Custom HTTP tools an administrator defines

A row in custom_tools becomes a ToolDef like any built-in, offered beside
the thirteen. The registry had to stop being an import-time constant for
that: `resolve_tools` now returns the schemas *and* the runners together,
carried to the loop on the ToolContext.

That closes a hole on the way. `run_tool` looked names up in the global
REGISTRY with no reference to what had been offered, so a model naming a
tool its chat was gated out of -- a family switched off, a permission the
reader lacks -- had it run anyway. The resolved set is now authoritative.

Arguments come from a model, so an argument may fill a hole but never move
the target: the scheme and host of a URL template are literal, values are
escaped for where they land, and the origin is pinned afterwards. Every
redirect hop is checked the way services/fetch.py checks one, and the
secret is dropped if a hop leaves the origin it was issued for.

Also fixes the tool-activity block claiming every library tool had
"searched the web", which it has done since the second family landed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Jaroslav Beneš
2026-08-01 16:26:47 +02:00
parent 4ee7d3db7d
commit d4cefb066a
26 changed files with 2771 additions and 60 deletions
+17
View File
@@ -371,6 +371,23 @@
line-height: var(--leading-relaxed);
}
/* What a tool returned, verbatim. Preformatted rather than rendered: this is
third-party text and markdown is the one path allowed to emit HTML. */
.tool-result__text {
margin: 0;
padding: var(--sp-3);
border-radius: var(--radius-sm);
background: var(--bg-sunken);
color: var(--ink-muted);
font-family: var(--font-mono);
font-size: var(--text-xs);
line-height: var(--leading-relaxed);
white-space: pre-wrap;
overflow-wrap: anywhere;
max-height: 22em;
overflow-y: auto;
}
/* --- Stop, notes and editing ---------------------------------------------- */
.msg__status { font-size: var(--text-xs); color: var(--ink-faint); font-style: italic; }
.msg__status:empty { display: none; }