waaseyaa / ai-tools
Shared agent-tool catalogue (#[AsAgentTool] + AttributeToolRegistry) used by AgentExecutor and the MCP endpoint
Requires
- php: >=8.5
- waaseyaa/access: ^0.1.0-alpha.300
- waaseyaa/entity: ^0.1.0-alpha.300
- waaseyaa/entity-storage: ^0.1.0-alpha.300
- waaseyaa/foundation: ^0.1.0-alpha.300
- waaseyaa/media: ^0.1.0-alpha.300
- waaseyaa/publishing: ^0.1.0-alpha.300
Requires (Dev)
- phpunit/phpunit: ^13.0
- waaseyaa/audit: ^0.1.0-alpha.300
- waaseyaa/database-legacy: ^0.1.0-alpha.300
- waaseyaa/field: ^0.1.0-alpha.300
- waaseyaa/search: ^0.1.0-alpha.300
- waaseyaa/testing: ^0.1.0-alpha.300
Suggests
- waaseyaa/search: Provides principal-safe ranked CMS search tools and content resources
Provides
None
Conflicts
- waaseyaa/search: <0.1.0-alpha.287 || >=0.2.0
Replaces
None
- dev-main / 0.1.x-dev
- v0.1.0-alpha.300
- v0.1.0-alpha.299
- v0.1.0-alpha.298
- v0.1.0-alpha.297
- v0.1.0-alpha.296
- v0.1.0-alpha.295
- v0.1.0-alpha.294
- v0.1.0-alpha.293
- v0.1.0-alpha.292
- v0.1.0-alpha.291
- v0.1.0-alpha.290
- v0.1.0-alpha.289
- v0.1.0-alpha.288
- v0.1.0-alpha.287
- v0.1.0-alpha.286
- v0.1.0-alpha.285
- v0.1.0-alpha.284
- v0.1.0-alpha.283
- v0.1.0-alpha.282
- v0.1.0-alpha.281
- v0.1.0-alpha.280
- v0.1.0-alpha.279
- v0.1.0-alpha.278
- v0.1.0-alpha.277
- v0.1.0-alpha.276
- v0.1.0-alpha.275
- v0.1.0-alpha.274
- v0.1.0-alpha.273
- v0.1.0-alpha.272
- v0.1.0-alpha.271
- v0.1.0-alpha.270
- v0.1.0-alpha.269
- v0.1.0-alpha.268
- v0.1.0-alpha.267
- v0.1.0-alpha.266
- v0.1.0-alpha.265
- v0.1.0-alpha.264
- v0.1.0-alpha.263
- v0.1.0-alpha.262
- v0.1.0-alpha.261
- v0.1.0-alpha.260
- v0.1.0-alpha.259
- v0.1.0-alpha.258
- v0.1.0-alpha.257
- v0.1.0-alpha.256
- v0.1.0-alpha.255
- v0.1.0-alpha.254
- v0.1.0-alpha.253
- v0.1.0-alpha.252
- v0.1.0-alpha.251
- v0.1.0-alpha.250
- v0.1.0-alpha.249
- v0.1.0-alpha.248
- v0.1.0-alpha.247
- v0.1.0-alpha.246
- v0.1.0-alpha.245
- v0.1.0-alpha.244
- v0.1.0-alpha.243
- v0.1.0-alpha.242
- v0.1.0-alpha.241
- v0.1.0-alpha.240
- v0.1.0-alpha.239
- v0.1.0-alpha.238
- v0.1.0-alpha.237
- v0.1.0-alpha.236
- v0.1.0-alpha.235
- v0.1.0-alpha.234
- v0.1.0-alpha.233
- v0.1.0-alpha.232
- v0.1.0-alpha.231
- v0.1.0-alpha.230
- v0.1.0-alpha.229
- v0.1.0-alpha.228
- v0.1.0-alpha.227
- v0.1.0-alpha.226
- v0.1.0-alpha.225
- v0.1.0-alpha.224
- v0.1.0-alpha.223
- v0.1.0-alpha.222
- v0.1.0-alpha.221
- v0.1.0-alpha.220
- v0.1.0-alpha.219
- v0.1.0-alpha.218
- v0.1.0-alpha.217
- v0.1.0-alpha.216
- v0.1.0-alpha.215
- v0.1.0-alpha.214
- v0.1.0-alpha.213
- v0.1.0-alpha.212
- v0.1.0-alpha.211
- v0.1.0-alpha.210
- v0.1.0-alpha.209
- v0.1.0-alpha.208
- v0.1.0-alpha.207
- v0.1.0-alpha.206
- v0.1.0-alpha.205
- v0.1.0-alpha.204
- v0.1.0-alpha.203
- v0.1.0-alpha.202
- v0.1.0-alpha.201
- v0.1.0-alpha.200
- v0.1.0-alpha.199
- v0.1.0-alpha.198
- v0.1.0-alpha.197
- v0.1.0-alpha.196
- v0.1.0-alpha.195
- v0.1.0-alpha.194
- v0.1.0-alpha.193
- v0.1.0-alpha.192
- v0.1.0-alpha.191
- v0.1.0-alpha.190
- v0.1.0-alpha.189
- v0.1.0-alpha.188
- v0.1.0-alpha.187
- v0.1.0-alpha.186
- v0.1.0-alpha.185
- v0.1.0-alpha.184
- v0.1.0-alpha.183
- v0.1.0-alpha.182
- v0.1.0-alpha.181
This package is auto-updated.
Last update: 2026-09-02 16:13:18 UTC
README
Shared agent-tool catalogue for Waaseyaa. Defines the #[AsAgentTool]
attribute, the AgentTool value object, AgentToolInterface, and the
attribute-discovered AttributeToolRegistry consumed by both
Waaseyaa\AI\Agent\AgentExecutor and the live
Waaseyaa\Mcp\McpEndpoint through AgentToolRegistryBridge.
Tool names are globally unique: duplicate discovered or manual registrations
raise DuplicateToolNameException instead of silently replacing a tool.
See docs/specs/agent-executor.md for the design spec and the eight
stock tools shipped in this package.
Principal-safe content search
When the optional waaseyaa/search package is installed, the catalogue adds
content.search. The non-destructive tool returns ranked excerpts, bounded
metadata, and facets from Search's access-checked read surface. It passes the
acting AuthorizationPrincipalInterface unchanged, so entity access, guarded
field reads, tenant claims, and denied-result counts retain Search's fail-closed
semantics. Search inspects one raw 1,000-candidate relevance window plus a
truncation sentinel so an anonymous caller cannot amplify one rate-limited
request into an unbounded offset scan. is_complete: false marks exhaustion;
totals, pages, and facets are then lower bounds, while filters and
non-relevance sorts cover only principal-safe matches inside that window. The
flag can accompany zero visible hits when every inspected candidate is denied
or filtered.
Search is an explicit composition opt-in, not a hard dependency. The catalogue
checks only autoload availability during boot and tools/list; it resolves the
database-backed provider lazily on tools/call. An absent package means the
tool is absent. An installed but broken binding leaves the advertised tool
stable and returns a sanitized correlated TOOL_UNAVAILABLE error when called.
The adapter copies every result into an ai-tools-owned closed schema and rejects malformed or
oversized provider output. Audit arguments retain filters and pagination but
replace the query and free-text filter values with lengths or counts.
Titles, excerpts, URLs, and metadata are CMS-authored, untrusted data. Agent integrators must treat returned hit text as evidence to inspect, never as instructions that override the agent's policy or tool contract.
Principal-safe content resources
The MCP-neutral ContentResourceRegistry accepts bounded, principal-explicit
resource contributions. When Search is installed, a lazy string-resolved
adapter contributes up to 50 access-checked public-path resources plus the
waaseyaa://content/{public_path_token} RFC 6570 template. Canonical tokens are
strict unpadded base64url encodings of public routes, never entity IDs or
filesystem paths. Reads return bounded UTF-8 text/plain only. Denied and
missing reads both return no content; the MCP adapter owns their identical
protocol response.
Remote editorial mutations
Content\ContentToolSet is the canonical MCP editing surface. Applications
register one set per content bundle under stable app-owned names. Its schemas
are bundle-scoped and reject unknown fields; writes are draft-first,
idempotency-keyed, revision-aware, and optimistic-locking protected.
The stock entity.* mutation tools remain useful to trusted embedded agents,
but their entity-type argument makes them cross-bundle by construction. The MCP
write tier therefore withholds those generic mutations by default even when a
broad tool.entity.* capability is allowlisted.