Skip to main content
Tools

Built-in Tools

Pi's file and shell tools for agents with a sandbox, where they run, and how to limit them.

Built-in tools are Pi’s own coding tools, with the same names, parameters, and output as in Pi. They run in the agent’s sandbox instead of on your worker.

ToolWhat it does
read, write, editRead, create, and change files.
grep, find, lsSearch files and list directories.
bashRun a shell command.

A sandbox is optional. Without one, the agent has no built-in tools and only uses the custom tools you pass. Pi’s tools run with the permissions of the process they run in, which is your worker, so they’re only turned on when a sandbox gives them somewhere else to run.

client.tsReviewer agentSandboxexecuteBashread, grep, find, lsbash, edit, write excluded
  • The excludeTools option turns tools off by name, so this reviewer can read and search files but can’t run commands or change them. The tools option does the opposite and enables only the tools you list.
  • The executeBash action runs a command in the agent’s sandbox from your backend, without the model. It works even though the reviewer can’t run bash itself. Its excludeFromContext option keeps the output out of the conversation.
  • File tools only reach paths inside the sandbox’s working directory. The bash tool accepts a timeout, and long output is truncated before it reaches the model.

To give an agent your own tools, see Custom Tools.