Skip to main content
Archived

This project has been archived by its maintainers, and is no longer receiving any updates.

autourgos-cap-fs

Framework: Autourgos Python License: Apache 2.0 Author Contributor Contributor

Filesystem tools for an Autourgos agent — read, write, list, glob, search, move, and delete — implementing autourgos_core.Capability so they plug straight into Engine(capabilities=[...]) and get root-jailed, risk-tiered, and journaled by autourgos-policy for free.

from autourgos_cap_fs import FsCapability

fs = FsCapability(trash_dir="C:/work/.trash")
fs.write_file("C:/work/report.md", "Hello")
print(fs.read_file("C:/work/report.md"))
# Hello

Features

  • Seven tools: read_file, list_dir, glob_files, search_text, write_file, move_file, delete_file
  • No root-jail of its own — every tool declares Resource(kind="path", ...) so autourgos_policy.FilesystemPolicy enforces containment, symlink/.. resolution, and case-insensitive Windows path handling
  • Nothing is ever silently discarded: delete_file moves the file into a managed trash directory instead of removing it, and write_file backs up whatever it's about to overwrite first
  • Undoable: FsCapability.register_undo(registry) wires the trash store into autourgos_policy.UndoRegistry — journal.undo_last(registry) restores the exact prior state
  • Atomic writes: write_file writes to a temp file and os.replace()s it into place, never leaving a half-written file behind
  • Fully typed (py.typed), zero required dependency beyond autourgos-core/autourgos-policy

Table of Contents


Install

pip install autourgos-cap-fs

Requires autourgos-core>=0.2.0 and autourgos-policy>=0.3.1.


Tools

Tool Risk Notes
read_file(path) READ
list_dir(path) READ Direct children only
glob_files(path, pattern) READ Recursive glob under path
search_text(path, query) READ Substring search over a file or a directory (recursive), capped at 200 hits
write_file(path, content) WRITE Atomic. Backs up an overwritten file for undo
move_file(src, dest) WRITE Undoable
delete_file(path) DESTRUCTIVE Soft-delete — moved to trash, not removed

Usage

Direct calls

from autourgos_cap_fs import FsCapability

fs = FsCapability(trash_dir="C:/work/.trash")

fs.write_file("C:/work/notes.txt", "First draft")
print(fs.read_file("C:/work/notes.txt"))
# First draft

print(fs.list_dir("C:/work"))
# notes.txt

print(fs.glob_files("C:/work", "*.txt"))
# C:/work/notes.txt

print(fs.search_text("C:/work", "draft"))
# C:/work/notes.txt:1: First draft

Through a PolicyGate

from autourgos_cap_fs import FsCapability
from autourgos_core import Action, Resource, Risk
from autourgos_policy import PolicyConfig, PolicyExecutor, PolicyGate

fs = FsCapability(trash_dir="C:/work/.trash")
gate = PolicyGate(
    PolicyConfig(profile="assisted", writable_roots=("C:/work/output",), readable_roots=("C:/work",))
)
executor = PolicyExecutor(gate, confirmation_callback=lambda action, decision: True)

action = Action(
    tool="write_file",
    arguments={"path": "C:/work/output/report.md", "content": "Done"},
    targets=[Resource("path", "C:/work/output/report.md")],
    risk=Risk.WRITE,
)
outcome = await executor.execute(action, fs.write_file)
assert outcome.executed

A path outside writable_roots/readable_roots is denied by FilesystemPolicy before fs.write_file ever runs — cap-fs itself never checks containment.

With autourgos-kernel

from autourgos_kernel import Engine, Run
from autourgos_policy import PolicyConfig, PolicyExecutor, PolicyGate

engine = Engine(llm=my_llm, capabilities=[fs])
gate = PolicyGate(PolicyConfig(profile="assisted", writable_roots=("C:/work/output",)))
result = await engine.run(Run(goal="Write a report to output/report.md"), policy_executor=PolicyExecutor(gate))

Soft Delete and Undo

write_file (on overwrite) and delete_file never discard prior content — both stash it in a TrashStore first and return an autourgos_policy.ExecutionValue with reversible=True and an fscap:<id> undo token. move_file records enough to move the file back too.

from autourgos_cap_fs import FsCapability
from autourgos_policy import EffectJournal, UndoRegistry

fs = FsCapability(trash_dir="C:/work/.trash")
registry = UndoRegistry()
fs.register_undo(registry)

journal = EffectJournal("run-effects.jsonl")
# ... run tools through a PolicyExecutor(gate, journal=journal) ...

outcome = await journal.undo_last(registry)
assert outcome.ok

API Reference

FsCapability(trash_dir: str)

Method Returns Description
.tools() list[ToolBinding] The seven bindings above, for autourgos_kernel.Engine(capabilities=[...])
.describe(call) Action Turns a ToolCall into a policy-checkable Action
.register_undo(registry) None Wires the trash store into an autourgos_policy.UndoRegistry
.read_file(path) str File contents
.list_dir(path) str Newline-joined entry names
.glob_files(path, pattern) str Newline-joined matching paths
.search_text(path, query) str Newline-joined path:line: text hits
.write_file(path, content) ExecutionValue reversible=True, undo_token="fscap:<id>"
.move_file(src, dest) ExecutionValue reversible=True, undo_token="fscap:<id>"
.delete_file(path) ExecutionValue reversible=True, undo_token="fscap:<id>"

TrashStore(root: str)

The backing store FsCapability owns internally (fs.trash) — stash_delete/stash_overwrite/ stash_create/stash_move record what happened, restore(entry_id) reverses it. Not root-jailed itself; pair FsCapability with FilesystemPolicy for containment.


License

Apache License 2.0, Copyright (c) 2026 Jitin Kumar Sengar

Metadata

Release files for autourgos-cap-fs 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for autourgos-cap-fs 0.1.1
File Size Uploaded
autourgos_cap_fs-0.1.1.tar.gz 22.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for autourgos-cap-fs 0.1.1
File Interpreter ABI Platform
autourgos_cap_fs-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 39.2 kB

Release files / autourgos_cap_fs-0.1.1.tar.gz

Download URL autourgos_cap_fs-0.1.1.tar.gz
Size 22.1 kB
Tags Source
SHA-256 checksum
How to use checksums
3bef35fe50e1deb3dd3949e14f539064798f7e330a6b18de67913c74761e1a72
BLAKE2b-256 checksum
How to use checksums
8dc1714f05282b63b688054cd48be957518b5ec8941dff62e0ac6484471b46bb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.9

Release files / autourgos_cap_fs-0.1.1-py3-none-any.whl

Download URL autourgos_cap_fs-0.1.1-py3-none-any.whl
Size 17.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b47ec5e571c5024147a0204d734e841203a343c6c7988c4963814727328cb798
BLAKE2b-256 checksum
How to use checksums
09365ab4cfca5dfc79903da3cca120c7a61ef3262e641514dda3ae219248fe43
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.9

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page