Register the permission capability of a tool that a host application
attaches to the chat (via chat$register_tool()), so codeagent's central
permission gate governs it like a native tool.
codeagent classifies every tool call by capability. Built-in tools are known;
any unregistered tool defaults to "exec" and is therefore gated as a
sensitive operation. If a host tool is read-only and benign, declare it as
"read" so the gate will allow it without prompting under default mode.
Built-in tool metadata stays authoritative – this only classifies tools not already known to codeagent. Registrations persist for the R session.
Usage
register_tool_meta(
name,
capability = c("read", "write", "exec", "net"),
set = "C"
)Arguments
- name
Character(1). Tool name (must match the
ellmer::tool()name).- capability
One of
"read","write","exec","net". Use"read"for read-only/benign tools (allowed without prompting);"write"/"exec"/"net"route through the permission gate.- set
Character(1). Tool-set label used by the central gate (default
"C"= host/custom). The set must be enabled insettings$tools$sets.