You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 7dc259d
Browse filesBrowse the repository at this point in the historyBrowse files
|`KYROZEN_APPROVAL_MODE`| CLI confirmation mode for high-impact Git actions (`dangerous`/`never`) |`dangerous`|
592
+
|`KYROZEN_APPROVAL_MODE`| CLI confirmation mode for high-impact Git actions and dynamic-tool registration (`dangerous`/`never`) |`dangerous`|
593
593
|`KYROZEN_WEB_CAPABILITIES`| Web chat capabilities: `readonly`, `workspace`, or `full`|`workspace`|
594
594
|`KYROZEN_MCP_CAPABILITIES`| MCP capabilities: `readonly`, `workspace`, or `full`|`workspace`|
595
595
596
-
The local CLI is intentionally a high-permission agent, similar to Codex or OpenClaw: it can read and write the active workspace, run shell commands, use the network, and operate Git. The Web and MCP surfaces expose the same rich `workspace` profile by default, but keep irreversible `git_reset` and LLM-generated Python tools behind the explicit `full`/`KYROZEN_ALLOW_DYNAMIC_TOOLS=1` opt-in. Authentication and the command safety filter still apply.
596
+
The local CLI is intentionally a high-permission agent, similar to Codex or OpenClaw: it can read and write the active workspace, run shell commands, use the network, and operate Git. The Web and MCP surfaces expose the same rich `workspace` profile by default, but keep irreversible `git_reset` and LLM-generated Python tools behind the explicit `full`/`KYROZEN_ALLOW_DYNAMIC_TOOLS=1` opt-in. On the interactive CLI, dynamic registration also follows `KYROZEN_APPROVAL_MODE`; use `never` only for an explicitly automated deployment. Authentication and the command safety filter still apply.
"You are currently inside the project root directory of the repository the user is working in. Relative paths (like \"README.md\" or \"main.py\") will be resolved correctly. You can use `read_file`, `write_file`, `list_dir`, `find_files`, `run_cmd`, etc. **without needing the user to provide a path**. Do **not** ask the user to supply a local path or a remote URL unless you intend to use the `analyze_remote_repo` tool to clone an external repository."
1754
1770
)
1771
+
dynamic_tool_instructions= (
1772
+
"## Dynamic tools\n"
1773
+
"Dynamic tools are enabled only when the active surface grants the `dynamic` capability and the approval policy allows registration. "
1774
+
"When a missing pure helper is genuinely needed, you may output exactly one DefineTool block; never include imports, filesystem/process/network access, secrets, permission changes, or capability grants. "
1775
+
"The runtime validates and registers it, refreshes the tool inventory, and then you may call it by its exact name:\n"
0 commit comments