Skip to main content
Built-in abilities return configured ability uses. Add them to defineHarness({ abilities: [...] }); the runtime binds them for each run. Tool availability and permission are separate: supplying a tool does not grant execution.

Choose a preset or ability

research() disables filesystem, contextFiles, fileMemory, and subagents by default. Explicit defaults can override those choices. Its built-in instance IDs are research-text, research-files, and research-tools; avoid reusing those IDs in additional abilities.

Read project files

This factory builds a runtime but does not run it. Call run() with verified identity and a session to read the files and invoke the Agent.
fileContext checks canonical paths against its root, rejects invalid or duplicate file selections, and bounds reads. File contents become source entries with URI/version metadata. This is application-level path containment; use a separate process or sandbox when you need OS isolation.

Supply existing tools

Set grants.toolIds to the intended ToolDef.name values when constructing the runtime. requiredToolIds additionally makes missing tools a setup error. The runtime also accepts a direct tools array; duplicate names across direct tools and abilities are rejected.

Connect MCP resources

Provide a principal-scoped connection factory and authorization function. This example is an integration factory: your host implements both callbacks and supplies a connected client.
connect(ctx) returns { client, dispose? }. Setup defaults to a 5,000 ms timeout; valid values are 1–120,000 ms. A late connection is disposed if setup was cancelled. The binding disposes its connection at the end of the run. Resource URIs and MIME types are exact allowlists. Wildcard MIME types are rejected; include "" only if you intentionally accept responses without a MIME type. select(query, ctx) may choose a subset of declared URIs; duplicate or undeclared selections fail. Authorization runs before reads and before content is returned, including subsequent fetches. This ability does not discover resources across a server, turn resources into tools, or fetch their URIs over HTTP.

Understand context bounds and trust

Runtime retrieval shares a budget across all context sources: 32 entries, 65,536 bytes, an estimated 16,000 tokens, and 5,000 ms. These are the current runtime retrieval defaults, not fields you can configure through HarnessRuntimeConfig. A source receives the remaining budget in fetch() and should honor its abort signal. The runtime wraps context with source and entry IDs plus optional URI/version/locator metadata. Retrieved content is always treated as source data, even if an entry claims trust: "host". Invalid, expired, or failed entries can be discarded; oversized text can be truncated. Providers receive source data separately from host prompt fragments. Use a context policy to project bounded requests without modifying canonical history. For exact option shapes, see presets and context reference.