Skip to main content
Tools

Built-in Tools

Pi's file and shell tools, where they run with and without a sandbox, and how to choose them.

Built-in tools are Pi’s own file and shell tools. The CodingTools extension from @earendil-works/pi-durable/tools installs all four:

ToolWhat it does
readReads a text file. The model reads a long file in parts.
writeCreates or replaces a file.
editChanges part of a file.
bashRuns a shell command.

Where they run

The sandbox option decides where the tools run. They never touch your worker’s file system or shell.

ToolWithout a sandboxWith a sandbox
read, write, editFiles in the Actor’s own SQLite database.Files in the sandbox.
bashReturns an error. There is no shell.Runs in the sandbox.
Agent ActorActor’s SQLite databaseSandboxread, write, editno sandboxread, write, edit, bashwith a sandbox

Without a sandbox, there is nothing to set up. The files are saved with the conversation and survive sleep and crashes. This agent has no sandbox, so it installs the file tools without bash:

The second prompt edits the file that the first prompt wrote. To run commands, give the agent a sandbox.

Choose tools

Each tool also has its own factory: createReadTool, createWriteTool, createEditTool, and createBashTool. Install only the tools you want in your own extension. This reviewer can read files and run tests, but it has no write or edit tool:

import { createRegistry, defineExtension } from "@earendil-works/pi-durable";
import { createBashTool, createReadTool } from "@earendil-works/pi-durable/tools";
import { pi } from "@rivet-dev/pi";
import { e2bProvider } from "@rivet-dev/sandbox-adapter/e2b";
import { setup } from "rivetkit";

// read and bash, without the write and edit tools
const extensions = createRegistry();
extensions.install(defineExtension({ name: "review-tools", tools: [createReadTool(), createBashTool()] }));

const reviewer = pi({
	model: "anthropic/claude-opus-5-5",
	registry: extensions,
	sandbox: e2bProvider(),
});

export const registry = setup({ use: { reviewer } });

registry.start();
  • The bash tool can still change files in the sandbox. For an agent that must not change anything, leave bash out too.
  • A client can narrow the tools of one conversation with conversation.configure(id, { tools: ["read"] }).
  • In a sandbox, the file tools reject paths outside the sandbox’s working directory.
  • The bash tool accepts a timeout, and long output is truncated before it reaches the model.
  • Images aren’t supported yet. The read tool returns an error for an image file.

To give an agent your own tools, see Custom Tools.