Skip to main content
Tools are the agent’s hands. Every tool is registered through createAllTools() in src/tools/registry.ts, which wraps each one with large-result truncation, sandbox-404 auto-recovery, and a per-turn dedup cache.
Tools

Always-on tools (16)

These are registered for every build session, regardless of env or context.

Conditional tools

Registered only when their dependency is configured or their context is present. See Connectors for the connector catalog.

Plan mode

Plan mode is read-only. filterToolsForPlanMode() keeps an explicit allowlist — read, list_files, glob, grep, web_search, web_scrape, db_schema, read_runtime_errors, mcp_list, mcp_call, spawn_subagent, use_skill, ask_user, and exit_plan_mode — and drops everything that writes or executes. The agent leaves plan mode by calling exit_plan_mode, after which the full toolset is restored. (exit_plan_mode is the one tool a build turn never gets: BUILD_EXCLUDED_TOOLS strips it.)

Timeouts

There is no per-tool timeout in the wrapper. Each tool enforces its own limit — bash defaults to 60 s and takes a timeout argument — and every tool receives the session’s abortSignal, so POST /vibe/abort/:projectId cancels whatever is in flight.

Sandbox-404 auto-recovery

If a tool call fails because the sandbox container is gone (404 or "No such container"), the wrapper:
  1. Logs sandbox_recovery_attempted (alertable).
  2. Sleeps 1.5 s for the sandbox control plane to settle.
  3. Calls WorkspaceManager.getOrCreate() to get a fresh sandbox.
  4. Retries the tool call once.
After 3 recoveries on the same project the wrapper bails with a hard error, so a flapping sandbox can’t burn the whole session in a retry loop. Don’t bypass the wrapper. The recovery path is the only thing keeping a transient sandbox blip from terminating an otherwise-successful build.

Result truncation

Tool results larger than the configured cap are truncated and a marker is appended (… [truncated, N more bytes]). The agent is told the result was truncated so it can re-fetch a smaller slice if needed. Without truncation a single read of a 100 KB lockfile can blow the model’s context budget for the rest of the session.

Dedup

Inside a single turn, identical tool calls (same name + same args, by stable hash) are deduped — the second call returns the first call’s result without re-executing. This catches a failure mode where a model double-emits the same read against the same path.