features: /changes, /search, /fork, web_search, prompt memoization, per-turn spend cap, workspace refresh
- /changes diffs the last turn's file snapshot (added/modified/deleted), reusing undo infra via SnapshotStack.peek() - system prompt memoized behind version counters (notebook/memory/skills/plugins/tools/workspace); hit-rate in /cost, foundation for provider caching - web_search: DuckDuckGo Lite, keyless, 5 results, SSRF-filtered, in the net set with ask permission - /search <query>: full-text grep over saved sessions incl. tool-input JSON - workspace file list re-walks at a turn boundary after writes - maxSpendPerTurn: per-turn cap stops a runaway step with a notice - /fork: branch the session at the last turn boundary, original untouched 821 tests pass, typecheck clean, build green
This commit is contained in:
+2
-1
@@ -37,6 +37,7 @@ remain are the ones worth reading.
|
||||
| `move_file` | both ends; one match is enough |
|
||||
| `apply_patch` | every file marker path in the patch |
|
||||
| `web_fetch` | the URL |
|
||||
| `web_search` | the query |
|
||||
| `read_many_files` | every path in the batch; one match is enough |
|
||||
| `glob` `grep` | the pattern |
|
||||
| `git_diff` `git_log` `git_blame` | the path, when given |
|
||||
@@ -99,7 +100,7 @@ With no `permission` config:
|
||||
| `glob` `grep` `list_dir` | `allow` |
|
||||
| the git tools | `allow` — they cannot mutate anything |
|
||||
| `task`, and every session tool | `allow` — they touch the agent's own state |
|
||||
| `write_file` `edit_file` `multi_edit` `apply_patch` `move_file` `delete_file` `bash` `web_fetch` | `ask` |
|
||||
| `write_file` `edit_file` `multi_edit` `apply_patch` `move_file` `delete_file` `bash` `web_fetch` `web_search` | `ask` |
|
||||
| anything else, including every `mcp__*` tool | `ask` |
|
||||
|
||||
Credentials are denied on read rather than gated, because there is no recovery. A model that
|
||||
|
||||
Reference in New Issue
Block a user