Skip to content

Tool validation ​

This page is a smoke-validation checklist for Alisio's tools: for each tool, one concrete call and the result that proves it is wired and reachable. It records the verification scope for tools; runtime and packaging limits are in Known limitations, and the effect model is in Tools & permissions.

Scope ​

  • Covers the tools Alisio ships: the built-in set plus the tools added by the built-in memory and subagents plugins.
  • Third-party MCP tools are out of scope beyond the fact that they depend on their server: the list is whatever the connected server exposes.
  • Validation is a live call in a real session, not a unit test, and every row is reproducible by a user with the same flags.

Built-in tools ​

ToolEffectValidationExpected result
read_filereadRead a tracked file such as package.jsonContent plus a sha256 fingerprint
list_filesreadList a directory such as packagesEntries with nextOffset and truncated
search_textreadSearch a literal that exists in the repoMatches with file and line
git_statusreadRun it inside a Git repositorygit status --porcelain=v1 output
git_diffreadRun it with pending changesA unified diff
skill_loadreadLoad an installed skillSkill root plus its instructions
skill_searchreadSearch a termMatching skills, or [] when none match
skill_resourcereadRead a file under a skill rootThe file content
context_explainreadExplain the AGENTS.md files for a pathThe scopes that apply, closest last
ask_user_questionreadAsk 1-4 questions in the TUIThe selected answers, or a fast error headless
write_filewriteCreate a scratch fileThe new path plus a sha256
edit_filewriteReplace one unique matchAn updated sha256
run_processprocessRun git rev-parse --short HEADThe short commit id
shellprocessRun pwd && node --versionThe working directory and the Node version
executeprocessCall one read-only tool inside a snippetThat tool's result as JSON
webfetchexternalFetch https://example.comStatus 200 and the page text
websearchexternalSearch any queryRanked results, or a provider error
plugin_installprocessInstall a known npm pluginThe installed path and the config entry

Plugin tools ​

ToolEffectValidationExpected result
memory_saveinternalSave an observationThe id and the action (created, updated, duplicate)
memory_searchinternalSearch a word already storedCompact rows, or []
memory_getinternalFetch a saved idThe full observation
memory_contextinternalCall it at session startA bounded context block
memory_timelineinternalAsk for the neighbours of an idOlder and newer rows
memory_pininternalPin, then unpin, an idpinned: true, then false
memory_forgetinternalSoft delete; hard: true removes itforgotten: true
taskinternalDelegate a small read-only jobA task id, foreground or background
task_statusinternalCheck that idState, agent and token count
task_waitinternalWait for that idThe subagent's final report
send_messageinternalMessage a finished taskIt resumes in the background

Permission-gated tools ​

read tools are always available and internal tools only touch Alisio's own state; write, process and external need a flag or an interactive approval in the TUI. To validate a gated tool, allow its effect first.

EffectEnable withHeadless run with no flag
readAlways enabledAvailable
write--allow-write, or approve in the TUIUnavailable
process--allow-process, or approve in the TUIUnavailable
external--allow-external, --allow-mcp, --allow-agents, or approve in the TUIUnavailable
internalAlways enabledAvailable

--read-only wins over every --allow-* flag: the effect is never offered, in the TUI or headless.

External dependencies ​

  • list_files and search_text need the rg executable on PATH.
  • webfetch and websearch need network access. websearch uses the configured websearch.provider, else a public SearXNG instance; public instances may answer with a bot-check page instead of results, so configure a provider for reliable use.
  • MCP tools exist only after their server is connected (--allow-mcp, or the global mcp.allow).
  • ask_user_question needs a bound interactive UI; in a headless run it fails fast and tells the model to ask in plain text instead.

Procedure ​

sh
# Interactive: read is immediate; approve write/process/external per call
alisio

# Or start permissive for the session
alisio --allow-write --allow-process --allow-external

# Headless: an unset flag means the effect is unavailable
alisio run "list the available tools" --allow-write --allow-process --allow-external

After changing tools, run the repository checks (pnpm check) so typecheck, lint, tests, the CLI end-to-end and the docs gates stay green.

Last run ​

Snapshot of 2026-09-27 (Node v22.19.0, commit ace8def): every built-in and plugin tool above answered as expected except websearch, which failed because the default public SearXNG instance returned a bot-check page — a provider problem, not a tool problem. ask_user_question was exercised in the interactive TUI and returned answers. plugin_install was not run because it changes global state.

Released under the MIT License.