Skip to main content

Why this page matters

An agent’s capabilities are exactly the tools it can call. Instructions describe intent; tools determine what’s possible. Before writing an agent, check that the work you have in mind maps onto something here — otherwise the agent will try, fail, and narrate the failure. Use these names in an agent’s allowed-tools. Omitting allowed-tools inherits the default set rather than granting everything.
Availability differs slightly by surface. Tools that operate on a cloned target repository or on your organization’s connections are available to cloud agents; the CLI runs against your working directory instead.

Reading and searching code

Understanding code structure

code_lineage provides three structural operations backed by tree-sitter. Coverage is limited to languages with a grammar; on anything else, use ripgrep_search. This is how an agent traces taint: find the sink, walk callers back toward a source, and confirm nothing on the path neutralizes the input.

Scanning

Reading the outside world

web_fetch performs reads only — it takes a URL, headers, and an extraction mode, with no request method or body. There is no general-purpose tool for writing to a third-party API. Agents write to other systems only through integration tools for connected apps and through workflow outputs.

Your vendors’ data

These three are the entire vendor-data surface today, and they are scoped to vulnerability findings. See what agents can read for what that covers and what it doesn’t.

Integrations

When an organization admin connects a third-party app, its tools join this list for every agent in the organization. They’re named <App>_<Action>, and each app’s page lists them in full: None of these delete, remove, or archive anything. If an app isn’t connected, its tools are absent rather than failing. See using integration tools in an agent for how to grant them and add a Slack or Jira step to a workflow.

Projects

Recording results

Detections

Coordination

Managing agents

Managing skills

Both are CLI-only and work while signed in. They’re how the built-in skill-creator skill does its work; see organization skills.

Next steps

Write an agent

Put these names in allowed-tools.

Skills

Package a procedure an agent can load on demand.