency review's policy"),
479 a("workspace_settings", Op::Security(SecurityOp::GetWorkspaceSettings), "A workspace's delegated bypass and validity checks"),
480 a("update_workspace_settings", Op::Security(SecurityOp::UpdateWorkspaceSettings), "Turn delegated bypass or validity checks on or off"),
481 a("overview", Op::Security(SecurityOp::GetOverview), "A workspace's alerts, trends and coverage"),
482 ],
483 },
484 Tool {
485 name: "notifications",
486 title: "Notifications",
487 description: "Your inbox: what needs you, and what you follow. One thread per issue, pull request, workflow or deployment, with why you were told (`reason`): an agent waiting on you, a review asked of you, an assignment, a mention, your work's checks, or what you subscribe to and watch. Mark threads read or done once handled, and choose what you hear of with subscribe, unsubscribe and watch. Your own: a personal token.",
488 default_action: Some("list"),
489 actions: &[
490 a("list", Op::ListNotifications, "Unread threads, latest first; all, a view, a reason, a repository"),
491 a("get", Op::GetNotificationThread, "One thread with its recent activity and your subscription"),
492 a("mark_read", Op::MarkThreadRead, "Mark a thread read, or unread"),
493 a("mark_all_read", Op::MarkNotificationsRead, "Mark everything read up to a time, or one repository's"),
494 a("done", Op::MarkThreadDone, "Mark a thread done; new activity brings it back"),
495 a("save", Op::SaveThread, "Save a thread, or unsave it"),
496 a("snooze", Op::SnoozeThread, "Snooze a thread until a time, or bring it back"),
497 a("subscription", Op::GetThreadSubscription, "Your subscription to an issue or pull request"),
498 a("subscribe", Op::SetThreadSubscription, "Subscribe to an issue or pull request, or ignore it"),
499 a("unsubscribe", Op::DeleteThreadSubscription, "Unsubscribe until you comment or are mentioned"),
500 a("watching", Op::GetRepoSubscription, "How you watch a repository"),
501 a("watch", Op::SetRepoSubscription, "Watch a repository: participating, all, ignore or custom"),
502 a("unwatch", Op::DeleteRepoSubscription, "Stop watching a repository"),
503 a("watched", Op::ListWatchedRepos, "Repositories you watch other than the default way"),
504 ],
505 },
506 Tool {
507 name: "account",
508 title: "Your account",
509 description: "Who this token acts as and its workspaces (`whoami`), your email addresses, your invites, and invitations to workspaces and repositories waiting for you.",
510 default_action: Some("whoami"),
511 actions: &[
512 a("whoami", Op::Whoami, "Who the token acts as, and its workspaces"),
513 a("list_emails", Op::ListEmails, "Your addresses"),
514 a("add_email", Op::AddEmail, "Add an address"),
515 a("confirm_email", Op::ConfirmEmail, "Confirm an address with the code from its email"),
516 a("remove_email", Op::RemoveEmail, "Remove an address"),
517 a("update_email_settings", Op::UpdateEmailSettings, "Primary, backup and privacy"),
518 a("list_invites", Op::ListInvites, "Your invites to g1t"),
519 a("create_invite", Op::CreateInvite, "Make an invite"),
520 a("revoke_invite", Op::RevokeInvite, "Revoke one"),
521 a("list_workspace_invitations", Op::ListInvitations, "Invitations to workspaces for you"),
522 a("accept_workspace_invitation", Op::AcceptInvitation, "Accept one and join"),
523 a("decline_workspace_invitation", Op::DeclineInvitation, "Decline one"),
524 a("list_repository_invitations", Op::ListMyRepoInvitations, "Invitations to repositories for you"),
525 a("accept_repository_invitation", Op::AcceptRepoInvitation, "Accept one"),
526 a("decline_repository_invitation", Op::DeclineRepoInvitation, "Decline one"),
527 ],
528 },
529 Tool {
530 name: "artifact",
531 title: "Artifacts",
532 description: "A workspace's docs, slides, designs and dashboards (Artifacts mode), as you can open them: list, search and read them (a doc's content is Markdown, with block ids to target), make them, edit them (a change with the edit role, a suggestion with comment), move, trash and restore them, their versions, and who can open them. Name one by its id (fol_…) or its address. Not the `workflow` tool's run artifacts. Slides, designs and dashboards answer that they are not here yet.",
533 default_action: None,
534 actions: &[
535 a("list", Op::Folios(FoliosOp::List), "Artifacts you can open; tab, kind, space, q; state trashed for the trash"),
536 a("search", Op::Folios(FoliosOp::Search), "Search them by words and meaning, with the passage that matched"),
537 a("get", Op::Folios(FoliosOp::Get), "One artifact: kind, title, space, owner, your role, who it is shared with"),
538 a("read", Op::Folios(FoliosOp::GetContent), "Its content: a doc's Markdown and block ids, and what you may do"),
539 a("versions", Op::Folios(FoliosOp::ListVersions), "Its saved versions, newest first"),
540 a("access", Op::Folios(FoliosOp::GetAccess), "Who can open it, and how"),
541 a("templates", Op::Folios(FoliosOp::ListTemplates), "Templates to start one from"),
542 a("spaces", Op::Folios(FoliosOp::ListSpaces), "The spaces in your sidebar"),
543 a("query_data", Op::Folios(FoliosOp::QueryDataset), "Run a dataset query as you, over what you can read"),
544 a("create", Op::Folios(FoliosOp::Create), "Make one: in a space, under a doc, or in your Private"),
545 a("update", Op::Folios(FoliosOp::Update), "Rename it, change its icon, or move it"),
546 a("edit", Op::Folios(FoliosOp::Edit), "Change its content: append, replace it all, a section or blocks"),
547 a("trash", Op::Folios(FoliosOp::Trash), "Move it to the trash; restorable for 30 days"),
548 a("restore", Op::Folios(FoliosOp::Restore), "Bring it back from the trash"),
549 a("restore_version", Op::Folios(FoliosOp::RestoreVersion), "Make an earlier version its content again"),
550 a("share", Op::Folios(FoliosOp::SetAccess), "Share it, change general access, or take access away"),
551 a("purge", Op::Folios(FoliosOp::Purge), "Delete one in the trash for good"),
552 ],
553 },
554];
555
556/// Operations that cannot be undone, or reach beyond g1t's own records:
557/// clients ask before running a tool that has any of them.
558fn destructive(op: Op) -> bool {
559 matches!(
560 op,
561 Op::Security(SecurityOp::DeleteCustomPattern | SecurityOp::BypassPushProtection)
562 | Op::Rules(RulesOp::DeleteRepoRuleset | RulesOp::DeleteWorkspaceRuleset)
563 | Op::DeleteWorkspace
564 | Op::UpdateWorkspace
565 | Op::Tokens(TokenOp::RevokeMemberToken | TokenOp::SetTokenPolicy)
566 | Op::RemoveMember
567 | Op::TransferOwnership
568 | Op::LeaveWorkspace
569 | Op::DeleteRepo
570 | Op::PurgeRepo
571 | Op::TransferRepo
572 | Op::SetRepoVisibility
573 | Op::RemoveEmail
574 | Op::RemoveCollaborator
575 | Op::DisconnectIntegration
576 | Op::UpdateIntegration
577 | Op::DeleteWebhook
578 | Op::DeleteActionsSecret
579 | Op::DeleteActionsVariable
580 | Op::SetActionsSecret
581 | Op::SetActionsVariable
582 | Op::SetModelRoutes
583 | Op::SetBasePermission
584 | Op::DeleteTeam
585 | Op::RemoveTeamRepo
586 | Op::MergePullRequest
587 | Op::RemoveRunner
588 | Op::DeleteRunnerGroup
589 | Op::UpdateRunnerSettings
590 | Op::Folios(FoliosOp::SetAccess | FoliosOp::Purge)
591 )
592}
593
594/// Whether an operation only reads.
595pub fn reads_only(op: Op) -> bool {
596 NO_SCOPE.contains(&op.name())
597 || scope_for(op.name()).is_some_and(|scope| scope.level() == Level::Read)
598}
599
600/// What decides which actions a caller sees.
601pub enum Gate<'a> {
602 /// No limit beyond the person's own role.
603 Everything,
604 /// A g1t agent's token: the operations its run lists.
605 Agent(&'a AgentScope),
606 /// An access token with scopes.
607 Token(&'a TokenAccess),
608}
609
610impl Gate<'_> {
611 pub fn allows(&self, op: Op) -> bool {
612 match self {
613 Gate::Everything => true,
614 Gate::Agent(scope) => op.allowed_by(scope) && !NEVER.contains(&op.name()),
615 Gate::Token(access) => {
616 if NO_SCOPE.contains(&op.name()) {
617 return true;
618 }
619 match scope_for(op.name()) {
620 Some(scope) => access.allows(scope),
621 None => access.scopes.is_none(),
622 }
623 }
624 }
625 }
626}
627
628impl Tool {
629 pub fn by_name(name: &str) -> Option<&'static Tool> {
630 TOOLS.iter().find(|tool| tool.name == name)
631 }
632
633 pub fn action(&self, name: &str) -> Option<&'static Action> {
634 // The tools are 'static; find through TOOLS to keep the lifetime.
635 TOOLS
636 .iter()
637 .find(|tool| tool.name == self.name)
638 .and_then(|tool| tool.actions.iter().find(|action| action.name == name))
639 }
640
641 pub fn visible(&self, gate: &Gate) -> Vec<&'static Action> {
642 TOOLS
643 .iter()
644 .find(|tool| tool.name == self.name)
645 .map(|tool| tool.actions.iter().filter(|action| gate.allows(action.op)).collect())
646 .unwrap_or_default()
647 }
648
649 /// The flat input schema of the actions given.
650 pub fn input_schema(&self, actions: &[&Action]) -> Value {
651 let mut properties = Map::new();
652 let lines: Vec<String> = actions
653 .iter()
654 .map(|action| {
655 let required: Vec<String> = action.op.required();
656 if required.is_empty() {
657 format!("{}: {}.", action.name, action.summary)
658 } else {
659 format!("{} ({}): {}.", action.name, required.join(", "), action.summary)
660 }
661 })
662 .collect();
663 let mut action_schema = json!({
664 "type": "string",
665 "enum": actions.iter().map(|action| action.name).collect::<Vec<_>>(),
666 "description": lines.join("\n"),
667 });
668 if let Some(default) = self.default_action.filter(|name| actions.iter().any(|action| action.name == *name)) {
669 action_schema["default"] = json!(default);
670 }
671 properties.insert("action".to_owned(), action_schema);
672 for action in actions {
673 for (name, schema) in action.op.properties() {
674 merge_property(&mut properties, name, schema);
675 }
676 }
677 let mut required = vec![];
678 if self.default_action.is_none() {
679 required.push("action");
680 }
681 let mut schema = json!({ "type": "object", "properties": properties });
682 if !required.is_empty() {
683 schema["required"] = json!(required);
684 }
685 schema
686 }
687
688 /// The input schema keyed by action: one `oneOf` branch per action,
689 /// each with its own fields and the ones it needs.
690 pub fn discriminated(&self, actions: &[&Action]) -> Value {
691 let branches: Vec<Value> = actions
692 .iter()
693 .map(|action| {
694 let mut properties = Map::new();
695 properties.insert("action".to_owned(), json!({ "const": action.name }));
696 properties.extend(action.op.properties());
697 let mut required = vec![Value::String("action".to_owned())];
698 // The default action may leave `action` out.
699 if self.default_action == Some(action.name) {
700 required.clear();
701 }
702 required.extend(action.op.required().into_iter().map(Value::String));
703 json!({
704 "title": action.name,
705 "description": action.summary,
706 "type": "object",
707 "properties": properties,
708 "required": required,
709 })
710 })
711 .collect();
712 json!({ "type": "object", "oneOf": branches })
713 }
714
715 /// MCP's hints about the actions given: whether the tool only reads,
716 /// whether it can destroy something, and whether calling it twice is
717 /// the same as once.
718 pub fn annotations(&self, actions: &[&Action]) -> Value {
719 let read_only = actions.iter().all(|action| reads_only(action.op));
720 json!({
721 "title": self.title,
722 "readOnlyHint": read_only,
723 "destructiveHint": !read_only && actions.iter().any(|action| destructive(action.op)),
724 "idempotentHint": read_only,
725 "openWorldHint": false,
726 })
727 }
728
729 /// The tool as `tools/list` gives it, for a caller behind `gate`, or
730 /// `None` when it may use none of its actions.
731 pub fn listed(&self, gate: &Gate) -> Option<Value> {
732 let actions = self.visible(gate);
733 if actions.is_empty() {
734 return None;
735 }
736 Some(json!({
737 "name": self.name,
738 "title": self.title,
739 "description": self.description,
740 "inputSchema": self.input_schema(&actions),
741 "annotations": self.annotations(&actions),
742 }))
743 }
744}
745
746/// Adds a property to a tool's flat schema. The first action to use a name
747/// describes it; a later one with other allowed values adds them.
748fn merge_property(properties: &mut Map<String, Value>, name: String, schema: Value) {
749 match properties.get_mut(&name) {
750 None => {
751 properties.insert(name, schema);
752 }
753 Some(existing) => {
754 if let (Some(Value::Array(had)), Some(Value::Array(more))) =
755 (existing.get("enum").cloned(), schema.get("enum"))
756 {
757 let mut merged = had;
758 for value in more {
759 if !merged.contains(value) {
760 merged.push(value.clone());
761 }
762 }
763 existing["enum"] = Value::Array(merged);
764 }
765 // Different kinds of value under one name: say less, accept both.
766 if existing.get("type") != schema.get("type")
767 && let Some(fields) = existing.as_object_mut()
768 {
769 fields.remove("type");
770 fields.remove("items");
771 }
772 }
773 }
774}
775
776/// What a call to a tool runs: the operation its action names, or why not.
777pub fn resolve(tool: &Tool, arguments: &Value) -> Result<Op, String> {
778 let names = || {
779 tool.actions
780 .iter()
781 .map(|action| action.name)
782 .collect::<Vec<_>>()
783 .join(", ")
784 };
785 let Some(name) = arguments["action"].as_str().or(tool.default_action) else {
786 return Err(format!("Give an action: one of {}.", names()));
787 };
788 let Some(action) = tool.action(name) else {
789 return Err(format!("{} has no action {name}. Its actions: {}.", tool.name, names()));
790 };
791 let missing: Vec<String> = action
792 .op
793 .required()
794 .into_iter()
795 .filter(|field| arguments.get(field).is_none_or(Value::is_null))
796 .collect();
797 if !missing.is_empty() {
798 return Err(format!("{}.{name} needs {}.", tool.name, missing.join(", ")));
799 }
800 Ok(action.op)
801}
802
803#[cfg(test)]
804mod tests {
805 use super::*;
806 use g1t_contracts::scopes::{Preset, Scope};
807
808 fn listed(gate: &Gate) -> Vec<Value> {
809 TOOLS.iter().filter_map(|tool| tool.listed(gate)).collect()
810 }
811
812 fn token(scopes: Option<Vec<Scope>>) -> TokenAccess {
813 TokenAccess {
814 token_id: "tok_1".to_owned(),
815 scopes: scopes.map(|scopes| scopes.iter().map(|scope| scope.as_str().to_owned()).collect()),
816 legacy: false,
817 name: None,
818 ..TokenAccess::default()
819 }
820 }
821
822 #[test]
823 fn every_operation_is_exactly_one_action_of_one_tool() {
824 for op in Op::ALL {
825 let count = TOOLS
826 .iter()
827 .flat_map(|tool| tool.actions.iter())
828 .filter(|action| action.op == op)
829 .count();
830 assert_eq!(count, 1, "{} is {count} actions", op.name());
831 }
832 for tool in TOOLS {
833 let mut names = std::collections::HashSet::new();
834 for action in tool.actions {
835 assert!(names.insert(action.name), "{}.{} twice", tool.name, action.name);
836 }
837 if let Some(default) = tool.default_action {
838 assert!(tool.action(default).is_some(), "{}", tool.name);
839 }
840 }
841 assert!(TOOLS.len() <= 19, "{} tools", TOOLS.len());
842 }
843
844 #[test]
845 fn every_operation_needs_exactly_one_scope_or_none() {
846 use g1t_contracts::scopes::OPERATIONS;
847 for op in Op::ALL {
848 let mapped = OPERATIONS.iter().filter(|(name, _)| *name == op.name()).count();
849 let free = NO_SCOPE.contains(&op.name());
850 assert_eq!(mapped + usize::from(free), 1, "{}", op.name());
851 }
852 for (name, _) in OPERATIONS {
853 assert!(Op::by_name(name).is_some(), "{name} is not an operation");
854 }
855 }
856
857 #[test]
858 fn each_tool_schema_is_valid_with_one_branch_per_action() {
859 for tool in TOOLS {
860 let actions: Vec<&Action> = tool.actions.iter().collect();
861 let flat = tool.input_schema(&actions);
862 assert_eq!(flat["type"], "object");
863 assert!(flat.get("oneOf").is_none(), "no oneOf at the top level");
864 let listed: Vec<&str> = flat["properties"]["action"]["enum"]
865 .as_array()
866 .unwrap()
867 .iter()
868 .map(|name| name.as_str().unwrap())
869 .collect();
870 assert_eq!(listed, tool.actions.iter().map(|action| action.name).collect::<Vec<_>>());
871 for action in tool.actions {
872 for field in action.op.required() {
873 assert!(flat["properties"].get(&field).is_some(), "{}.{}: {field}", tool.name, action.name);
874 }
875 }
876 let keyed = tool.discriminated(&actions);
877 let branches = keyed["oneOf"].as_array().unwrap();
878 assert_eq!(branches.len(), tool.actions.len());
879 for (branch, action) in branches.iter().zip(tool.actions) {
880 assert_eq!(branch["properties"]["action"]["const"], action.name);
881 for field in branch["required"].as_array().unwrap() {
882 assert!(branch["properties"].get(field.as_str().unwrap()).is_some(), "{}.{}: {field}", tool.name, action.name);
883 }
884 }
885 // A well-formed JSON Schema object throughout.
886 let text = serde_json::to_string(&flat).unwrap();
887 assert!(serde_json::from_str::<Value>(&text).is_ok());
888 }
889 }
890
891 #[test]
892 fn a_read_only_token_sees_read_actions_only() {
893 let access = token(Preset::ReadOnly.scopes());
894 let gate = Gate::Token(&access);
895 for tool in TOOLS {
896 for action in tool.visible(&gate) {
897 assert!(reads_only(action.op), "{}.{}", tool.name, action.name);
898 }
899 }
900 let tools = listed(&gate);
901 for tool in &tools {
902 assert_eq!(tool["annotations"]["readOnlyHint"], true, "{}", tool["name"]);
903 assert_eq!(tool["annotations"]["destructiveHint"], false);
904 }
905 let issue = tools.iter().find(|tool| tool["name"] == "issue").unwrap();
906 assert_eq!(issue["inputSchema"]["properties"]["action"]["enum"], json!(["list", "get", "labels"]));
907 // Nothing of the agent tool is a read.
908 assert!(!tools.iter().any(|tool| tool["name"] == "agent"));
909 }
910
911 #[test]
912 fn a_narrow_token_sees_only_its_tools() {
913 let access = token(Some(vec![Scope::IssuesWrite]));
914 let names: Vec<Value> = listed(&Gate::Token(&access)).into_iter().map(|tool| tool["name"].clone()).collect();
915 // Labels and milestones are the repository's, managed with issues:write.
916 assert_eq!(names, vec![json!("repository"), json!("issue"), json!("plan"), json!("account")]);
917 // Notifications are a resource of their own: reading them lists
918 // only what reads.
919 let reader = token(Some(vec![Scope::NotificationsRead]));
920 let tools = listed(&Gate::Token(&reader));
921 let notifications = tools.iter().find(|tool| tool["name"] == "notifications").unwrap();
922 assert_eq!(
923 notifications["inputSchema"]["properties"]["action"]["enum"],
924 json!(["list", "get", "subscription", "watching", "watched"])
925 );
926 assert_eq!(notifications["annotations"]["readOnlyHint"], true);
927 let full = token(None);
928 assert_eq!(listed(&Gate::Token(&full)).len(), TOOLS.len());
929 assert_eq!(listed(&Gate::Everything).len(), TOOLS.len());
930 }
931
932 #[test]
933 fn a_tool_that_can_destroy_says_so() {
934 let tools = listed(&Gate::Everything);
935 let repository = tools.iter().find(|tool| tool["name"] == "repository").unwrap();
936 assert_eq!(repository["annotations"]["destructiveHint"], true);
937 assert_eq!(repository["annotations"]["readOnlyHint"], false);
938 let memory = tools.iter().find(|tool| tool["name"] == "memory").unwrap();
939 assert_eq!(memory["annotations"]["destructiveHint"], false);
940 }
941
942 #[test]
943 fn calls_resolve_to_their_operation_or_say_what_is_missing() {
944 let issue = Tool::by_name("issue").unwrap();
945 assert_eq!(resolve(issue, &json!({ "action": "get", "repo": "a/b", "number": 1 })), Ok(Op::GetIssue));
946 assert_eq!(resolve(issue, &json!({ "action": "get", "repo": "a/b" })), Err("issue.get needs number.".to_owned()));
947 assert!(resolve(issue, &json!({})).unwrap_err().starts_with("Give an action"));
948 assert!(resolve(issue, &json!({ "action": "explode" })).unwrap_err().contains("no action explode"));
949 let search = Tool::by_name("search").unwrap();
950 assert_eq!(resolve(search, &json!({ "query": "x" })), Ok(Op::Search));
951 let account = Tool::by_name("account").unwrap();
952 assert_eq!(resolve(account, &json!({})), Ok(Op::Whoami));
953 }
954
955 #[test]
956 fn teams_are_one_tool_and_a_workspace_reader_sees_only_its_reads() {
957 let team = Tool::by_name("team").unwrap();
958 let names: Vec<&str> = team.actions.iter().map(|action| action.name).collect();
959 assert_eq!(
960 names,
961 [
962 "list",
963 "get",
964 "create",
965 "update",
966 "delete",
967 "list_members",
968 "set_member",
969 "remove_member",
970 "list_child_teams",
971 "list_repos",
972 "set_repo",
973 "remove_repo",
974 "set_review_assignment",
975 "list_user_teams",
976 ]
977 );
978 let reader = token(Some(vec![Scope::WorkspaceRead]));
979 let tools = listed(&Gate::Token(&reader));
980 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
981 assert_eq!(
982 listed_team["inputSchema"]["properties"]["action"]["enum"],
983 json!(["list", "get", "list_members", "list_child_teams", "list_repos", "list_user_teams"])
984 );
985 assert_eq!(listed_team["annotations"]["readOnlyHint"], true);
986 // A team's role on a repository is who has access.
987 let admin = token(Some(vec![Scope::WorkspaceAdmin]));
988 let tools = listed(&Gate::Token(&admin));
989 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
990 let actions = listed_team["inputSchema"]["properties"]["action"]["enum"].as_array().unwrap();
991 assert!(actions.contains(&json!("set_review_assignment")) && !actions.contains(&json!("set_repo")));
992 let access = token(Some(vec![Scope::AccessAdmin]));
993 let tools = listed(&Gate::Token(&access));
994 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
995 assert_eq!(listed_team["inputSchema"]["properties"]["action"]["enum"], json!(["set_repo", "remove_repo"]));
996 // Both kinds of role a schema names are offered.
997 let roles = &listed(&Gate::Everything).into_iter().find(|tool| tool["name"] == "team").unwrap()["inputSchema"]
998 ["properties"]["role"]["enum"];
999 for role in ["member", "maintainer", "read", "admin"] {
1000 assert!(roles.as_array().unwrap().contains(&json!(role)), "{role}");
1001 }
1002 assert_eq!(
1003 resolve(team, &json!({ "action": "set_repo", "workspace": "acme", "team": "backend", "repo": "rocket" })),
1004 Err("team.set_repo needs role.".to_owned())
1005 );
1006 }
1007
1008 #[test]
1009 fn reviewers_and_code_owners_are_actions_of_their_tools() {
1010 let pull = Tool::by_name("pull_request").unwrap();
1011 assert_eq!(
1012 resolve(pull, &json!({ "action": "request_reviewers", "repo": "a/b", "number": 1, "team_reviewers": ["backend"] })),
1013 Ok(Op::RequestReviewers)
1014 );
1015 assert_eq!(pull.action("remove_requested_reviewers").map(|action| action.op), Some(Op::RemoveRequestedReviewers));
1016 let repository = Tool::by_name("repository").unwrap();
1017 assert_eq!(resolve(repository, &json!({ "action": "codeowners", "repo": "a/b" })), Ok(Op::GetCodeownersErrors));
1018 assert!(reads_only(Op::GetCodeownersErrors));
1019 assert!(!reads_only(Op::RequestReviewers));
1020 }
1021
1022 /// The `artifact` tool offers each token only what its artifacts scope
1023 /// allows: reading, then changing, then sharing and deleting for good.
1024 /// Workflow runs' artifacts are the `workflow` tool's, under their own
1025 /// scope, and neither scope reaches the other's.
1026 #[test]
1027 fn the_artifact_tool_offers_what_the_artifacts_scope_allows() {
1028 let actions = |scopes: Vec<Scope>| -> Option<Value> {
1029 let access = token(Some(scopes));
1030 Tool::by_name("artifact").unwrap().listed(&Gate::Token(&access)).map(|tool| tool["inputSchema"]["properties"]["action"]["enum"].clone())
1031 };
1032 let reads = json!(["list", "search", "get", "read", "versions", "access", "templates", "spaces", "query_data"]);
1033 assert_eq!(actions(vec![Scope::ArtifactsRead]), Some(reads.clone()));
1034 let writes = actions(vec![Scope::ArtifactsWrite]).unwrap();
1035 for action in ["create", "update", "edit", "trash", "restore", "restore_version"] {
1036 assert!(writes.as_array().unwrap().contains(&json!(action)), "{action}");
1037 }
1038 assert!(!writes.as_array().unwrap().contains(&json!("share")) && !writes.as_array().unwrap().contains(&json!("purge")));
1039 let admin = actions(vec![Scope::ArtifactsAdmin]).unwrap();
1040 assert_eq!(admin.as_array().unwrap().len(), Tool::by_name("artifact").unwrap().actions.len());
1041 // Without an artifacts scope there is no artifact tool at all.
1042 assert_eq!(actions(vec![Scope::WorkflowsWrite, Scope::IssuesWrite]), None);
1043 // And an artifacts scope shows nothing of workflow runs' artifacts.
1044 let access = token(Some(vec![Scope::ArtifactsAdmin]));
1045 assert!(Tool::by_name("workflow").unwrap().listed(&Gate::Token(&access)).is_none());
1046 // The read-only and agent presets read artifacts and change none.
1047 for preset in [Preset::ReadOnly, Preset::Agent] {
1048 let access = token(preset.scopes());
1049 let tool = Tool::by_name("artifact").unwrap().listed(&Gate::Token(&access)).unwrap();
1050 assert_eq!(tool["inputSchema"]["properties"]["action"]["enum"], reads, "{}", preset.as_str());
1051 assert_eq!(tool["annotations"]["readOnlyHint"], true);
1052 }
1053 // Sharing and deleting for good can't be undone the same way.
1054 let tools = listed(&Gate::Everything);
1055 let artifact = tools.iter().find(|tool| tool["name"] == "artifact").unwrap();
1056 assert_eq!(artifact["annotations"]["destructiveHint"], true);
1057 assert!(artifact["description"].as_str().unwrap().contains("Not the `workflow` tool's run artifacts"));
1058 let tool = Tool::by_name("artifact").unwrap();
1059 assert_eq!(resolve(tool, &json!({ "action": "read", "workspace": "acme" })), Err("artifact.read needs artifact_id.".to_owned()));
1060 assert_eq!(
1061 resolve(tool, &json!({ "action": "edit", "workspace": "acme", "artifact_id": "fol_1", "markdown": "x" })),
1062 Ok(Op::Folios(FoliosOp::Edit))
1063 );
1064 }
1065
1066 /// How much smaller `tools/list` is than one tool per operation. Run
1067 /// with `--nocapture` to see the numbers.
1068 #[test]
1069 fn the_tool_list_is_much_smaller_than_one_tool_per_operation() {
1070 let before: Vec<Value> = Op::ALL
1071 .into_iter()
1072 .map(|op| json!({ "name": op.name(), "description": op.description(), "inputSchema": op.input() }))
1073 .collect();
1074 let after = listed(&Gate::Everything);
1075 let before_bytes = serde_json::to_string(&json!({ "tools": before })).unwrap().len();
1076 let after_bytes = serde_json::to_string(&json!({ "tools": after })).unwrap().len();
1077 let agent = token(Preset::Agent.scopes());
1078 let agent_bytes = serde_json::to_string(&json!({ "tools": listed(&Gate::Token(&agent)) })).unwrap().len();
1079 let read = token(Preset::ReadOnly.scopes());
1080 let read_bytes = serde_json::to_string(&json!({ "tools": listed(&Gate::Token(&read)) })).unwrap().len();
1081 println!(
1082 "tools/list: before {} tools, {before_bytes} bytes (~{} tokens); after {} tools, {after_bytes} bytes (~{} tokens); agent preset {agent_bytes} bytes (~{} tokens); read only {read_bytes} bytes (~{} tokens)",
1083 before.len(),
1084 before_bytes / 4,
1085 after.len(),
1086 after_bytes / 4,
1087 agent_bytes / 4,
1088 read_bytes / 4,
1089 );
1090 assert!(after_bytes * 2 < before_bytes, "{after_bytes} vs {before_bytes}");
1091 }
1092}