AgentsTools

Built-in tools

Switch on files and a shell, a to-do list, or memory for your agent, and check what it did.

Give your agent ready-made abilities without writing any tool code. Blazing Agents groups its tools into three sets you switch on per agent. A new agent starts with none, so it can only do what you turn on.

Tool groups

GroupToolsWhat the agent can do
workspaceread, write, edit, grep, glob, bash, publish_artifactsWork with files and run commands in its workspace, and publish finished files as artifacts.
write_todoswrite_todosKeep a to-do list to plan the current turn.
memorysave_memory, get_memory, search_memories, update_memory, delete_memorySave and recall notes in the agent's memory.

MCP tools are added through connections, not through these groups.

Enable a group

The tools list you send replaces the agent's whole selection, so read the current list and add to it:

const agent = await client.agents.get({ agentId });
if (!agent.tools.includes("workspace")) {
  await client.agents.update({
    agentId,
    tools: [...agent.tools, "workspace"],
  });
}

Like any agent update, this creates a new version.

Workspace tools

ToolWhat it does
readRead a file.
writeWrite a text file, creating folders as needed.
editReplace exact text in an existing file.
grepSearch file contents.
globList paths that match a pattern such as src/**/*.ts.
bashRun a shell command and return its exit code and output.
publish_artifactsPublish one to ten files as artifacts.

The agent works under /workspace. Relative paths resolve there, bash starts there, and paths that would leave it are rejected. Commands get no provider keys or application environment variables, and they can reach only the hosts the workspace's network policy allows.

Writing a file does not deliver it anywhere. The agent must call publish_artifacts to hand a file to your application, and it can do that only in a chat session or task run, not in stateless generation.

Tools that come with skills

An agent with skills also gets activate_skill and a read that can open its skill files, even without the workspace group. That read does not open workspace files. To run a script from a skill, the agent needs the workspace group: it reads the script, writes a copy into the workspace, and runs the copy with bash.

Verify durable file operations

Check that files survive between sessions: write a value in one session, then read it back in a new one. Check the saved tool result rather than the agent's reply, because the model can paraphrase.

First, ask the agent to write the file:

const sentinel = "BA_DURABLE_42";
const writeTurn = await client.chat({
  agentId,
  message: {
    id: crypto.randomUUID(),
    role: "user",
    parts: [
      {
        type: "text",
        text: `Use write to create durable.txt containing exactly ${sentinel}.`,
      },
    ],
  },
});
await writeTurn.toResponse().text();

Then read it from a new session and check the read result:

const readTurn = await client.chat({
  agentId,
  message: {
    id: crypto.randomUUID(),
    role: "user",
    parts: [{ type: "text", text: "Use read to read durable.txt." }],
  },
});
const sessionId = await readTurn.sessionId;
await readTurn.toResponse().text();

const { data } = await client.sessions.messages({ agentId, sessionId });
const output = data
  .flatMap((message) => message.parts)
  .find((part) => part.type === "tool-read" && part.state === "output-available")?.output;
if (
  typeof output !== "object" ||
  output === null ||
  !("content" in output) ||
  output.content !== sentinel
) {
  throw new Error("Persistence check failed");
}

Always read the whole stream, as these examples do. The turn finishes its tool work and saves the session only when the stream ends.

Failures and shared files

File changes are not undone when a turn fails or is stopped. Writes and edits that finished stay in the workspace, even though a failed turn saves nothing to the session. Turns that share a workspace can also change the same files at once, so coordinate writes when that matters.

Production checklist

  • Turn on only the groups the agent needs. Selecting a group gives the agent that ability; it does not check who the user is.
  • Keep secrets out of prompts, commands, files, and tool arguments.
  • Treat files, commands, and summaries the agent produces as untrusted until your application checks them.
  • Put a person in front of risky calls such as bash with tool approvals.
  • Expect limits on input and output size, file operations, and compute. See limits and reliability.

Next

On this page