Docs · Use

Tools

Nineteen tools, all sandboxed to the project root. Path traversal is rejected, bash has a timeout and output cap, and tool results are truncated hard (20k chars, 30k in SWE mode) before they hit context. Consecutive read-only calls run concurrently; writes run serially.

Read-only: every mode

  • readFile

    Read a file. Path must stay inside the project root.

  • listDirectory / glob

    List dirs and match paths without leaving the sandbox.

  • grep

    Ripgrep-style search with output caps before it hits context.

  • codeMap

    Repo symbol overview (functions/classes/exports per file) for bug localization without reading everything.

  • searchWeb

    Read-only lookup the agent can call in any mode.

  • diffFile

    Preview a unified diff of proposed changes without applying them.

  • todoRead

    Read the current task list. Available in every mode.

  • skill

    Load a skill workflow by name. Available in every mode.

Build: BUILD, FIX (no shell), SWE

  • writeFile

    Create or overwrite a file. Creates a checkpoint for /undo.

  • editFile / batchEdit

    Exact-match replacements. Batch applies atomically across files.

  • applyPatch

    Apply a unified diff (--- / +++ / @@ hunks) with strict context matching.

  • bash

    Runs with a timeout and output cap. Shell passthrough via ! in TUI.

  • runTests

    Test twin of bash: returns structured pass/fail lists (jest, pytest, mocha, TAP) instead of raw stdout.

  • undoLastChange / redoLastUndo

    Step through write checkpoints across turns.

  • todoWrite

    Overwrite the full task list, send ALL todos every call so the plan can't drift.

  • spawnAgent

    Delegate a bounded subtask to a fresh subagent. Returns its summary, not a transcript. Depth limit 1.

Checkpoints

Every write creates a checkpoint, /undo and /redo work across turns.

Guards

Dangerous commands (rm -rf /, fork bombs, shutdown) and secret files (.env, *.pem) are refused before they execute, in every mode.

Blast-radius gate

The first write to a migration, CI workflow, lockfile, schema, auth, billing or infra path is refused once per turn, and opens only with a justifying file:line and an exact rollback. Why it is designed this way →