> ## Documentation Index
> Fetch the complete documentation index at: https://docs.vibely.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# Tools

> The tool registry — what the agent can do inside the sandbox

Tools are the agent's hands. Every tool is registered through `createAllTools()` in `src/tools/registry.ts`, which wraps each one with large-result truncation, sandbox-404 auto-recovery, and a per-turn dedup cache.

<Frame>
  <img src="https://cdn.vibely.sh/doc/v1/engine-tools.webp" alt="Tools" width="1200" height="675" />
</Frame>

## Always-on tools (16)

These are registered for every build session, regardless of env or context.

| Tool | Purpose |
| - | - |
| `bash` | Run shell commands — also how the agent lists a directory (`bash ls`). `npm run dev` is short-circuited (load-bearing). Default timeout 60 s, overridable per call. |
| `write` | Create or overwrite a file in the sandbox. |
| `read` | Read a file from the sandbox. Images come back as pixels, not base64. |
| `edit` | Find-and-replace inside an existing file. |
| `glob` | Pattern-match file paths. |
| `grep` | Content search across the project. |
| `add_dependency` | Install a package into the running project. |
| `ask_user` | Pause and wait for the user to answer via `/vibe/answer`. |
| `todo_write` | Manage the in-session todo list. |
| `use_skill` | Load a skill's instructions on demand. |
| `db_schema` | Read the linked database's live schema. |
| `parse_document` | Extract text from a document the user attached. |
| `supabase_setup` | Link a Supabase project, run a migration, restart it. |
| `spawn_subagent` | Hand a read-only research question to a subagent (read-only tools only). |
| `enter_plan_mode` | Drop into read-only plan mode. |
| `exit_plan_mode` | Leave plan mode and start writing code. |

## Conditional tools

Registered only when their dependency is configured or their context is present.

| Tool | Required env / context |
| - | - |
| `web_search` | `TAVILY_API_KEY` |
| `web_scrape` | `FIRECRAWL_API_KEY` |
| `image_gen` | `FAL_KEY` |
| `mcp_list` / `mcp_call` | MCP enabled, or a `userId` on the request |
| `read_runtime_errors` | `projectId` — read what the running preview is throwing |
| `download_to_repo` | `projectId` — pull a remote asset into the project |
| `clone_site` | `projectId` — capture a reference site's layout and assets |
| `secrets` | `projectId` — collect a secret from the user |
| `enable_stripe` | `projectId` — collect a Stripe secret key |
| `connect_supabase` | `projectId` — prompt the user to link Supabase |
| `reference_project` | `projectId` + `userId` — read another project of theirs |
| `run_security_scan` | `userId` + `projectId` |
| `connector_call` | `userId` + connectors allowed — call a connected service through the gateway |
| `connector_scaffold` | `projectId` + connectors allowed — write the integration into the project |

See [Connectors](/integrations/connectors/overview) for the connector catalog.

## Plan mode

Plan mode is read-only. `filterToolsForPlanMode()` keeps an explicit allowlist —
`read`, `list_files`, `glob`, `grep`, `web_search`, `web_scrape`, `db_schema`,
`read_runtime_errors`, `mcp_list`, `mcp_call`, `spawn_subagent`, `use_skill`,
`ask_user`, and `exit_plan_mode` — and drops everything that writes or executes.
The agent leaves plan mode by calling `exit_plan_mode`, after which the full
toolset is restored. (`exit_plan_mode` is the one tool a *build* turn never
gets: `BUILD_EXCLUDED_TOOLS` strips it.)

## Timeouts

There is no per-tool timeout in the wrapper. Each tool enforces its own limit —
`bash` defaults to 60 s and takes a `timeout` argument — and every tool receives
the session's `abortSignal`, so `POST /vibe/abort/:projectId` cancels whatever is
in flight.

## Sandbox-404 auto-recovery

If a tool call fails because the sandbox container is gone (`404` or `"No such container"`), the wrapper:

1. Logs `sandbox_recovery_attempted` (alertable).
2. Sleeps 1.5 s for the sandbox control plane to settle.
3. Calls `WorkspaceManager.getOrCreate()` to get a fresh sandbox.
4. Retries the tool call **once**.

After 3 recoveries on the same project the wrapper bails with a hard error, so a flapping sandbox can't burn the whole session in a retry loop.

Don't bypass the wrapper. The recovery path is the only thing keeping a transient sandbox blip from terminating an otherwise-successful build.

## Result truncation

Tool results larger than the configured cap are truncated and a marker is appended (`… [truncated, N more bytes]`). The agent is told the result was truncated so it can re-fetch a smaller slice if needed. Without truncation a single `read` of a 100 KB lockfile can blow the model's context budget for the rest of the session.

## Dedup

Inside a single turn, identical tool calls (same name + same args, by stable hash) are deduped — the second call returns the first call's result without re-executing. This catches a failure mode where a model double-emits the same `read` against the same path.


## Related topics

- [MCP Tools](/reference/mcp/tools.md)
- [Connect tools, services, and APIs](/integrations/connectors/overview.md)
- [Add a third-party analytics tool](/integrations/connectors/analytics.md)
- [Publish your app as an MCP server](/features/grow/agent-integrations.md)
- [Vibely MCP server](/integrations/vibely-mcp-server.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.