Something went wrong. Try again.
This repository has no description
Something went wrong. Try again.
123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126import { createHash } from "node:crypto";import { createFetchTools, type FetchResult,} from "@cloudflare/think/tools/fetch";import * as Effect from "effect/Effect";import { tool, type ToolSet } from "ai";import { z } from "zod";import type { CapabilityReference } from "../shared/capability-policy";import type { SkillRequirements } from "../shared/skill-permissions";import { agentCall, agentValidation, runAgent } from "./agent-io";import type { SkillExecutionGrant } from "./skill-execution-permissions";import type { McpInvocation } from "./mcp-invocation";import { publicWebUrl } from "./web-source";
const fetchTool = createFetchTools({ allowlist: ["https://**"], maxBytes: 16_384, maxModelChars: 16_384, timeoutMs: 10_000, response: "text", spillToWorkspace: false, followRedirects: "none", modelHeaderAllowlist: [],}).fetch_url;const networkInput = z.strictObject({ url: z.string().min(1).max(2048) });export const skillExternalToolName = (reference: CapabilityReference) => `capability_${createHash("sha256") .update( JSON.stringify([ reference.source.kind, reference.source.id, reference.id, ]), ) .digest("hex")}`;
export function skillScriptTools(options: { requirements: SkillRequirements; grant: SkillExecutionGrant; signal: AbortSignal; conversationId: string; toolCallId: string; external: (reference: CapabilityReference) => McpInvocation;}): ToolSet { const { grant, signal } = options; const tools: ToolSet = Object.create(null); if (options.requirements.network) tools.network_fetch = tool({ description: "Read a public HTTPS URL as bounded text. Redirects and custom credentials are not supported.", inputSchema: networkInput, execute: (value) => runAgent( grant.use("network", () => Effect.gen(function* () { const url = yield* agentValidation(() => { const input = networkInput.parse(value); const parsed = publicWebUrl(input.url); if (parsed.protocol !== "https:") throw new Error("HTTPS is required"); return parsed.href; }); const result = yield* agentCall( () => Promise.resolve( fetchTool.execute!( { url }, { toolCallId: options.toolCallId, messages: [], context: {}, abortSignal: signal, }, ), ) as Promise<FetchResult>, "Skill network request failed", ); if (!result.ok) throw new Error("Skill network request failed"); return { text: result.body ?? "", truncated: result.truncated }; }), ), signal, ), }); for (const reference of options.requirements.externalCapabilities) { tools[skillExternalToolName(reference)] = tool({ description: "Call the exact declared capability. Its own current policy must allow this call.", inputSchema: z.record(z.string(), z.unknown()), execute: (value) => runAgent( grant.use( "externalCapabilities", () => Effect.gen(function* () { const input = yield* agentValidation(() => z.record(z.string(), z.unknown()).parse(value), ); const invocation = options.external(reference); const cancel = () => invocation.cancel(); signal.addEventListener("abort", cancel, { once: true }); try { signal.throwIfAborted(); const result = yield* agentCall(() => invocation.run(input, false), ); if ("error" in result) throw new Error( "External Skill capability failed or requires separate approval", ); return result; } finally { signal.removeEventListener("abort", cancel); invocation[Symbol.dispose](); } }), reference, ), signal, ), }); } return tools;}