When an agent context is present, only dispatch tools in the agent's tool list. The global fallback was bypassing per-agent tool restrictions — a subconscious agent could call bash, edit, or any tool even if its .agent file only allowed memory tools. Co-Authored-By: Proof of Concept <poc@bcachefs.org> |
||
|---|---|---|
| .. | ||
| api | ||
| tools | ||
| context.rs | ||
| mod.rs | ||
| oneshot.rs | ||
| tokenizer.rs | ||