-
Notifications
You must be signed in to change notification settings - Fork 3
$.tool.register: one typed supertool tool, so Bash stops impersonating it — not one tool per op #2294
Copy link
Copy link
Open
Labels
cohort-29Open at the v0.60.0 tag, 2026-09-11. Frozen: nothing joins a cohort.Open at the v0.60.0 tag, 2026-09-11. Frozen: nothing joins a cohort.cohort-30Open at the v0.61.0 tag, 2026-09-12. Frozen: nothing joins a cohort.Open at the v0.61.0 tag, 2026-09-12. Frozen: nothing joins a cohort.cohort-31Open at the v0.63.0 tag, 2026-09-19. Frozen: nothing joins a cohort.Open at the v0.63.0 tag, 2026-09-19. Frozen: nothing joins a cohort.cohort-32Open at the v0.64.0 tag, 2026-09-23. Frozen: nothing joins a cohort.Open at the v0.64.0 tag, 2026-09-23. Frozen: nothing joins a cohort.enhancementNew feature or requestNew feature or requestlane-containmentpayload gate and trust model — reaches into other lanes, wants their reviewpayload gate and trust model — reaches into other lanes, wants their reviewpriority-mediumRecurring cost; compounds if unfixedRecurring cost; compounds if unfixed
Milestone
Description
Activity
Metadata
Metadata
Assignees
Labels
cohort-29Open at the v0.60.0 tag, 2026-09-11. Frozen: nothing joins a cohort.Open at the v0.60.0 tag, 2026-09-11. Frozen: nothing joins a cohort.cohort-30Open at the v0.61.0 tag, 2026-09-12. Frozen: nothing joins a cohort.Open at the v0.61.0 tag, 2026-09-12. Frozen: nothing joins a cohort.cohort-31Open at the v0.63.0 tag, 2026-09-19. Frozen: nothing joins a cohort.Open at the v0.63.0 tag, 2026-09-19. Frozen: nothing joins a cohort.cohort-32Open at the v0.64.0 tag, 2026-09-23. Frozen: nothing joins a cohort.Open at the v0.64.0 tag, 2026-09-23. Frozen: nothing joins a cohort.enhancementNew feature or requestNew feature or requestlane-containmentpayload gate and trust model — reaches into other lanes, wants their reviewpayload gate and trust model — reaches into other lanes, wants their reviewpriority-mediumRecurring cost; compounds if unfixedRecurring cost; compounds if unfixed
Follows #2293. A function-hooks module can register tools at run time:
(strings from
@anthropic-ai/claude-code-darwin-arm64@2.1.260, verified 2026-09-04)The wrong version of this idea is to register the roster. It inverts the premise. A tool call carries one call;
supertool 'read:A' 'read:B' 'git-status'is three answers in one round-trip, and three registered tools is three round-trips each re-paying the cached prefix.ops:fullsays it costs 80100 bytes of descriptions alone, before aninputSchemaper op, and as registered tools that is prompt weight on every session whether or not the session calls one. This repo's own listing already ships signature-only for exactly that reason (#1774).The right version is one tool.
{ name: "supertool", description: <the ops table>, inputSchema: { ops: string[] } }. Same batching, same op strings, but the model fills a schema instead of composing a shell string that the raw-command guard then has to police. Today every supertool call is aBashcall, which means:python3 supertool.pyversussupertoolis a distinction the model has to remember (The mixed-tree refusal fires on git-commit but not on paste/edit, so a write from a worktree lands silently in the main clone #1942) rather than one the host resolves;rtkwrapper mangles anything redirected or captured, which is a session-level trap with no home in the tool itself.A registered tool moves all three from advice to mechanism.
Open questions:
read, maybegrep), and I have not measured which. The default answer is none.tool.describehook can rewrite it per session, so it need not be static.Blocked on the same flag as #2293:
CLAUDE_CODE_ENABLE_FUNCTION_HOOKS=1, flagtengu_plugin_hooks_modules, GrowthBook-gated.