No way to scope an externally-registered tool away from sub-agents
- 主要言語
- Java
- スター
- 10.5k
- フォーク
- 1.5k
- 平均マージ
- 1日 11時間
- マージ済み PR(30日)
- 128
説明
An SDK consumer registers external tools via `SessionConfig.tools` / `ResumeSessionConfig.tools`. Those tools reach the default agent **and** are inherited by sub-agent runs, including built-in ones (`task`, `explore`, …). There is no supported way to express "this tool is for the top-level agent only."
## The existing controls are asymmetric
- `DefaultAgentConfig.excluded_tools` hides a tool from the default agent *while keeping it available to sub-agents* — precisely the opposite of what's needed. (Its own doc comment says so: "hide tools from the default agent while keeping them available to custom sub-agents that list them in their `CustomAgentConfig::tools`".)
- `CustomAgentConfig.tools` is a per-custom-agent allowlist, so it only constrains agents the consumer defines. Built-in sub-agents can't be reached this way.
- `excluded_builtin_agents` removes the sub-agent outright — far too coarse, and it disables capability the consumer still wants.
## Why this is general
Many externally-registered tools are either:
1. **UI-bound** — they drive a picker, a canvas, an editor, or another foreground surface that only exists for the conversation the user is actually looking at. A background sub-agent has nothing to drive.
2. **Acting with the user's authority in a third-party system** — posting messages, filing tickets, sending mail, spending money. Autonomous invocation from a delegated worker is the wrong default.
Neither of those is specific to one embedder; both follow from the tool being executed outside the agent loop, on behalf of a user who is present in exactly one conversation.
## Ask
A way to declare this at registration. Two shapes seem plausible:
- A field on `Tool`, e.g. `availability`: `session` (default) | `primary-agent-only`.
- A `DefaultAgentConfig`-symmetric sub-agent config carrying `excluded_tools`.
The `Tool`-level field seems stronger: the constraint belongs to the tool rather than to one agent's configuration, so it keeps holding as new built-in agents are added, and a consumer registering a tool doesn't have to enumerate the agent set to protect it.
## Current workaround
Refusing the invocation after the fact — the host answers the tool call with a failure instead of executing it. That works, but it costs a model turn, hands the model an error it may retry against, and gives no way to express that the tool simply isn't available in that context. The tool stays in the sub-agent's tool list either way.
コントリビューションガイド
調査の方向性
まず、SessionConfig.tools と ResumeSessionConfig.tools を Tool、DefaultAgentConfig、CustomAgentConfig、および組み込みサブエージェントの設定までたどります。Tool レベルでの可用性とエージェントレベルでの除外について、提案されている設計を比較します。登録済みのツールをプライマリエージェントでは引き続き利用可能にしつつ、組み込みサブエージェントでは利用できない状態にでき、なおかつそれらのエージェントを削除しないことが完了条件です。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- java
- 領域
- api
- issue の種類
- 機能追加
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 活発さ
- 活発
- 明瞭さ
- おおむね明確
- 初心者へのやさしさ
- 35/100