Перейти к основному содержимому

AI tool manifest & harness split (tool defs, risk metadata, registry)

Generated from mcp/patterns.registry.json — do not edit by hand; change the registry and run bun run patterns:build.

Category: AI · Tier: deep · Risk: high — governs what an LLM is allowed to execute

Tool definitions are thin wrappers whose risk-tier metadata and per-surface membership live in a registry, with harness concerns (agent loop, compaction, policy) factored out separately.

When to use: Use as soon as an LLM gets tools: the manifest/harness split is what keeps tool permissions auditable and surfaces honest.

Docs

Code

  • src/lib/server/ai/tools/index.ts — The manifest: chatbotToolMeta/deskbotToolMeta/allToolMeta maps + stepsForScopes (GitHub · GitLab)
  • src/lib/server/ai/tools/_types.ts — Risk vocabulary: ToolRisk = read|create|write|destructive; ToolMeta (GitHub · GitLab)
  • src/lib/server/ai/policy/governor.ts — requiresApproval(risk) + shouldRequirePlan (GitHub · GitLab)
  • src/lib/server/ai/tool-leak-guard.ts — Guard against tool/surface leakage (GitHub · GitLab)
  • src/lib/server/ai/loop/compact.ts — Loop compaction (harness side) (GitHub · GitLab)

Tests

  • src/lib/server/ai/tools/index.test.ts — Drift-guards the replay map against the live tool set (GitHub · GitLab)
  • src/lib/server/ai/policy/governor.test.ts (GitHub · GitLab)
  • src/lib/server/ai/tool-leak-guard.test.ts (GitHub · GitLab)
  • src/lib/server/ai/loop/compact.test.ts (GitHub · GitLab)

Invariants

  • Risk-tiered approval gates, not per-tool needsApproval flags — approval fatigue is reproducible; the tier rule is the working pattern.
  • executeDeskToolCall is the single door for mutating tool execution (one SSOT).
  • stepsForScopes caps agent steps per scope (read-only including desk
    = 3, mutation = 5).

Emulation notes

  • The manifest is not a single file: meta maps in tools/index.ts + risk vocab in tools/_types.ts + the approval rule in policy/governor.ts together form it.
  • Write the drift-guard test early — it is what keeps the manifest honest as tools accumulate.

Depends on


Machine-readable record: ai-tool-harness in mcp/patterns.registry.json.

← Back to Pattern Library

Думаете, этот паттерн можно сделать лучше? Расскажите как.

Оставить отзыв