add-tool
Four places change. Do all four or the tool is half-registered.
src/tools/<name>.ts— the tool module.zodschemas for input and output.- Declare
sideEffect(none|read|write|network|exec) andrisk(low|medium|high|critical). Be honest — these drive permission prompts and auto-approval. - All filesystem access via
src/sandbox/fs.tshelpers. - All shell commands via
src/sandbox/shell.ts+classifyCommandRisk. - Request permission via
requestPermission(src/permissions/manager.ts) before the side effect. - Return
{ ok, data }/{ ok: false, error }. Throw only for programmer errors, usingForgeRuntimeError.
Registration — wire into the registry following the pattern in an existing tool like
src/tools/read-file.ts.test/unit/<name>.test.ts— at minimum:- happy path,
- zod rejection on invalid input,
- permission denied → structured error (not throw),
- path-escape refused by sandbox,
- (if shell) critical command hard-blocked.
Use
vi.mockfor the permission manager and sandbox boundaries.Docs — if user-visible, update the tools table in
docs/ARCHITECTURE.mdand the README "At a glance" count.
Finish with the verify skill.