PoietesCMD

Documentation

Tools and limits

A task can only use the tools you ticked when you created it. Each tool has a policy: auto runs without asking, ask stops the task for your approval every time.

Every tool returns a structured result: { "ok": true, "data": … } or { "ok": false, "error": { "code", "message" } }. Failures are given to the model as they are, so it can adapt or report them.

The workspace

File tools see one folder, the workspace (/data/workspace in Docker, ./data/workspace in development). Upload files from Files in the console, or mount a host folder there.

Paths are relative to the workspace and use forward slashes. A path is refused when it is absolute, contains .., a drive letter, a NUL byte, a reserved device name, or when any part of it, after following symbolic links, resolves outside the workspace.

list_files

Lists files and folders. recursive goes up to six levels deep. At most 1,000 entries are returned; the result says when the list was cut.

read_file

Reads a text file of at most 2 MiB. Supported types:

.txt .md .markdown .csv .tsv .json .jsonl .yaml .yml .xml .html .htm .log .ini .toml .rst .tex .sql .js .ts .py .css

Long files come back in pages: the result has nextOffset to continue. Refused with an explicit error: other file types (unsupported_format), binary content, files that look like credentials such as .env, *.pem or id_rsa (file_refused), and files over the size limit (file_too_large).

search_files

Finds lines containing an exact phrase. It is a literal match, not a regular expression. It scans up to 2,000 supported files of at most 2 MiB each and returns up to 200 matches with file, line number and the line.

analyze_csv

Parses a .csv, .tsv or delimited .txt file on the server and returns exact statistics, so reports are built from computed numbers rather than from what a model read.

  • Limits: 10 MiB, 200,000 rows, 200 columns.
  • Parsing follows RFC 4180: quoted fields, doubled quotes, delimiters and line breaks inside quotes, CRLF or LF. The delimiter is detected from the first lines (, ; tab |) or can be given.
  • Per column: type, values, missing, distinct. A column is numeric only when every non-empty value is a number; then you get min, max, sum, mean, median, quartiles and the sample standard deviation (n − 1). Quantiles use linear interpolation. Boolean columns get counts, ISO-date columns get the first and last date, text columns get their most frequent values.
  • A column that is mostly numeric but has other values is reported as text, with a warning that names examples.

write_artifact

Saves generated text as a file you can open and download. Allowed types: .md, .txt, .csv, .json (JSON must parse). The name is a bare filename: no folders, no leading dot. One artifact is at most the task's artifact-size limit.

Artifacts are written to the artifact store, never into the workspace, so a task cannot overwrite your files. The file location is derived from the task and the tool call, which makes the write safe to repeat after a crash.

fetch_url

Fetches one public page with a GET request and returns its readable text. HTML is reduced to text: scripts, styles and embedded content are dropped, headings and list items are marked, and when the page marks its main content, navigation and footers are left out. JSON, XML and plain text are returned as they are.

Restrictions, none of which can be switched off:

  • Only http and https. No usernames or passwords in the URL.
  • Only the ports in PCMD_FETCH_ALLOWED_PORTS (80 and 443 by default).
  • The host must resolve only to public addresses. Refused: loopback, private ranges, link-local including the cloud metadata address 169.254.169.254, carrier-grade NAT, multicast, reserved and documentation ranges, and IPv6 forms that embed such an address. Local names such as localhost and *.internal are refused without a lookup.
  • The address is checked again at the moment the connection is made, so a name cannot pass the check and then resolve somewhere else.
  • Redirects are followed only on the same host, at most five, never from https to http. A redirect to another host is reported to the model, which must request that URL itself and go through the permission check again.
  • 20 seconds in total, 2 MiB of response body.
  • Each request, redirects included, counts against the task's network-request limit.

Approval. With policy ask, every fetch needs approval. With policy auto, a fetch runs without asking only when the host is in the task's allowed domains (a domain covers its subdomains); any other host needs approval for that exact URL. An approval does not bypass the restrictions above.

Text from the web is untrusted. The result carries a notice saying so, and the system prompt tells the model never to act on instructions found in tool output. The enforcement does not depend on the model obeying: a page cannot add a tool to a task or approve anything.

Built-in tools

Two tools are always handled by the runner itself and touch no files and no network:

  • update_plan records the plan shown in the console.
  • propose_memory stores a suggestion as an inactive proposal. It is offered only when memory and proposals are on for the task, and at most three per task are accepted.

What is deliberately missing

There is no tool that runs shell commands, and no tool that writes into the workspace. Both would need a sandbox with its own limits, which this version does not include.

NextMemory