This project has been archived by its maintainers, and is no longer receiving any updates.
autourgos-cap-fs
Filesystem tools for an Autourgos agent — read, write, list, glob, search, move,
and delete — implementing autourgos_core.Capability so they plug straight into Engine(capabilities=[...])
and get root-jailed, risk-tiered, and journaled by autourgos-policy for free.
from autourgos_cap_fs import FsCapability
fs = FsCapability(trash_dir="C:/work/.trash")
fs.write_file("C:/work/report.md", "Hello")
print(fs.read_file("C:/work/report.md"))
# Hello
Features
- Seven tools:
read_file,list_dir,glob_files,search_text,write_file,move_file,delete_file - No root-jail of its own — every tool declares
Resource(kind="path", ...)soautourgos_policy.FilesystemPolicyenforces containment, symlink/..resolution, and case-insensitive Windows path handling - Nothing is ever silently discarded:
delete_filemoves the file into a managed trash directory instead of removing it, andwrite_filebacks up whatever it's about to overwrite first - Undoable:
FsCapability.register_undo(registry)wires the trash store intoautourgos_policy.UndoRegistry—journal.undo_last(registry)restores the exact prior state - Atomic writes:
write_filewrites to a temp file andos.replace()s it into place, never leaving a half-written file behind - Fully typed (
py.typed), zero required dependency beyondautourgos-core/autourgos-policy
Table of Contents
Install
pip install autourgos-cap-fs
Requires autourgos-core>=0.2.0 and autourgos-policy>=0.3.1.
Tools
| Tool | Risk | Notes |
|---|---|---|
read_file(path) |
READ |
|
list_dir(path) |
READ |
Direct children only |
glob_files(path, pattern) |
READ |
Recursive glob under path |
search_text(path, query) |
READ |
Substring search over a file or a directory (recursive), capped at 200 hits |
write_file(path, content) |
WRITE |
Atomic. Backs up an overwritten file for undo |
move_file(src, dest) |
WRITE |
Undoable |
delete_file(path) |
DESTRUCTIVE |
Soft-delete — moved to trash, not removed |
Usage
Direct calls
from autourgos_cap_fs import FsCapability
fs = FsCapability(trash_dir="C:/work/.trash")
fs.write_file("C:/work/notes.txt", "First draft")
print(fs.read_file("C:/work/notes.txt"))
# First draft
print(fs.list_dir("C:/work"))
# notes.txt
print(fs.glob_files("C:/work", "*.txt"))
# C:/work/notes.txt
print(fs.search_text("C:/work", "draft"))
# C:/work/notes.txt:1: First draft
Through a PolicyGate
from autourgos_cap_fs import FsCapability
from autourgos_core import Action, Resource, Risk
from autourgos_policy import PolicyConfig, PolicyExecutor, PolicyGate
fs = FsCapability(trash_dir="C:/work/.trash")
gate = PolicyGate(
PolicyConfig(profile="assisted", writable_roots=("C:/work/output",), readable_roots=("C:/work",))
)
executor = PolicyExecutor(gate, confirmation_callback=lambda action, decision: True)
action = Action(
tool="write_file",
arguments={"path": "C:/work/output/report.md", "content": "Done"},
targets=[Resource("path", "C:/work/output/report.md")],
risk=Risk.WRITE,
)
outcome = await executor.execute(action, fs.write_file)
assert outcome.executed
A path outside writable_roots/readable_roots is denied by FilesystemPolicy before fs.write_file ever
runs — cap-fs itself never checks containment.
With autourgos-kernel
from autourgos_kernel import Engine, Run
from autourgos_policy import PolicyConfig, PolicyExecutor, PolicyGate
engine = Engine(llm=my_llm, capabilities=[fs])
gate = PolicyGate(PolicyConfig(profile="assisted", writable_roots=("C:/work/output",)))
result = await engine.run(Run(goal="Write a report to output/report.md"), policy_executor=PolicyExecutor(gate))
Soft Delete and Undo
write_file (on overwrite) and delete_file never discard prior content — both stash it in a TrashStore
first and return an autourgos_policy.ExecutionValue with reversible=True and an fscap:<id> undo token.
move_file records enough to move the file back too.
from autourgos_cap_fs import FsCapability
from autourgos_policy import EffectJournal, UndoRegistry
fs = FsCapability(trash_dir="C:/work/.trash")
registry = UndoRegistry()
fs.register_undo(registry)
journal = EffectJournal("run-effects.jsonl")
# ... run tools through a PolicyExecutor(gate, journal=journal) ...
outcome = await journal.undo_last(registry)
assert outcome.ok
API Reference
FsCapability(trash_dir: str)
| Method | Returns | Description |
|---|---|---|
.tools() |
list[ToolBinding] |
The seven bindings above, for autourgos_kernel.Engine(capabilities=[...]) |
.describe(call) |
Action |
Turns a ToolCall into a policy-checkable Action |
.register_undo(registry) |
None |
Wires the trash store into an autourgos_policy.UndoRegistry |
.read_file(path) |
str |
File contents |
.list_dir(path) |
str |
Newline-joined entry names |
.glob_files(path, pattern) |
str |
Newline-joined matching paths |
.search_text(path, query) |
str |
Newline-joined path:line: text hits |
.write_file(path, content) |
ExecutionValue |
reversible=True, undo_token="fscap:<id>" |
.move_file(src, dest) |
ExecutionValue |
reversible=True, undo_token="fscap:<id>" |
.delete_file(path) |
ExecutionValue |
reversible=True, undo_token="fscap:<id>" |
TrashStore(root: str)
The backing store FsCapability owns internally (fs.trash) — stash_delete/stash_overwrite/
stash_create/stash_move record what happened, restore(entry_id) reverses it. Not root-jailed itself;
pair FsCapability with FilesystemPolicy for containment.
License
Apache License 2.0, Copyright (c) 2026 Jitin Kumar Sengar
Metadata
Release files for autourgos-cap-fs 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| autourgos_cap_fs-0.1.1.tar.gz | 22.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| autourgos_cap_fs-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 39.2 kB
Release files / autourgos_cap_fs-0.1.1.tar.gz
| Download URL | autourgos_cap_fs-0.1.1.tar.gz |
|---|---|
| Size | 22.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
3bef35fe50e1deb3dd3949e14f539064798f7e330a6b18de67913c74761e1a72
|
|
BLAKE2b-256 checksum How to use checksums |
8dc1714f05282b63b688054cd48be957518b5ec8941dff62e0ac6484471b46bb
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.11.9
|
Release files / autourgos_cap_fs-0.1.1-py3-none-any.whl
| Download URL | autourgos_cap_fs-0.1.1-py3-none-any.whl |
|---|---|
| Size | 17.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
b47ec5e571c5024147a0204d734e841203a343c6c7988c4963814727328cb798
|
|
BLAKE2b-256 checksum How to use checksums |
09365ab4cfca5dfc79903da3cca120c7a61ef3262e641514dda3ae219248fe43
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.11.9
|