Tools
Built-in Tools
Pi's file and shell tools for agents with a sandbox, where they run, and how to limit them.
Built-in tools are Pi’s own coding tools, with the same names, parameters, and output as in Pi. They run in the agent’s sandbox instead of on your worker.
| Tool | What it does |
|---|---|
read, write, edit | Read, create, and change files. |
grep, find, ls | Search files and list directories. |
bash | Run a shell command. |
A sandbox is optional. Without one, the agent has no built-in tools and only uses the custom tools you pass. Pi’s tools run with the permissions of the process they run in, which is your worker, so they’re only turned on when a sandbox gives them somewhere else to run.
import { pi } from "@rivet-dev/pi";
import { e2bProvider } from "@rivet-dev/sandbox-adapter/e2b";
import { setup } from "rivetkit";
const reviewer = pi({
model: "anthropic/claude-opus-5-5",
sandbox: e2bProvider(),
excludeTools: ["bash", "edit", "write"],
});
export const registry = setup({ use: { reviewer } });
registry.start();
import { createClient } from "rivetkit/client";
import type { registry } from "./server";
const client = createClient<typeof registry>();
const reviewer = client.reviewer.getOrCreate(["pr-123"]);
const checkout = await reviewer.executeBash(
"git clone https://github.com/acme/app . && git fetch origin pull/123/head:pr-123 && git checkout pr-123",
{ excludeFromContext: true },
);
if (checkout.exitCode !== 0) throw new Error(checkout.output);
await reviewer.prompt("Review the changes on this branch.");
console.log(await reviewer.getLastAssistantText());
- The
excludeToolsoption turns tools off by name, so this reviewer can read and search files but can’t run commands or change them. Thetoolsoption does the opposite and enables only the tools you list. - The
executeBashaction runs a command in the agent’s sandbox from your backend, without the model. It works even though the reviewer can’t runbashitself. ItsexcludeFromContextoption keeps the output out of the conversation. - File tools only reach paths inside the sandbox’s working directory. The
bashtool accepts a timeout, and long output is truncated before it reaches the model.
To give an agent your own tools, see Custom Tools.