Compose configured toolkits
Host factory: pass configured toolkit instances and a model. The factory constructs an Agent from their public tools. The host owns toolkit clients and closes them according to each toolkit’s lifecycle after all consumers finish; it also closes the returned Agent.getTools() exposes the toolkit’s collection; filter it before passing tools if your application needs a smaller surface. A prompt that says “read only” does not remove write tools or authorize access to a service record.
For a complete lookup and approval example, use tool patterns. Import concrete toolkits from @agentium/core/toolkits or the documented individual subpath, not the core root.
Messaging and collaboration
Also see Gmail, WhatsApp, and Google Workspace. Service authorization and application record ownership remain host responsibilities.
Data, files, and execution
A filesystem base path and command restrictions are not OS isolation. Choose local, E2B, or Daytona execution according to the workload and ownership contract. Account for database pools, subprocesses, and remote sessions in shutdown.
Search, media, and judgments
“No API key” does not mean offline. Tools that search, scrape, or download still perform network I/O. Test live-service behavior separately from type-checking your configuration.