OptionaladditionalTools?: (BaseTool | BaseToolset)[]OptionalallowInlineScripts?: booleanWhether to expose the run_skill_inline_script tool, which executes
model-provided script content in the configured code executor. This is
disabled by default because arbitrary inline-script execution is a
sensitive capability; opt in explicitly by setting this to true.
Execution additionally remains gated behind a human-in-the-loop
confirmation.
OptionalcodeExecutor?: BaseCodeExecutorOptionalregistry?: SkillRegistryOptionalscriptOutputDir?: stringDirectory that files produced by run_skill_script /
run_skill_inline_script are written into. Output file names come from
the executed script, so this must be a directory dedicated to
throwaway script output — never the application's working directory or
a source tree.
Defaults to a private, randomly named directory created under the OS
temp dir on first use. Nothing removes that directory: close() runs
once per invocation on a toolset instance that concurrent invocations
share (see Runner), so it cannot tell whose output is still in use.
Set this to own the location and the lifetime of the output.
Readonly[OptionalcodeOptional ReadonlyprefixOptionalregistryReadonlytoolCloses the toolset.
NOTE: This method is invoked, for example, at the end of an agent server's lifecycle or when the toolset is no longer needed. Implementations should ensure that any open connections, files, or other managed resources are properly released to prevent leaks.
A Promise that resolves when the toolset is closed.
OptionalinvocationId: stringResolves the directory that script output files are materialized into.
Script output file names are attacker-influenced (a prompt-injected skill
controls what its script writes), so they must never be resolved against
the host application's working directory. When no scriptOutputDir was
configured this hands back a private temp directory instead, created once
and reused for the lifetime of the toolset.
Returns the tools that should be exposed to LLM.
Optionalcontext: ReadonlyContextContext used to filter tools available to the agent. If not defined, all tools in the toolset are returned.
A Promise that resolves to the list of tools.
ProtectedisReturns whether the tool should be exposed to LLM.
The tool to check.
Context used to filter tools available to the agent.
Whether the tool should be exposed to LLM.
Processes the outgoing LLM request for this toolset. This method will be called before each tool processes the llm request.
Use cases:
Base class for toolset.
A toolset is a collection of tools that can be used by an agent.