Skip to content

Tools Reference ​

Cloud Harness MCP exposes 92 tools across six operational domains. Every tool executes strictly inside a sandboxed, TTL-limited Docker container with non-root privileges and default network isolation.

Security & Capability Badges ​

  • readOnly: Tool inspects state without mutating workspace filesystem or runtime.
  • destructive: Tool modifies files, processes, or git state.
  • idempotent: Calling the tool repeatedly with identical inputs yields equivalent state.
  • openWorld: Tool may interact with network or long-running execution boundaries.

Workspace Lifecycle ​

Tools for opening, inspecting, listing, secrets discovery, and closing isolated TTL-bound workspaces.

workspace_open ​

Open workspace

Clone an approved HTTPS repository and start an owner-bound, TTL-limited coding workspace.

Attributes: idempotent · openWorld

ParameterTypeRequiredConstraints & Notes
repositoryUrlstringYesformat: uri
refstringNolength: 1–255
idempotencyKeystringYespattern: ^[A-Za-z0-9._:-]+$, length: 8–128
fetchDepthintegerNoCommits of history to clone; 0 clones full history. Omitted keeps the default single-commit clone. (range: 0–100000)
shallowSincestring | stringNoClone history newer than this ISO date or datetime instead of a commit count.
networkProfile"network-none" | "dependency-access"No—
networkModeany · DeprecatedNoRetired and rejected: this field was replaced by networkProfile.
environmentIdstringNopattern: ^env_[A-Za-z0-9_-]{20,80}$
confirmEnvironmentInjectiontrueNo—
toolkitsany[]Nodefault: []
skillSetsobject[]Nodefault: []
skillOverridesobjectNodefault: {}
allowToolkitWorkspaceChangestrueNo—

workspace_list ​

List workspaces

List owner-visible workspace records with bounded cursor pagination.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
cursorstringNomax length: 256
limitintegerNorange: 1–500, default: 100

workspace_status ​

Workspace status

Read the lifecycle state and metadata for one workspace.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$

workspace_capabilities ​

Workspace capabilities

Inspect workspace and repository authorization capabilities (including issue and pull request operations mapped to github_action) without modifying state or minting tokens.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$

workspace_context ​

Workspace context

Read the active workspace ID, branch, lease time, Git identity, and repository overview.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
clientProfile"all" | "claude" | "codex" | "cursor" | "aider"Nodefault: "all"
includestring[]Nodefault: ["instructions","languages","test_commands","skills"]
contentMode"none" | "excerpt"Nodefault: "none"
cursorstringNomax length: 256
limitintegerNorange: 1–100, default: 50
maxBytesintegerNorange: 4096–131072, default: 32768

workspace_set_active ​

Set active workspace

Set the caller preferred active workspace when multiple workspaces exist.

Attributes: idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringYespattern: ^ws_[A-Za-z0-9_-]{20,80}$

workspace_lease_renew ​

Renew workspace lease

Explicitly renew the workspace idle lease duration or reactivate a recoverable expired workspace.

Attributes: idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
extensionSecondsintegerNorange: 60–86400

workspace_recover ​

Recover workspace state

Recover a recoverable expired workspace to active state, or inspect, patch, or export unpushed work.

Attributes: destructive

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
mode"resume" | "status" | "patch" | "export"Nodefault: "resume"
targetBranchstringNolength: 1–255

workspace_close ​

Close workspace

Stop a workspace executor and permanently remove all workspace files, including unpushed commits.

Attributes: destructive · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$

secrets_list ​

List available secrets

List available global and environment secret names and descriptions without revealing secret values. Reference credentials by name in commands.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
environmentIdstringNopattern: ^env_[A-Za-z0-9_-]{20,80}$
querystringNomax length: 200
cursorstringNomax length: 256
limitintegerNorange: 1–500, default: 100

Files and Code Intelligence ​

Tools for navigating directory trees, reading/writing files, structural search, and symbol analysis.

files_list ​

List files

List one workspace directory with bounded cursor pagination.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
pathstringNolength: 1–1024, default: "."
cursorstringNomax length: 256
limitintegerNorange: 1–500, default: 100

files_read ​

Read file

Read a bounded byte range from a workspace file with its size, SHA-256, and continuation cursor.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
pathstringYeslength: 1–1024
offsetintegerNorange: 0–9007199254740991, default: 0
limitintegerNorange: 1–1048576, default: 65536
cursorstringNomax length: 256
readAllbooleanNo—

files_write ​

Write file

Atomically create or replace a workspace file, optionally guarded by its current SHA-256.

Attributes: destructive · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
pathstringYeslength: 1–1024
contentstringYesmax length: 1048576
expectedSha256stringNolength: 64–64

files_write_batch ​

Write batch files

Atomically write multiple workspace files in one call, automatically creating missing parent directories.

Attributes: destructive · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
filesobject[]Yes—
createParentsbooleanNodefault: true
atomicbooleanNodefault: true
idempotencyKeystringNopattern: ^[A-Za-z0-9._:-]+$, length: 8–128

files_apply_patch ​

Apply text patch

Replace one unique exact text occurrence, optionally guarded by the file SHA-256.

Attributes: destructive · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
pathstringYeslength: 1–1024
oldTextstringYesmax length: 262144
newTextstringYesmax length: 262144
expectedSha256stringNolength: 64–64

files_delete ​

Delete file or directory

Delete one workspace file or directory, with explicit recursion and optional file hash guard.

Attributes: destructive

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
pathstringYeslength: 1–1024
recursivebooleanNodefault: false
expectedSha256stringNolength: 64–64

files_move ​

Move file or directory

Move or rename one workspace entry, optionally overwriting an existing file.

Attributes: destructive

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
sourcestringYeslength: 1–1024
destinationstringYeslength: 1–1024
overwritebooleanNodefault: false

files_mkdir ​

Create directory

Create one workspace directory, including missing parents by default.

Attributes: idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
pathstringYeslength: 1–1024
recursivebooleanNodefault: true

Search workspace

Search workspace text with a bounded regular expression and optional path, glob filter, and continuation cursor.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
patternstringYeslength: 1–4096
pathstringNolength: 1–1024, default: "."
globstringNomax length: 512
maxResultsintegerNorange: 1–500, default: 100

Find symbol definitions

Find bounded indexed symbol definitions by case-insensitive substring.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
querystringYeslength: 1–256
pathstringNolength: 1–1024, default: "."
languagestringNopattern: ^[A-Za-z0-9_+#.-]{1,40}$
maxResultsintegerNorange: 1–500, default: 100

symbols_references ​

Find lexical symbol references

Find bounded lexical whole-word occurrences of a symbol in workspace text.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
symbolstringYeslength: 1–256
pathstringNolength: 1–1024, default: "."
globstringNomax length: 512
maxResultsintegerNorange: 1–500, default: 100

Commands and Shells ​

Tools for running isolated non-root commands, operations, and persistent interactive PTY shell sessions.

exec_run ​

Run command

Run one bounded shell command in the workspace and return captured output.

Attributes: destructive · openWorld

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
commandstringYeslength: 1–32768
cwdstringNolength: 1–1024, default: "."
timeoutMsintegerNorange: 100–300000, default: 60000
maxOutputBytesintegerNorange: 1024–1048576, default: 262144
privilegedbooleanNodefault: false
approvalGrantTokenstringNolength: 1–128
asyncbooleanNodefault: false

shell_open ​

Open shell

Open an idempotent ephemeral interactive shell in the workspace.

Attributes: idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
cwdstringNolength: 1–1024, default: "."
idempotencyKeystringYespattern: ^[A-Za-z0-9._:-]+$, length: 8–128

shell_io ​

Use shell

Send input to or poll bounded output from an open interactive shell.

Attributes: destructive · openWorld

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
shellIdstringYespattern: ^sh_[A-Za-z0-9_-]{20,80}$
inputstringNomax length: 65536
cursorstringNomax length: 256
waitMsintegerNorange: 0–5000, default: 100

shell_close ​

Close shell

Terminate an interactive shell and release its in-memory state.

Attributes: destructive · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
shellIdstringYespattern: ^sh_[A-Za-z0-9_-]{20,80}$

operation_status ​

Read operation status

Query the execution state, progress, and terminal result of a long-running operation.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
operationIdstringYespattern: ^op_[A-Za-z0-9_-]{20,80}$
cursorstringNomax length: 256

operation_cancel ​

Cancel operation

Cancel an in-flight long-running operation.

Attributes: destructive · idempotent

ParameterTypeRequiredConstraints & Notes
operationIdstringYespattern: ^op_[A-Za-z0-9_-]{20,80}$

operation_wait ​

Wait for operation

Wait for a long-running operation to reach a terminal state with a timeout.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
operationIdstringYespattern: ^op_[A-Za-z0-9_-]{20,80}$
timeoutMsintegerNorange: 100–300000, default: 60000

Sessions and Tasks ​

Tools for long-running agent sessions and directed acyclic task graph workflows.

sessions_list ​

List coding sessions

List named coding sessions in a workspace with bounded cursor pagination.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
cursorstringNomax length: 256
limitintegerNorange: 1–500, default: 100

sessions_open ​

Open coding session

Open an idempotent named coding session in the workspace.

Attributes: idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
namestringYespattern: ^[A-Za-z0-9._-]{1,80}$
cwdstringNolength: 1–1024, default: "."
idempotencyKeystringYespattern: ^[A-Za-z0-9._:-]+$, length: 8–128

sessions_io ​

Use coding session

Send input to or poll bounded output from a named coding session.

Attributes: destructive · openWorld

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
sessionIdstringYespattern: ^sess_[A-Za-z0-9_-]{20,80}$
inputstringNomax length: 65536
cursorstringNomax length: 256
waitMsintegerNorange: 0–5000, default: 100

sessions_close ​

Close coding session

Terminate a coding session and release its in-memory state.

Attributes: destructive · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
sessionIdstringYespattern: ^sess_[A-Za-z0-9_-]{20,80}$

tasks_list ​

List tasks

List managed background task records with bounded cursor pagination.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
cursorstringNomax length: 256
limitintegerNorange: 1–500, default: 100

tasks_run ​

Run task

Start an idempotent managed command task with optional task dependencies.

Attributes: destructive · idempotent · openWorld

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
commandstringYeslength: 1–32768
cwdstringNolength: 1–1024, default: "."
idempotencyKeystringYespattern: ^[A-Za-z0-9._:-]+$, length: 8–128
timeoutMsintegerNorange: 100–86400000, default: 900000
dependsOnstring[]Nodefault: []

tasks_status ​

Task status

Read one managed task state and its next bounded output chunk.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
taskIdstringYespattern: ^task_[A-Za-z0-9_-]{20,80}$
cursorstringNomax length: 256

tasks_cancel ​

Cancel task

Terminate a managed task process group without rolling back completed effects.

Attributes: destructive · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
taskIdstringYespattern: ^task_[A-Za-z0-9_-]{20,80}$

tasks_graph ​

Read task dependency graph

Read the current managed-task dependency graph for a workspace.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$

Git and Worktrees ​

Local repository version control, branch management, worktree isolation, Git identity, and credential-isolated origin transfer.

git_status ​

Git status

Read branch, index, and working-tree status for the workspace repository.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$

git_diff ​

Git diff

Read a bounded staged or unstaged Git diff with cursor pagination and readAll convenience.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
stagedbooleanNodefault: false
pathstringNolength: 1–1024
cursorstringNomax length: 256
limitintegerNorange: 1–500000, default: 65536
readAllbooleanNo—

git_log ​

Git log

Read bounded recent commit metadata from the workspace repository with cursor pagination.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
limitintegerNorange: 1–500, default: 20
cursorstringNomax length: 256
readAllbooleanNo—

git_branch ​

Manage Git branches

List, create, or delete a local Git branch with constrained ref arguments.

Attributes: destructive

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
action"list" | "create" | "delete"Yes—
namestringNolength: 1–255
startPointstringNolength: 1–255
forcebooleanNodefault: false

git_checkout ​

Checkout Git ref

Check out an existing Git ref or create and check out a local branch.

Attributes: destructive

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
refstringYeslength: 1–255
createbooleanNodefault: false

git_add ​

Stage Git changes

Stage either explicit workspace paths or all tracked and untracked changes.

Attributes: idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
allbooleanNodefault: false
pathsstring[]Nodefault: []

git_commit ​

Create Git commit

Create an unsigned local Git commit with default or explicit author and message.

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
messagestringYeslength: 1–10000
authorNamestringNolength: 1–200
authorEmailstringNoformat: email, pattern: ^(?!\.)(?!.*\.\.)([A-Za-z0-9_'+\-\.]*)[A-Za-z0-9_+-]@([A-Za-z0-9][A-Za-z0-9\-]*\.)+[A-Za-z]{2,}$
allbooleanNodefault: false
expectedHeadOidstringNopattern: `^(?:[0-9a-f]
idempotencyKeystringNolength: 1–256

git_identity_status ​

Read Git author identity

Read the default or configured Git author name and email for the workspace.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$

git_identity_set ​

Set Git author identity

Configure default Git author name and email for workspace commits.

Attributes: destructive · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
namestringYeslength: 1–200
emailstringYesformat: email, pattern: ^(?!\.)(?!.*\.\.)([A-Za-z0-9_'+\-\.]*)[A-Za-z0-9_+-]@([A-Za-z0-9][A-Za-z0-9\-]*\.)+[A-Za-z]{2,}$

workspace_finalize ​

Finalize workspace commit and push

Transactionally stage changes, run preflights, commit with default or explicit identity, and push to remote in one call.

Attributes: destructive · idempotent · openWorld

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
pathsstring[]No—
allbooleanNodefault: true
commitMessagestringYeslength: 1–10000
branchstringNolength: 1–255
pushbooleanNodefault: true
authorNamestringNolength: 1–200
authorEmailstringNoformat: email, pattern: ^(?!\.)(?!.*\.\.)([A-Za-z0-9_'+\-\.]*)[A-Za-z0-9_+-]@([A-Za-z0-9][A-Za-z0-9\-]*\.)+[A-Za-z]{2,}$
preflightobjectNo—
idempotencyKeystringNopattern: ^[A-Za-z0-9._:-]+$, length: 8–128

git_fetch ​

Fetch Git refs

Fetch a constrained source ref from origin through the trusted repository broker.

Attributes: openWorld

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
remote"origin"Nodefault: "origin"
refspecstringNolength: 1–255
depthintegerNoDeepen history to this many commits from each fetched tip. (range: 1–100000)
unshallowbooleanNoFetch the complete history of a shallow workspace.
shallowSincestring | stringNoDeepen history back to this ISO date or datetime.

git_pull ​

Pull Git changes

Integrate an origin branch using ff-only, merge, or rebase strategy.

Attributes: destructive · openWorld

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
remote"origin"Nodefault: "origin"
branchstringNolength: 1–255
strategy"ff-only" | "merge" | "rebase"Nodefault: "ff-only"

git_push ​

Push Git changes

Push a constrained branch refspec to origin, with optional explicit force-with-lease.

Attributes: destructive · openWorld

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
remote"origin"Nodefault: "origin"
refspecstringNolength: 1–512
forceWithLeasebooleanNodefault: false
expectedRemoteOidstringNopattern: `^(?:[0-9a-f]
idempotencyKeystringNolength: 1–256

git_merge ​

Merge Git ref

Merge a Git ref with an explicit fast-forward policy and optional message.

Attributes: destructive

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
refstringYeslength: 1–255
fastForward"allow" | "only" | "never"Nodefault: "allow"
messagestringNolength: 1–10000

git_rebase ​

Manage Git rebase

Start, continue, or abort a local Git rebase with constrained ref arguments.

Attributes: destructive

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
action"start" | "continue" | "abort"Yes—
upstreamstringNolength: 1–255

worktrees_list ​

List worktrees

List managed Git worktrees and their current branch or HEAD state.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$

worktrees_create ​

Create worktree

Create a named managed worktree, optionally with a new local branch.

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
namestringYespattern: ^[A-Za-z0-9._-]{1,80}$
refstringYeslength: 1–255
createBranchbooleanNodefault: false

worktrees_remove ​

Remove worktree

Remove one named managed worktree, optionally discarding dirty state.

Attributes: destructive

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
namestringYespattern: ^[A-Za-z0-9._-]{1,80}$
forcebooleanNodefault: false

github_action ​

Create and manage GitHub issues, pull requests, and labels

Create GitHub issues (action: "issue_create"), list, view, comment on, update, and publish issues, manage labels, and list, view, create, update, and comment on pull requests in the repository bound to an owner-authorized workspace. Maps to advertised capabilities like operations.issueCreate, issueComment, and pullRequestCreate. Supported actions: issue_create, issue_list, issue_view, issue_comment, issue_comment_update, issue_update, issue_publish, label_create, issue_labels_add, issue_labels_remove, pr_list, pr_view, pr_create, pr_update, pr_comment, commit_list, compare, release_list, tag_list. Prefer github_read for read-only actions: this tool is annotated destructive, so clients may ask for approval on every call. Uses broker-managed GitHub App credentials via an ephemeral helper; GitHub tokens are never exposed to the workspace.

Attributes: destructive · openWorld

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
action"pr_list" | "pr_view" | "issue_list" | "issue_view" | "commit_list" | "compare" | "release_list" | "tag_list" | "pr_create" | "pr_update" | "pr_comment" | "issue_create" | "issue_comment" | "issue_comment_update" | "label_create" | "issue_labels_add" | "issue_labels_remove" | "issue_update" | "issue_publish"Yes—
limitintegerNorange: 1–250
state"open" | "closed" | "all"No—
prNumberintegerNorange: 0–9007199254740991
issueNumberintegerNorange: 0–9007199254740991
commentIdintegerNorange: 0–9007199254740991
titlestringNolength: 1–256
bodystringNomax length: 65536
headstringNolength: 1–256
basestringNolength: 1–256
draftbooleanNo—
labelsstring[]No—
assigneesstring[]No—
namestringNolength: 1–100
colorstringNopattern: ^[0-9A-Fa-f]{6}$
descriptionstringNomax length: 200
labelstringNolength: 1–100
createMissingbooleanNo—
createMissingLabelsbooleanNo—
stateReason"completed" | "not_planned" | "reopened"No—
commentstringNomax length: 65536
addLabelsstring[]No—
removeLabelsstring[]No—
shastringNolength: 1–255
pathstringNolength: 1–1024
sincestring | stringNo—
untilstring | stringNo—
idempotencyKeystringNopattern: ^[A-Za-z0-9._:-]+$, length: 8–128

Repository Extensions ​

Skills execution, workspace hooks, persistent memory, and repository-defined deployment operations.

skills_list ​

List skills

List repository-provided agent skills discovered in the workspace.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
limitintegerNorange: 1–100, default: 50
cursorstringNomax length: 256
includeShadowedbooleanNodefault: true

skills_read ​

Read skill

Read bounded instructions for one repository-provided agent skill.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
namestringYespattern: ^[A-Za-z0-9._:-]{1,120}$
source"built-in" | "owner" | "workspace" | "repository"No—
expectedSha256stringNolength: 64–64
offsetintegerNorange: 0–9007199254740991, default: 0
limitintegerNorange: 1–262144, default: 65536

skills_run ​

Run skill script

Execute one reviewed script packaged by a repository-provided skill.

Attributes: destructive · openWorld

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
namestringYespattern: ^[A-Za-z0-9._:-]{1,120}$
source"built-in" | "owner" | "workspace" | "repository"No—
scriptstringYespattern: ^[A-Za-z0-9._-]{1,120}$
argsstring[]Nodefault: []
timeoutMsintegerNorange: 100–300000, default: 60000
expectedSha256stringNolength: 64–64
expectedContentSha256stringNolength: 64–64
approvalGrantTokenstringNolength: 1–128

hooks_list ​

List hooks

List repository-defined Cloud Harness automation hooks without running them.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
event"on_workspace_open" | "post_checkout" | "pre_commit" | "post_commit" | "manual"No—
includeInactivebooleanNodefault: false
limitintegerNorange: 1–100, default: 50
cursorstringNomax length: 256

hooks_run ​

Run hook

Execute one named repository-defined hook as a bounded shell command.

Attributes: destructive · openWorld

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
namestringYespattern: ^[A-Za-z0-9._-]{1,120}$
event"on_workspace_open" | "post_checkout" | "pre_commit" | "post_commit" | "manual"No—
expectedSha256stringNolength: 64–64
expectedManifestSha256stringNolength: 64–64
timeoutMsintegerNorange: 100–300000, default: 60000

memories_list ​

List memories

List Cloud Harness memory note names across owner, repository, and workspace scopes.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
scope"owner" | "repository" | "workspace"No—
tagsstring[]No—
limitintegerNorange: 1–100, default: 50
cursorstringNomax length: 256

memories_read ​

Read memory

Read one bounded Cloud Harness memory note by name or ID.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
scope"owner" | "repository" | "workspace"No—
namestringNopattern: ^[A-Za-z0-9._-]{1,120}$
memoryIdstringNopattern: ^mem_[A-Za-z0-9_-]{10,80}$

memories_write ​

Write memory

Create or replace one scoped Cloud Harness memory note with optimistic concurrency.

Attributes: destructive · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
scope"owner" | "repository" | "workspace"Nodefault: "workspace"
namestringYespattern: ^[A-Za-z0-9._-]{1,120}$
contentstringYesmax length: 262144
tagsstring[]Nodefault: []
retentionSecondsintegerNorange: 60–31536000
expectedGenerationintegerNorange: 0–9007199254740991, default: 0
idempotencyKeystringNolength: 1–256

deployments_list ​

List deployment targets

List repository-defined deployment targets without running them.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$

deployments_run ​

Run deployment target

Execute one named repository-defined deployment target with external-effect risk.

Attributes: destructive · openWorld

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
namestringYespattern: ^[A-Za-z0-9._-]{1,120}$
timeoutMsintegerNorange: 100–300000, default: 60000

Retained Artifacts ​

Tools for snapshotting workspace files, listing, reading bounded ranges, restoring into workspaces, and deleting retained artifacts.

artifacts_snapshot ​

Preserve workspace file snapshot

Preserve one workspace file as a principal-owned, TTL-retained artifact snapshot.

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
pathstringYeslength: 1–1024
logicalNamestringYespattern: ^[A-Za-z0-9][A-Za-z0-9._-]{0,127}$
retentionSecondsintegerNorange: 60–2592000

artifacts_list ​

List retained artifacts

List principal-owned retained artifact snapshots with bounded pagination.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
cursorstringNomax length: 256
limitintegerNorange: 1–100, default: 50

artifacts_read ​

Read retained artifact chunk

Read a bounded base64 byte chunk from a principal-owned retained artifact with hash and EOF verification.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
artifactIdstringYespattern: ^art_[A-Za-z0-9_-]{20,80}$
offsetintegerNorange: 0–9007199254740991, default: 0
limitintegerNorange: 1–1048576, default: 65536

artifacts_restore ​

Restore artifact to workspace

Restore an unexpired principal-owned artifact into an active workspace file with overwrite protection.

Attributes: destructive

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
artifactIdstringYespattern: ^art_[A-Za-z0-9_-]{20,80}$
pathstringYeslength: 1–1024
overwritebooleanNodefault: false
expectedSha256stringNolength: 64–64

artifacts_delete ​

Delete retained artifact

Delete a principal-owned retained artifact snapshot before its retention expiry.

Attributes: destructive

ParameterTypeRequiredConstraints & Notes
artifactIdstringYespattern: ^art_[A-Za-z0-9_-]{20,80}$
expectedGenerationintegerNorange: 0–9007199254740991, default: 1

Additional Tools ​

skill_suggest ​

Suggest a skill

Suggest at most one skill from the workspace roster for a prompt. When an integration key is configured, the redacted prompt is sent to the configured TypeSafe endpoint; the answer is a skill name, never model prose.

Attributes: openWorld

ParameterTypeRequiredConstraints & Notes
promptstringYesmin length: 1
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$

hooks_activate ​

Activate lifecycle hooks

Explicitly activate reviewed lifecycle hooks for a workspace by exact manifest digest.

Attributes: destructive

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
manifestSha256stringYeslength: 64–64
eventsstring[]Yes—
retentionSecondsintegerNorange: 60–2592000

hooks_deactivate ​

Deactivate lifecycle hooks

Deactivate enrolled lifecycle hooks for a workspace.

Attributes: destructive

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
eventsstring[]No—

Search memories

Search scoped memory notes by literal text query and tag filters with bounded pagination.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
querystringYeslength: 1–512
scope"owner" | "repository" | "workspace"No—
tagsstring[]No—
tagMatch"all" | "any"Nodefault: "all"
limitintegerNorange: 1–50, default: 20
cursorstringNomax length: 256

memories_delete ​

Delete memory note

Delete one scoped memory note with generation guard.

Attributes: destructive

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
memoryIdstringNopattern: ^mem_[A-Za-z0-9_-]{10,80}$
namestringNopattern: ^[A-Za-z0-9._-]{1,120}$
scope"owner" | "repository" | "workspace"No—
expectedGenerationintegerNorange: 0–9007199254740991, default: 1

knowledge_create ​

Create knowledge note or journal

Create a new scoped memory or chronological journal entry in the control plane with CAS generation 0.

Attributes: destructive · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
kind"memory" | "journal"Nodefault: "memory"
scope"owner" | "project" | "workspace"Nodefault: "workspace"
projectIdstringNopattern: ^prj_[A-Za-z0-9_-]{20,80}$
titlestringYeslength: 1–120
contentstringYesmax length: 262144
journalType"engineering-log" | "decision-record" | "session-reflection"No—
occurredAtintegerNorange: 0–9007199254740991
tagsstring[]Nodefault: []
retentionSecondsintegerNorange: 60–31536000
expectedGenerationintegerNorange: 0–9007199254740991, default: 0
idempotencyKeystringNolength: 1–256

knowledge_read ​

Read knowledge item

Read one scoped knowledge item by stable ID with metadata, tags, and link relationships.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
idstringYespattern: ^kn_[A-Za-z0-9_-]{10,80}$

knowledge_update ​

Update knowledge item

Atomically update title, content, or metadata of one knowledge item with CAS expectedGeneration.

Attributes: destructive · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
idstringYespattern: ^kn_[A-Za-z0-9_-]{10,80}$
titlestringNolength: 1–120
contentstringNomax length: 262144
journalType"engineering-log" | "decision-record" | "session-reflection"No—
occurredAtintegerNorange: 0–9007199254740991
tagsstring[]No—
retentionSecondsintegerNorange: 60–31536000
expectedGenerationintegerYesrange: 0–9007199254740991

knowledge_delete ​

Delete knowledge item

Soft-delete one knowledge item by ID with generation guard.

Attributes: destructive · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
idstringYespattern: ^kn_[A-Za-z0-9_-]{10,80}$
expectedGenerationintegerYesrange: 0–9007199254740991

knowledge_list ​

List knowledge items

List knowledge items across scopes with project, journal-type, tag, and date filters.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
kind"memory" | "journal"No—
scope"owner" | "project" | "workspace"No—
projectIdstringNopattern: ^prj_[A-Za-z0-9_-]{20,80}$
journalType"engineering-log" | "decision-record" | "session-reflection"No—
tagsstring[]No—
tagMatch"all" | "any"Nodefault: "all"
limitintegerNorange: 1–100, default: 50
cursorstringNomax length: 256

Hybrid search knowledge items

Perform hybrid search combining FTS5 lexical matching and semantic vector similarity with 0–100 relevance scoring.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
querystringYeslength: 1–512
kindsstring[]No—
scope"owner" | "project" | "workspace"No—
projectIdstringNopattern: ^prj_[A-Za-z0-9_-]{20,80}$
journalType"engineering-log" | "decision-record" | "session-reflection"No—
tagsstring[]No—
tagMatch"all" | "any"Nodefault: "all"
limitintegerNorange: 1–50, default: 20
cursorstringNomax length: 256

Link knowledge items

Create a typed relationship link between two knowledge items.

Attributes: destructive · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
sourceIdstringYespattern: ^kn_[A-Za-z0-9_-]{10,80}$
targetIdstringYespattern: ^kn_[A-Za-z0-9_-]{10,80}$
relation"relates-to" | "references" | "supports" | "contradicts" | "supersedes"Nodefault: "relates-to"
expectedGenerationintegerNorange: 0–9007199254740991, default: 0

Unlink knowledge items

Remove a relationship link between two knowledge items.

Attributes: destructive · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
linkIdstringNopattern: ^knl_[A-Za-z0-9_-]{10,80}$
sourceIdstringNopattern: ^kn_[A-Za-z0-9_-]{10,80}$
targetIdstringNopattern: ^kn_[A-Za-z0-9_-]{10,80}$
relation"relates-to" | "references" | "supports" | "contradicts" | "supersedes"No—
expectedGenerationintegerNorange: 0–9007199254740991

knowledge_graph ​

Query knowledge neighborhood graph

Traverse and query the bounded neighborhood knowledge graph for a root node.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
rootIdstringNopattern: ^kn_[A-Za-z0-9_-]{10,80}$
depthintegerNorange: 1–3, default: 1
maxNodesintegerNorange: 1–200, default: 50
kindsstring[]No—
projectIdstringNopattern: ^prj_[A-Za-z0-9_-]{20,80}$

github_read ​

Read GitHub pull requests, issues, commits, comparisons, releases, and tags

Read-only GitHub access for the repository bound to an owner-authorized workspace, without per-call approval prompts. Supported actions: pr_list, pr_view, issue_list, issue_view, commit_list (history with sha, path, since, until filters), compare (base...head commits and changed files), release_list, tag_list. Maps to operations.pullRequestList, pullRequestView, issueList, issueView, commitList, compare, releaseList, and tagList. Uses broker-managed GitHub App credentials via an ephemeral helper; GitHub tokens are never exposed to the workspace.

Attributes: readOnly · idempotent · openWorld

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
action"pr_list" | "pr_view" | "issue_list" | "issue_view" | "commit_list" | "compare" | "release_list" | "tag_list"Yes—
limitintegerNorange: 1–250
state"open" | "closed" | "all"No—
prNumberintegerNorange: 0–9007199254740991
issueNumberintegerNorange: 0–9007199254740991
shastringNolength: 1–255
pathstringNolength: 1–1024
sincestring | stringNo—
untilstring | stringNo—
basestringNolength: 1–255
headstringNolength: 1–255

agent_spawn ​

Spawn coding agent

Spawn an owner-bound, budgeted Pi coding-agent subagent in an isolated container.

Attributes: destructive · idempotent · openWorld

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
promptstringYesmin length: 1
idempotencyKeystringYespattern: ^[A-Za-z0-9._:-]+$, length: 8–128
profileIdstringYespattern: ^[A-Za-z0-9._-]{1,80}$
parentAgentIdstringNopattern: ^agent_[A-Za-z0-9_-]{20,80}$
proxyOperationsstring[]Yes—
ttlSecondsintegerNorange: 30–86400, default: 900
maxOutputBytesintegerNorange: 1024–10485760, default: 262144
maxInputTokensintegerNorange: 1–2000000, default: 200000
maxOutputTokensintegerNorange: 1–2000000, default: 32000
maxCostMicrosintegerNorange: 0–1000000000, default: 10000000

agent_status ​

Read coding agent status

Read the execution state, budgets, and terminal summary of one coding agent.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
agentIdstringNopattern: ^agent_[A-Za-z0-9_-]{20,80}$
idempotencyKeystringNopattern: ^[A-Za-z0-9._:-]+$, length: 8–128

agent_logs ​

Read coding agent logs

Read bounded streaming diagnostic and tool events from one coding agent.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
agentIdstringYespattern: ^agent_[A-Za-z0-9_-]{20,80}$
cursorstringNopattern: `^(?:0
limitBytesintegerNorange: 1024–262144, default: 65536

agent_message ​

Message coding agent

Send an idempotent steering or follow-up message to a running coding agent.

Attributes: destructive · idempotent · openWorld

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
agentIdstringYespattern: ^agent_[A-Za-z0-9_-]{20,80}$
idempotencyKeystringYespattern: ^[A-Za-z0-9._:-]+$, length: 8–128
mode"steer" | "followUp"Yes—
messagestringYesmin length: 1

agent_cancel ​

Cancel coding agent

Cancel an in-flight coding agent and cascade cancellation to all its child agents.

Attributes: destructive · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
agentIdstringYespattern: ^agent_[A-Za-z0-9_-]{20,80}$
reasonstringNomax length: 2000

agent_list ​

List coding agents

List coding agents in a workspace with bounded pagination.

Attributes: readOnly · idempotent

ParameterTypeRequiredConstraints & Notes
workspaceIdstringNopattern: ^ws_[A-Za-z0-9_-]{20,80}$
parentAgentIdstringNopattern: ^agent_[A-Za-z0-9_-]{20,80}$
status"SPAWNING" | "RUNNING" | "CANCELLING" | "SUCCEEDED" | "FAILED" | "CANCELLED" | "TIMED_OUT" | "LIMIT_EXCEEDED" | "INTERRUPTED"No—
cursorstringNopattern: ^[1-9]\d*$
limitintegerNorange: 1–100, default: 50

Released under the MIT License. Single-owner private remote coding harness.