Skip to main content

Agents Function Tools

agents-function-tools is a portable Python library of policy-friendly system function tools. It contains no business model, Agent routing, domain workflow, database adapter, or code-review logic. Its Python import name is function_tools.

Included tools

Category Tools Effect class
Workspace read List, read UTF-8, inspect metadata, glob-style find, hash files, disk usage safe_read
Workspace write Write text, create directories, copy a regular file, move a path, delete a path workspace_write
ZIP List archive entries; create and extract bounded ZIP archives safe_read / workspace_write
Network Fetch bounded HTTPS text from configured hosts safe_read
Host Non-sensitive system info, UTC time, explicitly allowlisted environment variables safe_read
Commands Describe configured aliases; run one allowlisted executable with shell=False safe_read / workspace_execution

Every tool returns the same JSON envelope with ok, tool, effect, data, and error fields. Paths are always relative to a configured workspace root.

Safety boundary

  • Path traversal and access outside the workspace root are rejected.
  • The workspace root cannot be deleted.
  • Recursive deletion must be explicit.
  • File reads, writes, hashes, and archive expansion have byte limits.
  • Every workspace mutation and local command requires the SDK approval gate in addition to the orchestration approval policy. File copy accepts regular, non-symlink source files only.
  • ZIP creation rejects symlinks; ZIP extraction rejects path traversal and symlink entries before writing files.
  • HTTPS fetching requires an exact host allowlist, rejects redirects, URL credentials, and non-default ports, accepts only text-like content types, and blocks resolved private or loopback addresses. No host is enabled by default. Deployment still needs an egress proxy or firewall: application-layer DNS checks do not replace network isolation.
  • Host diagnostics intentionally exclude user identities, process lists, network configuration, installed software, and environment variables except for names explicitly configured by the host.
  • Command execution accepts an argument array, never a shell string. Programs must be mapped by the host application, execution has a timeout, and output is truncated.
  • The local command runner is not an OS security sandbox. Production deployment must run the service or runner inside the company-approved container/sandbox with no production secrets and restricted network access.
  • Approval remains the orchestration layer's responsibility. Only expose workspace_write or workspace_execution tools to an Agent after the matching approval has been validated.

This is a controlled operating-system capability adapter, not a general shell, process-management, credential, service-control, or unrestricted-network interface. Give each business Agent only the smallest subset of these tools it needs.

Example

import sys
from pathlib import Path

from function_tools.openai_tools import ToolConfig, create_function_tools

bundle = create_function_tools(
    ToolConfig(
        workspace_root=Path("./workspace"),
        command_programs={"python": sys.executable},
        http_allowed_hosts=frozenset({"api.example.internal"}),
        environment_variables=frozenset({"APP_ENV"}),
    )
)

# Safe tools can be attached to an Agent immediately.
safe_tools = list(bundle.safe_read)

# Select side-effect tools only after the policy and approval checks pass.
write_tools = list(bundle.workspace_write)
execution_tools = list(bundle.workspace_execution)

The SDK derives each FunctionTool's input schema from the Python signature and docstring. For production, keep the groups separate when attaching them to an Agent; do not use bundle.all by default.

License

Apache-2.0. See LICENSE.

Development

Use Python 3.10 or newer:

uv sync --python 3.10
uv run --python 3.10 pytest

Tests do not call the OpenAI API and do not require OPENAI_API_KEY.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

agents_function_tools-0.2.0.tar.gz (22.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

agents_function_tools-0.2.0-py3-none-any.whl (23.3 kB view details)

Uploaded Python 3

File details

Details for the file agents_function_tools-0.2.0.tar.gz.

File metadata

  • Download URL: agents_function_tools-0.2.0.tar.gz
  • Upload date:
  • Size: 22.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.12.1 {"installer":{"name":"uv","version":"0.12.1","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":null,"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

File hashes

Hashes for agents_function_tools-0.2.0.tar.gz
Algorithm Hash digest
SHA256 7e7a764a42037f485e2e7718593ad0d7597a50e9e4b2ab17c3c10e77354e0abf
MD5 e3ae1a645a32c36b2f55fbe28a595d2c
BLAKE2b-256 fe0e07ff0f493df8eea6a7634c43fe0a61f4710640471679fd0cae6a7920889e

See more details on using hashes here.

File details

Details for the file agents_function_tools-0.2.0-py3-none-any.whl.

File metadata

  • Download URL: agents_function_tools-0.2.0-py3-none-any.whl
  • Upload date:
  • Size: 23.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.12.1 {"installer":{"name":"uv","version":"0.12.1","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":null,"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

File hashes

Hashes for agents_function_tools-0.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 a4d22fc52d2b16f308f81dcbd1b47c6a7ab9bcb240f0d4b69649ced21baa5b4f
MD5 62e2fce7923a95e72fea51e7206677fd
BLAKE2b-256 78b74a7aa9681b15d813b5f2189dea87430bb80317f4f7b3a7ff2855573e594f

See more details on using hashes here.

Release history Release notifications | RSS feed

0.4.0

2 files

0.3.0

2 files

This release

0.2.0 This release

2 files

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page