# ToolCabana agent tools

> Deterministic utilities for data preparation, privacy checks, testing and publishing.

Version: 1.0.0. 136 local implementations; 0 optional network tools; 0 external-runtime capabilities.

## Connect

- Browser: https://www.toolcabana.com/agents (runs inputs in a dedicated Web Worker)
- OpenAPI: https://www.toolcabana.com/agents/openapi.json (no hosted operations are enabled)
- Catalog: https://www.toolcabana.com/agents/catalog.json
- Local MCP: `npm run agent:stdio --silent` (requires this repository and its installed dependencies)
- Local call: `npm run agent:call -- json.parse '{"text":"{\"ok\":true}"}'`

Hosted execution is disabled in this release. Use the browser console or local stdio server; this website does not currently provide a remote MCP service.

Hosted calls require `Authorization: Bearer <credential>`, `tools:execute`, and configured durable budgets. Network tools additionally require `network:read` and opt-in network configuration. Default Hobby configuration disables hosted calls, ads and sponsorship. For OAuth-capable clients, configure an external issuer and use protected-resource metadata. API keys alone are not an OAuth authorization server.

## Limits and trust

256 KiB arguments, 512 KiB results, 20 nesting levels and 2,000 array entries. All 136 local tools enforce authored output schemas before transport; caller data remains bounded recursive JSON. Inspect output contracts in the catalog or MCP tools/list. Shape validation does not prove algorithm correctness. Agent argument decoders, nested JSON/JWT/JSON-LD/JSONL, JSON/YAML conversion and conservative repair reject numeric precision loss; quote exact identifiers or decimals as strings. Calendar inputs use valid ISO dates or offset timestamps; impossible dates are rejected. Deadline, freshness and report helpers use the local clock. No arbitrary code execution, outbound webhooks, paid inference or durable file/job storage is implemented on Hobby. External-runtime entries are documented requirements and are omitted from callable MCP/OpenAPI tools. Rule-based guardrails are advisory; scopes, exact grants, public DNS validation and atomic budgets are enforced outside the model. Inputs and outputs are not logged by this layer. Destination services observe network requests. Browser tools use no remote input submission.

## json.parse — Parse and validate JSON

Parse bounded JSON without silently rounding unsafe integers or high-precision decimal literals. Quote exact numeric identifiers or decimals as strings.

Status: implemented. Runtime: browser-or-local.

Bound bytes, nesting, row count and schema compilation; report loss and numeric precision.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "{\"ok\":true}"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/json.parse)

## json.schema — Validate JSON against a schema

Reject malformed arguments or deliverables before downstream use.

Status: implemented. Runtime: browser-or-local.

Bound bytes, nesting, row count and schema compilation; report loss and numeric precision.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "value": {},
    "schema": {
      "type": "object",
      "maxProperties": 2000
    }
  },
  "required": [
    "value",
    "schema"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "value": {
    "age": 2
  },
  "schema": {
    "type": "object",
    "properties": {
      "age": {
        "type": "integer"
      }
    },
    "required": [
      "age"
    ]
  }
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/json.schema)

## json.convert — Convert JSON, CSV, YAML and XML

Convert bounded JSON, CSV, YAML or XML to JSON, CSV or YAML. JSON and YAML inputs reject numeric precision loss; output reports format and spreadsheet-safety warnings.

Status: implemented. Runtime: browser-or-local.

Bound bytes, nesting, row count and schema compilation; report loss and numeric precision.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    },
    "from": {
      "type": "string",
      "enum": [
        "json",
        "csv",
        "yaml",
        "xml"
      ]
    },
    "to": {
      "type": "string",
      "enum": [
        "json",
        "csv",
        "yaml"
      ]
    }
  },
  "required": [
    "text",
    "from",
    "to"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "a,b\n1,2",
  "from": "csv",
  "to": "json"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/json.convert)

## json.diff — Compare JSON values

Inspect changes to configurations or model outputs.

Status: implemented. Runtime: browser-or-local.

Bound bytes, nesting, row count and schema compilation; report loss and numeric precision.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "before": {},
    "after": {}
  },
  "required": [
    "before",
    "after"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "before": {
    "a": 1
  },
  "after": {
    "a": 2
  }
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/json.diff)

## json.query — Query JSON with JSONPath

Read own object properties and array indices using bounded structural paths. Filters, expressions and inherited properties are unsupported.

Status: implemented. Runtime: browser-or-local.

Bound bytes, nesting, row count and schema compilation; report loss and numeric precision.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "value": {},
    "path": {
      "type": "string",
      "maxLength": 500
    }
  },
  "required": [
    "value",
    "path"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "value": {
    "items": [
      {
        "name": "A"
      }
    ]
  },
  "path": "$.items[0].name"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/json.query)

## json.repair — Repair malformed JSON with an edit log

Conservatively remove trailing commas outside JSON strings. Preserve string contents, reject numeric precision loss and return the candidate for review.

Status: implemented. Runtime: browser-or-local.

Bound bytes, nesting, row count and schema compilation; report loss and numeric precision.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "{\"a\":1,}"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/json.repair)

## json.types — Generate types from sample JSON

Infer a TypeScript declaration from one JSON sample. Empty arrays use unknown[]; unseen types and optional fields cannot be inferred.

Status: implemented. Runtime: browser-or-local.

Bound bytes, nesting, row count and schema compilation; report loss and numeric precision.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "value": {},
    "name": {
      "type": "string",
      "pattern": "^[A-Za-z][A-Za-z0-9_]{0,40}$"
    }
  },
  "required": [
    "value"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "value": {
    "name": "A",
    "count": 2
  }
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/json.types)

## data.profile — Profile CSV data

Understand a dataset before transforming it.

Status: implemented. Runtime: browser-or-local.

Bound bytes, nesting, row count and schema compilation; report loss and numeric precision.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "rows": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "maxProperties": 2000
      }
    }
  },
  "required": [
    "rows"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "rows": [
    {
      "age": 2
    },
    {
      "age": null
    }
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/data.profile)

## data.join — Join tabular datasets

Combine records across two exports with explicit keys.

Status: implemented. Runtime: browser-or-local.

Bound bytes, nesting, row count and schema compilation; report loss and numeric precision.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "left": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "maxProperties": 2000
      }
    },
    "right": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "maxProperties": 2000
      }
    },
    "leftKey": {
      "type": "string",
      "maxLength": 200000
    },
    "rightKey": {
      "type": "string",
      "maxLength": 200000
    },
    "type": {
      "type": "string",
      "enum": [
        "inner",
        "left"
      ]
    }
  },
  "required": [
    "left",
    "right",
    "leftKey",
    "rightKey"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "left": [
    {
      "id": 1
    }
  ],
  "right": [
    {
      "id": 1,
      "b": 2
    }
  ],
  "leftKey": "id",
  "rightKey": "id"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/data.join)

## data.pivot — Build a pivot table

Produce an auditable aggregation from raw rows.

Status: implemented. Runtime: browser-or-local.

Bound bytes, nesting, row count and schema compilation; report loss and numeric precision.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "rows": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "maxProperties": 2000
      }
    },
    "groupBy": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    },
    "valueKey": {
      "type": "string",
      "maxLength": 200000
    },
    "operation": {
      "type": "string",
      "enum": [
        "sum",
        "count",
        "mean"
      ]
    }
  },
  "required": [
    "rows",
    "groupBy",
    "operation"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "rows": [
    {
      "kind": "A",
      "value": 2
    }
  ],
  "groupBy": [
    "kind"
  ],
  "valueKey": "value",
  "operation": "sum"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/data.pivot)

## text.normalize — Normalize Unicode and whitespace

Prepare consistent text for matching across sources.

Status: implemented. Runtime: browser-or-local.

Specify Unicode, locale and truncation behavior; preserve source offsets where possible.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    },
    "form": {
      "type": "string",
      "enum": [
        "NFC",
        "NFD",
        "NFKC",
        "NFKD"
      ]
    },
    "whitespace": {
      "type": "boolean"
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": " café  "
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/text.normalize)

## text.diff — Compare text

Review an agent rewrite before accepting it.

Status: implemented. Runtime: browser-or-local.

Specify Unicode, locale and truncation behavior; preserve source offsets where possible.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "before": {
      "type": "string",
      "maxLength": 10000
    },
    "after": {
      "type": "string",
      "maxLength": 10000
    }
  },
  "required": [
    "before",
    "after"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "before": "one two",
  "after": "one three"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/text.diff)

## text.deduplicate — Deduplicate lines

Clean repeated logs or retrieved snippets.

Status: implemented. Runtime: browser-or-local.

Specify Unicode, locale and truncation behavior; preserve source offsets where possible.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    },
    "ignoreCase": {
      "type": "boolean"
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "A\nA\nB"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/text.deduplicate)

## text.slug — Generate a URL slug

Produce a stable slug for a page or record.

Status: implemented. Runtime: browser-or-local.

Specify Unicode, locale and truncation behavior; preserve source offsets where possible.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "Hello World!"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/text.slug)

## text.urls — Extract URLs

Collect referenced destinations for verification.

Status: implemented. Runtime: browser-or-local.

Specify Unicode, locale and truncation behavior; preserve source offsets where possible.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "Read https://example.com."
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/text.urls)

## text.html — Convert HTML to plain text

Read content without scripts or presentation markup.

Status: implemented. Runtime: browser-or-local.

Specify Unicode, locale and truncation behavior; preserve source offsets where possible.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "html": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "html"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "html": "<p>Hello</p><script>bad()</script>"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/text.html)

## text.markdown — Convert Markdown to sanitized HTML

Prepare a report for safe display.

Status: implemented. Runtime: browser-or-local.

Specify Unicode, locale and truncation behavior; preserve source offsets where possible.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "# Title\n\nHello"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/text.markdown)

## tokens.count — Count tokens with a named tokenizer

Prevent avoidable context overflow.

Status: implemented. Runtime: browser-or-local.

Specify Unicode, locale and truncation behavior; preserve source offsets where possible.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    },
    "encoding": {
      "type": "string",
      "enum": [
        "o200k_base",
        "cl100k_base"
      ]
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "Hello world"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/tokens.count)

## tokens.cost — Estimate inference cost

Compare a planned batch against a supplied price sheet.

Status: implemented. Runtime: browser-or-local.

Specify Unicode, locale and truncation behavior; preserve source offsets where possible.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "inputTokens": {
      "type": "number",
      "minimum": 0
    },
    "outputTokens": {
      "type": "number",
      "minimum": 0
    },
    "inputPerMillion": {
      "type": "number",
      "minimum": 0
    },
    "outputPerMillion": {
      "type": "number",
      "minimum": 0
    },
    "currency": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "inputTokens",
    "outputTokens",
    "inputPerMillion",
    "outputPerMillion"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "inputTokens": 1000,
  "outputTokens": 100,
  "inputPerMillion": 1,
  "outputPerMillion": 2
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/tokens.cost)

## context.pack — Pack context within a token budget

Pack exact JSONL within the chosen token budget, 200,000 serialized UTF-16 units and a complete 512 KiB UTF-8 result. Frames, escaping, IDs and annotations count toward mechanical caps; oversized items are omitted. Shorten or split omitted text/IDs. Inject serialized; reserve prompt/schema overhead separately.

Status: implemented. Runtime: browser-or-local.

Specify Unicode, locale and truncation behavior; preserve source offsets where possible.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "items": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "maxLength": 200000
          },
          "text": {
            "type": "string",
            "maxLength": 200000
          },
          "priority": {
            "type": "number"
          }
        },
        "required": [
          "id",
          "text"
        ],
        "additionalProperties": false
      }
    },
    "budget": {
      "type": "integer",
      "minimum": 1,
      "maximum": 50000
    },
    "encoding": {
      "type": "string",
      "enum": [
        "o200k_base",
        "cl100k_base"
      ]
    }
  },
  "required": [
    "items",
    "budget"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "items": [
    {
      "id": "source1",
      "text": "Evidence",
      "priority": 1
    }
  ],
  "budget": 100
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/context.pack)

## document.citations — Format supplied document citations

Create citation IDs from caller-supplied page, text and coordinate records; does not extract or verify document evidence.

Status: implemented. Runtime: browser-or-local.

Use tenant-scoped file handles, temporary storage and parser isolation; extraction is not evidence of truth.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "spans": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "maxProperties": 2000
      }
    }
  },
  "required": [
    "spans"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "spans": [
    {
      "page": 1,
      "text": "Evidence",
      "box": [
        0,
        0,
        20,
        10
      ]
    }
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/document.citations)

## file.checksum — Hash UTF-8 text

Compute a SHA-256/384/512 digest of supplied UTF-8 text. Binary files use the existing browser file utility.

Status: implemented. Runtime: browser-or-local.

Enforce decompression, pixel and output limits; reject traversal, links and active payloads.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    },
    "algorithm": {
      "type": "string",
      "enum": [
        "SHA-256",
        "SHA-384",
        "SHA-512"
      ]
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "hello"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/file.checksum)

## file.encoding — Decode bounded text bytes

Decode supplied base64 bytes using a selected text encoding; return UTF-8 text with strict decoding errors.

Status: implemented. Runtime: browser-or-local.

Enforce decompression, pixel and output limits; reject traversal, links and active payloads.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "base64": {
      "type": "string",
      "maxLength": 100000
    },
    "encoding": {
      "type": "string",
      "enum": [
        "utf-8",
        "windows-1252",
        "utf-16le",
        "utf-16be"
      ]
    }
  },
  "required": [
    "base64",
    "encoding"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "base64": "aGVsbG8=",
  "encoding": "utf-8"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/file.encoding)

## file.line_endings — Convert line endings

Prepare a file for a different platform.

Status: implemented. Runtime: browser-or-local.

Enforce decompression, pixel and output limits; reject traversal, links and active payloads.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    },
    "target": {
      "type": "string",
      "enum": [
        "lf",
        "crlf"
      ]
    }
  },
  "required": [
    "text",
    "target"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "a\r\nb",
  "target": "lf"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/file.line_endings)

## math.evaluate — Evaluate a bounded mathematical expression

Use calculation rather than generated arithmetic.

Status: implemented. Runtime: browser-or-local.

Declare units, rounding, timezone and clock source; separate estimates from authoritative values.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "expression": {
      "type": "string",
      "maxLength": 1000
    }
  },
  "required": [
    "expression"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "expression": "(2 + 3) * 4"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/math.evaluate)

## units.convert — Convert physical units

Prevent mixing incompatible measurement units.

Status: implemented. Runtime: browser-or-local.

Declare units, rounding, timezone and clock source; separate estimates from authoritative values.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "value": {
      "type": "number"
    },
    "from": {
      "type": "string",
      "enum": [
        "m",
        "cm",
        "mm",
        "km",
        "in",
        "ft",
        "kg",
        "g",
        "lb",
        "celsius",
        "fahrenheit",
        "kelvin"
      ]
    },
    "to": {
      "type": "string",
      "enum": [
        "m",
        "cm",
        "mm",
        "km",
        "in",
        "ft",
        "kg",
        "g",
        "lb",
        "celsius",
        "fahrenheit",
        "kelvin"
      ]
    }
  },
  "required": [
    "value",
    "from",
    "to"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "value": 1,
  "from": "m",
  "to": "cm"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/units.convert)

## statistics.describe — Compute descriptive statistics

Summarize a dataset with explicit assumptions.

Status: implemented. Runtime: browser-or-local.

Declare units, rounding, timezone and clock source; separate estimates from authoritative values.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "values": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "number"
      },
      "minItems": 1
    }
  },
  "required": [
    "values"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "values": [
    1,
    2,
    3
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/statistics.describe)

## statistics.interval — Calculate a confidence interval

Quantify uncertainty for a supported sampling model.

Status: implemented. Runtime: browser-or-local.

Declare units, rounding, timezone and clock source; separate estimates from authoritative values.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "mean": {
      "type": "number"
    },
    "knownPopulationSD": {
      "type": "number",
      "minimum": 0
    },
    "count": {
      "type": "integer",
      "minimum": 1,
      "maximum": 100000000
    },
    "confidence": {
      "type": "string",
      "enum": [
        "90",
        "95",
        "99"
      ]
    }
  },
  "required": [
    "mean",
    "knownPopulationSD",
    "count"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "mean": 10,
  "knownPopulationSD": 2,
  "count": 100,
  "confidence": "95"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/statistics.interval)

## date.difference — Calculate date differences

Determine elapsed time using clear calendar semantics.

Status: implemented. Runtime: browser-or-local.

Declare units, rounding, timezone and clock source; separate estimates from authoritative values.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "start": {
      "type": "string",
      "maxLength": 200000
    },
    "end": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "start",
    "end"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "start": "2026-01-01T00:00:00Z",
  "end": "2026-01-02T00:00:00Z"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/date.difference)

## date.business_days — Calculate business days

Estimate scheduling intervals with a named calendar.

Status: implemented. Runtime: browser-or-local.

Declare units, rounding, timezone and clock source; separate estimates from authoritative values.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "start": {
      "type": "string",
      "maxLength": 200000,
      "pattern": "^\\d{4}-\\d{2}-\\d{2}$"
    },
    "end": {
      "type": "string",
      "maxLength": 200000,
      "pattern": "^\\d{4}-\\d{2}-\\d{2}$"
    },
    "holidays": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000,
        "pattern": "^\\d{4}-\\d{2}-\\d{2}$"
      }
    }
  },
  "required": [
    "start",
    "end"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "start": "2026-01-01",
  "end": "2026-01-05",
  "holidays": [
    "2026-01-01"
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/date.business_days)

## date.timezone — Convert timezones

Prevent an agent from scheduling at the wrong local time.

Status: implemented. Runtime: browser-or-local.

Declare units, rounding, timezone and clock source; separate estimates from authoritative values.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "timestamp": {
      "type": "string",
      "maxLength": 200000
    },
    "zones": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    }
  },
  "required": [
    "timestamp",
    "zones"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "timestamp": "2026-01-01T00:00:00Z",
  "zones": [
    "America/Bogota",
    "UTC"
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/date.timezone)

## date.cron — Explain a cron schedule

Check the next occurrences before creating automation.

Status: implemented. Runtime: browser-or-local.

Declare units, rounding, timezone and clock source; separate estimates from authoritative values.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "expression": {
      "type": "string",
      "maxLength": 200
    },
    "zone": {
      "type": "string",
      "maxLength": 200000
    },
    "start": {
      "type": "string",
      "maxLength": 200000
    },
    "count": {
      "type": "integer",
      "minimum": 1,
      "maximum": 20
    }
  },
  "required": [
    "expression",
    "zone",
    "start"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "expression": "0 9 * * 1-5",
  "zone": "UTC",
  "start": "2026-01-01T00:00:00Z",
  "count": 3
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/date.cron)

## date.deadline — Calculate an agent deadline budget

Bound a multi-step run by a trusted clock.

Status: implemented. Runtime: browser-or-local.

Declare units, rounding, timezone and clock source; separate estimates from authoritative values.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "deadline": {
      "type": "string",
      "maxLength": 200000
    },
    "reserveMs": {
      "type": "integer",
      "minimum": 0,
      "maximum": 86400000
    }
  },
  "required": [
    "deadline"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "deadline": "2099-01-01T00:00:00Z",
  "reserveMs": 1000
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/date.deadline)

## math.verify — Verify arithmetic claims

Check supplied totals and formulas independently.

Status: implemented. Runtime: browser-or-local.

Declare units, rounding, timezone and clock source; separate estimates from authoritative values.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "claims": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "properties": {
          "terms": {
            "type": "array",
            "maxItems": 2000,
            "items": {
              "type": "number"
            },
            "minItems": 1
          },
          "total": {
            "type": "number"
          },
          "tolerance": {
            "type": "number",
            "minimum": 0
          }
        },
        "required": [
          "terms",
          "total"
        ],
        "additionalProperties": false
      }
    }
  },
  "required": [
    "claims"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "claims": [
    {
      "terms": [
        1,
        2
      ],
      "total": 3
    }
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/math.verify)

## privacy.detect — Detect supported sensitive-data patterns

Find known PII patterns before a model call.

Status: implemented. Runtime: browser-or-local.

Rule coverage is explicit; model scores are uncertain. Never log submitted secrets or retain reidentification maps by default.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    },
    "custom": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "Email a@example.com"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/privacy.detect)

## privacy.redact — Redact supported sensitive text

Prepare a safer prompt or exported log.

Status: implemented. Runtime: browser-or-local.

Rule coverage is explicit; model scores are uncertain. Never log submitted secrets or retain reidentification maps by default.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    },
    "custom": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "Email a@example.com"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/privacy.redact)

## privacy.mask — Mask structured sensitive values

Share a dataset while preserving useful record shape.

Status: implemented. Runtime: browser-or-local.

Rule coverage is explicit; model scores are uncertain. Never log submitted secrets or retain reidentification maps by default.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "value": {
      "type": "object",
      "maxProperties": 2000
    },
    "fields": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    },
    "replacement": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "value",
    "fields"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "value": {
    "email": "a@example.com"
  },
  "fields": [
    "email"
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/privacy.mask)

## privacy.transcript — Redact timestamped transcripts

Remove sensitive terms while preserving subtitle timings.

Status: implemented. Runtime: browser-or-local.

Rule coverage is explicit; model scores are uncertain. Never log submitted secrets or retain reidentification maps by default.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    },
    "custom": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "1\n00:00:01,000 --> 00:00:02,000\na@example.com"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/privacy.transcript)

## privacy.secrets — Scan for credential patterns

Block accidental transmission of known key formats.

Status: implemented. Runtime: browser-or-local.

Rule coverage is explicit; model scores are uncertain. Never log submitted secrets or retain reidentification maps by default.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "password=abcdefghijk"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/privacy.secrets)

## privacy.log_clean — Sanitize an agent log

Remove terminal/control formatting before scanning recognizable credentials and personal data. Rule-based redaction can miss unfamiliar formats; inspect cleaned logs before sharing.

Status: implemented. Runtime: browser-or-local.

Rule coverage is explicit; model scores are uncertain. Never log submitted secrets or retain reidentification maps by default.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "password=abcdefghijk\u001b[31m"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/privacy.log_clean)

## privacy.pseudonyms — Create dataset-scoped pseudonyms

Hash selected fields with a caller-provided confidential salt. This is pseudonymization, not anonymization or a server-issued tenant identity.

Status: implemented. Runtime: browser-or-local.

Rule coverage is explicit; model scores are uncertain. Never log submitted secrets or retain reidentification maps by default.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "records": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "maxProperties": 2000
      }
    },
    "fields": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    },
    "salt": {
      "type": "string",
      "maxLength": 200000,
      "minLength": 16
    }
  },
  "required": [
    "records",
    "fields",
    "salt"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "records": [
    {
      "email": "a@example.com"
    }
  ],
  "fields": [
    "email"
  ],
  "salt": "synthetic-dataset-salt"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/privacy.pseudonyms)

## privacy.egress — Evaluate a proposed data transfer

Check whether selected fields may leave a trust boundary.

Status: implemented. Runtime: browser-or-local.

Rule coverage is explicit; model scores are uncertain. Never log submitted secrets or retain reidentification maps by default.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "destination": {
      "type": "string",
      "maxLength": 200000
    },
    "labels": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    },
    "allowedDomains": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    },
    "forbiddenLabels": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    }
  },
  "required": [
    "destination",
    "labels",
    "allowedDomains",
    "forbiddenLabels"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "destination": "https://example.com",
  "labels": [
    "public"
  ],
  "allowedDomains": [
    "example.com"
  ],
  "forbiddenLabels": [
    "secret"
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/privacy.egress)

## privacy.minimize — Minimize a payload by policy

Send only fields a downstream task actually needs.

Status: implemented. Runtime: browser-or-local.

Rule coverage is explicit; model scores are uncertain. Never log submitted secrets or retain reidentification maps by default.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "value": {
      "type": "object",
      "maxProperties": 2000
    },
    "fields": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    }
  },
  "required": [
    "value",
    "fields"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "value": {
    "name": "A",
    "secret": "B"
  },
  "fields": [
    "name"
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/privacy.minimize)

## privacy.output_leak — Check an output for supplied canaries and secrets

Catch leakage before returning or publishing generated text.

Status: implemented. Runtime: browser-or-local.

Rule coverage is explicit; model scores are uncertain. Never log submitted secrets or retain reidentification maps by default.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    },
    "canaries": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    }
  },
  "required": [
    "text",
    "canaries"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "do not reveal marker",
  "canaries": [
    "marker"
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/privacy.output_leak)

## prompt.template — Render a literal prompt template

Create consistent prompts without template-code execution.

Status: implemented. Runtime: browser-or-local.

Heuristics cannot guarantee injection resistance. Enforce privileges outside the model and treat external text as untrusted.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "template": {
      "type": "string",
      "maxLength": 200000
    },
    "variables": {
      "type": "object",
      "maxProperties": 2000
    }
  },
  "required": [
    "template",
    "variables"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "template": "Hello {{name}}",
  "variables": {
    "name": "A"
  }
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/prompt.template)

## prompt.boundaries — Label trusted and untrusted prompt sections

Preserve origin and trust labels while assembling context.

Status: implemented. Runtime: browser-or-local.

Heuristics cannot guarantee injection resistance. Enforce privileges outside the model and treat external text as untrusted.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "sections": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "maxLength": 200000
          },
          "text": {
            "type": "string",
            "maxLength": 200000
          },
          "trust": {
            "type": "string",
            "enum": [
              "trusted",
              "untrusted"
            ]
          }
        },
        "required": [
          "id",
          "text",
          "trust"
        ],
        "additionalProperties": false
      }
    }
  },
  "required": [
    "sections"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "sections": [
    {
      "id": "web",
      "text": "External text",
      "trust": "untrusted"
    }
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/prompt.boundaries)

## prompt.injection_scan — Flag suspicious instruction patterns

Provide advisory evidence for indirect-injection review.

Status: implemented. Runtime: browser-or-local.

Heuristics cannot guarantee injection resistance. Enforce privileges outside the model and treat external text as untrusted.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "Ignore previous instructions"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/prompt.injection_scan)

## prompt.hidden_text — Find hidden or off-screen HTML instructions

Inspect content a model might see but users might miss.

Status: implemented. Runtime: browser-or-local.

Heuristics cannot guarantee injection resistance. Enforce privileges outside the model and treat external text as untrusted.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "html": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "html"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "html": "<span hidden>instructions</span>"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/prompt.hidden_text)

## prompt.unicode_risk — Inspect confusables and bidi controls

Expose text tricks in identifiers or instructions.

Status: implemented. Runtime: browser-or-local.

Heuristics cannot guarantee injection resistance. Enforce privileges outside the model and treat external text as untrusted.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "ab‮cd"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/prompt.unicode_risk)

## prompt.encoded_payload — Inspect bounded encoded text

Reveal common encoded payloads for review without executing them.

Status: implemented. Runtime: browser-or-local.

Heuristics cannot guarantee injection resistance. Enforce privileges outside the model and treat external text as untrusted.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 16000
    },
    "encoding": {
      "type": "string",
      "enum": [
        "base64",
        "percent"
      ]
    }
  },
  "required": [
    "text",
    "encoding"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "aGVsbG8=",
  "encoding": "base64"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/prompt.encoded_payload)

## prompt.tool_description — Lint a tool description for instruction-like content

Spot misleading or poisoned tool metadata.

Status: implemented. Runtime: browser-or-local.

Heuristics cannot guarantee injection resistance. Enforce privileges outside the model and treat external text as untrusted.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "description": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "description"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "description": "Ignore previous instructions"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/prompt.tool_description)

## prompt.manifest_diff — Compare versioned tool manifests

Detect unexpected schema, permission or description drift.

Status: implemented. Runtime: browser-or-local.

Heuristics cannot guarantee injection resistance. Enforce privileges outside the model and treat external text as untrusted.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "before": {
      "type": "object",
      "maxProperties": 2000
    },
    "after": {
      "type": "object",
      "maxProperties": 2000
    }
  },
  "required": [
    "before",
    "after"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "before": {
    "tools": []
  },
  "after": {
    "tools": [
      {
        "name": "read"
      }
    ]
  }
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/prompt.manifest_diff)

## prompt.model_rules — Check messages against provider-independent role rules

Catch malformed role ordering before dispatch.

Status: implemented. Runtime: browser-or-local.

Heuristics cannot guarantee injection resistance. Enforce privileges outside the model and treat external text as untrusted.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "messages": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "maxProperties": 2000
      }
    }
  },
  "required": [
    "messages"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "messages": [
    {
      "role": "user",
      "content": "Hi"
    }
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/prompt.model_rules)

## prompt.attack_fixture — Generate approved injection test fixtures

Exercise an agent against explicit attack categories.

Status: implemented. Runtime: browser-or-local.

Heuristics cannot guarantee injection resistance. Enforce privileges outside the model and treat external text as untrusted.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "categories": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    }
  },
  "required": [
    "categories"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "categories": [
    "override"
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/prompt.attack_fixture)

## policy.evaluate — Preview a proposed policy decision

Evaluate a caller-supplied tool/domain allowlist. Advisory only; this cannot grant a capability or override gateway authorization.

Status: implemented. Runtime: browser-or-local.

Policies and approvals come from a trusted control plane. Bind decisions to identity, action digest, resource, expiry and nonce.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "action": {
      "type": "object",
      "maxProperties": 2000
    },
    "allowedTools": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    },
    "allowedDomains": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    }
  },
  "required": [
    "action",
    "allowedTools"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "action": {
    "tool": "json.parse"
  },
  "allowedTools": [
    "json.parse"
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/policy.evaluate)

## policy.tool_allowlist — Check an allowed tool set

Keep an agent inside a declared capability boundary.

Status: implemented. Runtime: browser-or-local.

Policies and approvals come from a trusted control plane. Bind decisions to identity, action digest, resource, expiry and nonce.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "tool": {
      "type": "string",
      "maxLength": 200000
    },
    "allowed": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    }
  },
  "required": [
    "tool",
    "allowed"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "tool": "json.parse",
  "allowed": [
    "json.parse"
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/policy.tool_allowlist)

## policy.path_scope — Inspect lexical path scope

Check relative path prefixes and traversal syntax. Filesystem access requires independent realpath and symlink enforcement.

Status: implemented. Runtime: browser-or-local.

Policies and approvals come from a trusted control plane. Bind decisions to identity, action digest, resource, expiry and nonce.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "path": {
      "type": "string",
      "maxLength": 200000
    },
    "root": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "path",
    "root"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "path": "docs/readme.md",
  "root": "docs"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/policy.path_scope)

## policy.domain_scope — Validate an outbound domain against a grant

Restrict reads and writes to approved destinations.

Status: implemented. Runtime: browser-or-local.

Policies and approvals come from a trusted control plane. Bind decisions to identity, action digest, resource, expiry and nonce.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "maxLength": 200000
    },
    "domains": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    }
  },
  "required": [
    "url",
    "domains"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "url": "https://example.com/a",
  "domains": [
    "example.com"
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/policy.domain_scope)

## policy.side_effects — Classify declared action effects

Identify operations requiring write or destructive scopes.

Status: implemented. Runtime: browser-or-local.

Policies and approvals come from a trusted control plane. Bind decisions to identity, action digest, resource, expiry and nonce.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "effects": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    }
  },
  "required": [
    "effects"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "effects": [
    "network_read"
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/policy.side_effects)

## approval.prepare — Prepare a reviewable action request

Present exactly what a human is being asked to approve.

Status: implemented. Runtime: browser-or-local.

Policies and approvals come from a trusted control plane. Bind decisions to identity, action digest, resource, expiry and nonce.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "action": {
      "type": "object",
      "maxProperties": 2000
    },
    "preview": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "action",
    "preview"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "action": {
    "tool": "write",
    "path": "draft.txt"
  },
  "preview": "Create draft"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/approval.prepare)

## policy.dry_run — Preview a bounded write operation

Show changes and affected resources before committing.

Status: implemented. Runtime: browser-or-local.

Policies and approvals come from a trusted control plane. Bind decisions to identity, action digest, resource, expiry and nonce.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "before": {
      "type": "object",
      "maxProperties": 2000
    },
    "after": {
      "type": "object",
      "maxProperties": 2000
    }
  },
  "required": [
    "before",
    "after"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "before": {
    "a": 1
  },
  "after": {
    "a": 2
  }
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/policy.dry_run)

## run.retry — Compute a bounded retry schedule

Respect Retry-After and avoid retry storms.

Status: implemented. Runtime: browser-or-local.

Tenant isolation and atomic counters are required. These are execution services, not stateless calculation wrappers.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "attempt": {
      "type": "integer",
      "minimum": 0,
      "maximum": 20
    },
    "baseMs": {
      "type": "integer",
      "minimum": 1,
      "maximum": 60000
    },
    "maxMs": {
      "type": "integer",
      "minimum": 1,
      "maximum": 3600000
    },
    "retryAfterMs": {
      "type": "integer",
      "minimum": 0,
      "maximum": 3600000
    },
    "remainingMs": {
      "type": "integer",
      "minimum": 0,
      "maximum": 3600000
    }
  },
  "required": [
    "attempt",
    "remainingMs"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "attempt": 2,
  "remainingMs": 20000
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/run.retry)

## run.trace_validate — Validate a structured execution trace

Find malformed steps and missing outcomes.

Status: implemented. Runtime: browser-or-local.

Tenant isolation and atomic counters are required. These are execution services, not stateless calculation wrappers.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "steps": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "maxProperties": 2000
      }
    }
  },
  "required": [
    "steps"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "steps": [
    {
      "id": "s1",
      "tool": "json.parse",
      "status": "success"
    }
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/run.trace_validate)

## run.loop_detect — Detect repeated unproductive calls

Stop a run that keeps repeating equivalent actions.

Status: implemented. Runtime: browser-or-local.

Tenant isolation and atomic counters are required. These are execution services, not stateless calculation wrappers.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "calls": {
      "type": "array",
      "maxItems": 2000
    },
    "threshold": {
      "type": "integer",
      "minimum": 2,
      "maximum": 100
    }
  },
  "required": [
    "calls"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "calls": [
    {
      "tool": "read"
    },
    {
      "tool": "read"
    },
    {
      "tool": "read"
    }
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/run.loop_detect)

## run.error_normalize — Normalize tool errors for recovery

Make retries depend on explicit error semantics.

Status: implemented. Runtime: browser-or-local.

Tenant isolation and atomic counters are required. These are execution services, not stateless calculation wrappers.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "error": {
      "type": "object",
      "maxProperties": 2000
    }
  },
  "required": [
    "error"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "error": {
    "status": 429,
    "code": "RATE_LIMIT"
  }
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/run.error_normalize)

## api.openapi_lint — Lint an OpenAPI document

Check an integration contract before connecting.

Status: implemented. Runtime: browser-or-local.

Schema compatibility is tested by client profile; generated declarations do not prove server behavior.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "document": {
      "type": "object",
      "maxProperties": 2000
    }
  },
  "required": [
    "document"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "document": {
    "openapi": "3.0.3",
    "info": {
      "title": "Example",
      "version": "1"
    },
    "paths": {}
  }
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/api.openapi_lint)

## api.compatibility_diff — Detect breaking API contract changes

Review schema changes before upgrading an agent.

Status: implemented. Runtime: browser-or-local.

Schema compatibility is tested by client profile; generated declarations do not prove server behavior.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "before": {
      "type": "object",
      "maxProperties": 2000
    },
    "after": {
      "type": "object",
      "maxProperties": 2000
    }
  },
  "required": [
    "before",
    "after"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "before": {
    "paths": {
      "/old": {}
    }
  },
  "after": {
    "paths": {}
  }
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/api.compatibility_diff)

## api.curl_fetch — Convert cURL into a fetch example

Translate a known request into agent integration code.

Status: implemented. Runtime: browser-or-local.

Schema compatibility is tested by client profile; generated declarations do not prove server behavior.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "command": {
      "type": "string",
      "maxLength": 20000
    }
  },
  "required": [
    "command"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "command": "curl https://example.com"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/api.curl_fetch)

## api.schema_example — Generate a bounded schema example

Create plausible request shapes from a supported schema.

Status: implemented. Runtime: browser-or-local.

Schema compatibility is tested by client profile; generated declarations do not prove server behavior.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "schema": {
      "type": "object",
      "maxProperties": 2000
    }
  },
  "required": [
    "schema"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "schema": {
    "type": "object",
    "properties": {
      "id": {
        "type": "integer"
      }
    },
    "required": [
      "id"
    ]
  }
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/api.schema_example)

## api.request_validate — Validate a request against a contract

Catch wrong parameters before a real API request.

Status: implemented. Runtime: browser-or-local.

Schema compatibility is tested by client profile; generated declarations do not prove server behavior.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "value": {},
    "schema": {
      "type": "object",
      "maxProperties": 2000
    }
  },
  "required": [
    "value",
    "schema"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "value": {
    "id": 1
  },
  "schema": {
    "type": "object",
    "required": [
      "id"
    ]
  }
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/api.request_validate)

## api.response_validate — Validate an API response contract

Prevent malformed tool output from propagating.

Status: implemented. Runtime: browser-or-local.

Schema compatibility is tested by client profile; generated declarations do not prove server behavior.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "value": {},
    "schema": {
      "type": "object",
      "maxProperties": 2000
    }
  },
  "required": [
    "value",
    "schema"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "value": {
    "id": 1
  },
  "schema": {
    "type": "object",
    "required": [
      "id"
    ]
  }
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/api.response_validate)

## mcp.manifest_lint — Lint an MCP tool manifest

Check names, schemas, hints and descriptions.

Status: implemented. Runtime: browser-or-local.

Schema compatibility is tested by client profile; generated declarations do not prove server behavior.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "tools": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "maxProperties": 2000
      }
    }
  },
  "required": [
    "tools"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "tools": [
    {
      "name": "json_parse",
      "description": "Parse JSON",
      "inputSchema": {
        "type": "object"
      }
    }
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/mcp.manifest_lint)

## api.jwt_inspect — Inspect JWT structure without trusting it

Debug token shape while avoiding a false authentication verdict.

Status: implemented. Runtime: browser-or-local.

Schema compatibility is tested by client profile; generated declarations do not prove server behavior.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "token": {
      "type": "string",
      "maxLength": 16000
    }
  },
  "required": [
    "token"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "token": "eyJhbGciOiJub25lIn0.eyJzdWIiOiJleGFtcGxlIn0."
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/api.jwt_inspect)

## test.synthetic_records — Generate seeded synthetic records

Exercise import and validation flows.

Status: implemented. Runtime: browser-or-local.

Synthetic data is labelled. Seeds are reproducible; secrets and real personal data are excluded.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "template": {
      "type": "object",
      "maxProperties": 2000
    },
    "count": {
      "type": "integer",
      "minimum": 1,
      "maximum": 2000
    },
    "seed": {
      "type": "integer",
      "minimum": 1,
      "maximum": 2147483647
    }
  },
  "required": [
    "template",
    "count",
    "seed"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "template": {
    "name": "Test {{index}}",
    "score": "{{random}}"
  },
  "count": 3,
  "seed": 42
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/test.synthetic_records)

## test.jsonl_dataset — Validate chat JSONL dataset rows

Find invalid roles or content shapes before evaluation.

Status: implemented. Runtime: browser-or-local.

Synthetic data is labelled. Seeds are reproducible; secrets and real personal data are excluded.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "{\"messages\":[{\"role\":\"user\",\"content\":\"Test\"}]}"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/test.jsonl_dataset)

## test.regex_cases — Evaluate regex cases with a deadline

Check positive and negative examples without hanging.

Status: implemented. Runtime: browser-or-local.

Synthetic data is labelled. Seeds are reproducible; secrets and real personal data are excluded.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "pattern": {
      "type": "string",
      "maxLength": 200
    },
    "cases": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    }
  },
  "required": [
    "pattern",
    "cases"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "pattern": "^abc$",
  "cases": [
    "abc",
    "xyz"
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/test.regex_cases)

## test.schema_edges — Generate schema boundary cases

Test minimums, maximums, missing fields and wrong types.

Status: implemented. Runtime: browser-or-local.

Synthetic data is labelled. Seeds are reproducible; secrets and real personal data are excluded.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "schema": {
      "type": "object",
      "maxProperties": 2000
    }
  },
  "required": [
    "schema"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "schema": {
    "type": "integer",
    "minimum": 1,
    "maximum": 3
  }
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/test.schema_edges)

## test.property_cases — Check numeric-array properties

Check supplied numbers for nonnegative, sorted, unique or finite properties; no arbitrary property code is executed.

Status: implemented. Runtime: browser-or-local.

Synthetic data is labelled. Seeds are reproducible; secrets and real personal data are excluded.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "values": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "number"
      },
      "minItems": 1
    },
    "property": {
      "type": "string",
      "enum": [
        "nonnegative",
        "sorted",
        "unique",
        "finite"
      ]
    }
  },
  "required": [
    "values",
    "property"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "values": [
    1,
    2,
    2
  ],
  "property": "unique"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/test.property_cases)

## test.golden_compare — Compare a result to a golden fixture

Catch regression in deterministic tool behavior.

Status: implemented. Runtime: browser-or-local.

Synthetic data is labelled. Seeds are reproducible; secrets and real personal data are excluded.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "actual": {},
    "expected": {},
    "tolerance": {
      "type": "number",
      "minimum": 0
    }
  },
  "required": [
    "actual",
    "expected"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "actual": 1.001,
  "expected": 1,
  "tolerance": 0.01
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/test.golden_compare)

## test.fault_fixture — Describe a synthetic fault fixture

Build a bounded timeout/error/rate-limit fixture description; does not create a live mock service.

Status: implemented. Runtime: browser-or-local.

Synthetic data is labelled. Seeds are reproducible; secrets and real personal data are excluded.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "type": {
      "type": "string",
      "enum": [
        "timeout",
        "rate_limit",
        "server_error",
        "malformed"
      ]
    },
    "delayMs": {
      "type": "integer",
      "minimum": 0,
      "maximum": 60000
    }
  },
  "required": [
    "type"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "type": "rate_limit"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/test.fault_fixture)

## test.dataset_duplicates — Find exact and normalized dataset duplicates

Reduce leakage and repeated examples in eval sets.

Status: implemented. Runtime: browser-or-local.

Synthetic data is labelled. Seeds are reproducible; secrets and real personal data are excluded.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "records": {
      "type": "array",
      "maxItems": 2000
    }
  },
  "required": [
    "records"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "records": [
    {
      "a": 1
    },
    {
      "a": 1
    }
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/test.dataset_duplicates)

## test.split_leakage — Check train and test overlap

Find exact overlap and optional approximate candidates.

Status: implemented. Runtime: browser-or-local.

Synthetic data is labelled. Seeds are reproducible; secrets and real personal data are excluded.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "train": {
      "type": "array",
      "maxItems": 2000
    },
    "test": {
      "type": "array",
      "maxItems": 2000
    }
  },
  "required": [
    "train",
    "test"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "train": [
    "A",
    "B"
  ],
  "test": [
    "B",
    "C"
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/test.split_leakage)

## test.artifact_invariants — Compare supplied artifact measurements

Compare caller-supplied measurements with expected invariants. Does not parse or measure artifact bytes independently.

Status: implemented. Runtime: browser-or-local.

Synthetic data is labelled. Seeds are reproducible; secrets and real personal data are excluded.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "observed": {
      "type": "object",
      "maxProperties": 2000
    },
    "expected": {
      "type": "object",
      "maxProperties": 2000
    }
  },
  "required": [
    "observed",
    "expected"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "observed": {
    "mime": "application/pdf",
    "pages": 2
  },
  "expected": {
    "pages": 2
  }
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/test.artifact_invariants)

## eval.exact_match — Score exact and normalized answer matches

Compare caller-supplied actual and expected values for every case. Both fields are required; this deterministic comparison does not judge semantic correctness.

Status: implemented. Runtime: browser-or-local.

Keep deterministic scores separate from model judgments; show rubric, model version, evidence and uncertainty.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "cases": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "properties": {
          "actual": {},
          "expected": {}
        },
        "required": [
          "actual",
          "expected"
        ]
      }
    },
    "normalize": {
      "type": "boolean"
    }
  },
  "required": [
    "cases"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "cases": [
    {
      "actual": " A ",
      "expected": "a"
    }
  ],
  "normalize": true
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/eval.exact_match)

## eval.tool_choice — Score tool selection

Measure whether an agent picks the right capability.

Status: implemented. Runtime: browser-or-local.

Keep deterministic scores separate from model judgments; show rubric, model version, evidence and uncertainty.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "called": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    },
    "allowed": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    },
    "required": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    }
  },
  "required": [
    "called",
    "allowed"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "called": [
    "json.parse"
  ],
  "allowed": [
    "json.parse"
  ],
  "required": [
    "json.parse"
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/eval.tool_choice)

## eval.arguments — Score tool arguments

Measure correctness of selected parameters.

Status: implemented. Runtime: browser-or-local.

Keep deterministic scores separate from model judgments; show rubric, model version, evidence and uncertainty.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "actual": {
      "type": "object",
      "maxProperties": 2000
    },
    "expected": {
      "type": "object",
      "maxProperties": 2000
    }
  },
  "required": [
    "actual",
    "expected"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "actual": {
    "x": 2
  },
  "expected": {
    "x": 1
  }
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/eval.arguments)

## eval.trajectory — Score workflow completion constraints

Find skipped steps and forbidden actions.

Status: implemented. Runtime: browser-or-local.

Keep deterministic scores separate from model judgments; show rubric, model version, evidence and uncertainty.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "steps": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    },
    "required": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    },
    "forbidden": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    }
  },
  "required": [
    "steps",
    "required"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "steps": [
    "read",
    "validate"
  ],
  "required": [
    "read",
    "validate"
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/eval.trajectory)

## eval.refusal — Evaluate refusal and over-refusal

Check safe rejection and successful benign handling.

Status: implemented. Runtime: browser-or-local.

Keep deterministic scores separate from model judgments; show rubric, model version, evidence and uncertainty.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "cases": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "maxProperties": 2000
      }
    }
  },
  "required": [
    "cases"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "cases": [
    {
      "shouldRefuse": true,
      "didRefuse": true
    }
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/eval.refusal)

## eval.injection_resilience — Score approved injection tests

Measure failures against an explicit threat suite.

Status: implemented. Runtime: browser-or-local.

Keep deterministic scores separate from model judgments; show rubric, model version, evidence and uncertainty.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "cases": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "maxProperties": 2000
      }
    }
  },
  "required": [
    "cases"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "cases": [
    {
      "boundaryViolated": false
    }
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/eval.injection_resilience)

## eval.paired_runs — Compare two agent configurations

Use matched cases to compare cost and success rates.

Status: implemented. Runtime: browser-or-local.

Keep deterministic scores separate from model judgments; show rubric, model version, evidence and uncertainty.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "pairs": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "maxProperties": 2000
      }
    }
  },
  "required": [
    "pairs"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "pairs": [
    {
      "before": 0.5,
      "after": 0.8
    }
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/eval.paired_runs)

## eval.report — Build a reproducible evaluation report

Share results with fixtures, versions and limitations.

Status: implemented. Runtime: browser-or-local.

Keep deterministic scores separate from model judgments; show rubric, model version, evidence and uncertainty.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "metadata": {
      "type": "object",
      "maxProperties": 2000
    },
    "scores": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "maxProperties": 2000
      }
    }
  },
  "required": [
    "metadata",
    "scores"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "metadata": {
    "version": "1"
  },
  "scores": [
    {
      "passed": true
    }
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/eval.report)

## rag.chunk — Split text into bounded chunks

Prepare a document for retrieval with stable offsets.

Status: implemented. Runtime: browser-or-local.

Source boundaries and tenant filtering are mandatory. Similarity does not establish truth or entailment.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    },
    "size": {
      "type": "integer",
      "minimum": 100,
      "maximum": 10000
    },
    "overlap": {
      "type": "integer",
      "minimum": 0,
      "maximum": 9999
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "Some evidence",
  "size": 100,
  "overlap": 10
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/rag.chunk)

## rag.semantic_compare — Compare supplied embedding vectors

Compute cosine similarity of supplied nonzero vectors from a common model. Reject zero vectors; does not generate embeddings or establish entailment.

Status: implemented. Runtime: browser-or-local.

Source boundaries and tenant filtering are mandatory. Similarity does not establish truth or entailment.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "left": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "number"
      },
      "minItems": 1
    },
    "right": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "number"
      },
      "minItems": 1
    }
  },
  "required": [
    "left",
    "right"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "left": [
    1,
    0
  ],
  "right": [
    1,
    1
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/rag.semantic_compare)

## rag.keyphrases — Extract frequency-based keyphrases

Create lightweight retrieval hints from supplied text.

Status: implemented. Runtime: browser-or-local.

Source boundaries and tenant filtering are mandatory. Similarity does not establish truth or entailment.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    },
    "count": {
      "type": "integer",
      "minimum": 1,
      "maximum": 100
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "agent tools agent testing"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/rag.keyphrases)

## rag.retrieve — Search supplied source records

Rank caller-supplied sources by lexical query overlap. No persistent collection, vector database or cross-user data access.

Status: implemented. Runtime: browser-or-local.

Source boundaries and tenant filtering are mandatory. Similarity does not establish truth or entailment.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "query": {
      "type": "string",
      "maxLength": 200000
    },
    "sources": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "maxProperties": 2000
      }
    },
    "count": {
      "type": "integer",
      "minimum": 1,
      "maximum": 100
    }
  },
  "required": [
    "query",
    "sources"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "query": "agent",
  "sources": [
    {
      "id": "1",
      "text": "agent tools"
    }
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/rag.retrieve)

## rag.rerank — Rerank candidates by lexical overlap

Sort supplied candidates using query-term overlap. This bounded profile uses no neural reranking model.

Status: implemented. Runtime: browser-or-local.

Source boundaries and tenant filtering are mandatory. Similarity does not establish truth or entailment.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "query": {
      "type": "string",
      "maxLength": 200000
    },
    "candidates": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "maxProperties": 2000
      }
    }
  },
  "required": [
    "query",
    "candidates"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "query": "agent",
  "candidates": [
    {
      "id": "1",
      "text": "agent tools"
    }
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/rag.rerank)

## rag.citation_check — Check that cited passages exist

Catch missing sources and fabricated quotations.

Status: implemented. Runtime: browser-or-local.

Source boundaries and tenant filtering are mandatory. Similarity does not establish truth or entailment.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "citations": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "properties": {
          "sourceId": {
            "type": "string",
            "maxLength": 200000,
            "minLength": 1
          },
          "quote": {
            "type": "string",
            "maxLength": 200000,
            "minLength": 1,
            "pattern": "\\S"
          }
        },
        "required": [
          "sourceId",
          "quote"
        ]
      }
    },
    "sources": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "maxLength": 200000,
            "minLength": 1
          },
          "text": {
            "type": "string",
            "maxLength": 200000
          }
        },
        "required": [
          "id",
          "text"
        ]
      }
    }
  },
  "required": [
    "citations",
    "sources"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "citations": [
    {
      "sourceId": "1",
      "quote": "evidence"
    }
  ],
  "sources": [
    {
      "id": "1",
      "text": "Some evidence"
    }
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/rag.citation_check)

## rag.coverage — Measure source coverage for listed claims

Expose claims that have no linked evidence.

Status: implemented. Runtime: browser-or-local.

Source boundaries and tenant filtering are mandatory. Similarity does not establish truth or entailment.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "claims": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "maxProperties": 2000
      }
    },
    "sourceIds": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    }
  },
  "required": [
    "claims",
    "sourceIds"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "claims": [
    {
      "id": "1",
      "sources": [
        "s1"
      ]
    }
  ],
  "sourceIds": [
    "s1"
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/rag.coverage)

## rag.freshness — Check source age against a task policy

Avoid relying on stale snapshots for current tasks.

Status: implemented. Runtime: browser-or-local.

Source boundaries and tenant filtering are mandatory. Similarity does not establish truth or entailment.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "sources": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "maxProperties": 2000
      }
    },
    "maxAgeHours": {
      "type": "number",
      "minimum": 0,
      "maximum": 876000
    }
  },
  "required": [
    "sources",
    "maxAgeHours"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "sources": [
    {
      "id": "1",
      "observedAt": "2026-01-01T00:00:00Z"
    }
  ],
  "maxAgeHours": 24
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/rag.freshness)

## rag.source_dedupe — Deduplicate retrieved sources

Avoid counting mirrors as independent evidence.

Status: implemented. Runtime: browser-or-local.

Source boundaries and tenant filtering are mandatory. Similarity does not establish truth or entailment.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "sources": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "maxProperties": 2000
      }
    }
  },
  "required": [
    "sources"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "sources": [
    {
      "id": "1",
      "hash": "abc"
    },
    {
      "id": "2",
      "hash": "abc"
    }
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/rag.source_dedupe)

## seo.robots — Evaluate robots rules for a named crawler

Determine permitted public content access.

Status: implemented. Runtime: browser-or-local.

Only crawl authorized public pages within budgets. Metadata checks do not promise rankings or agent adoption.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    },
    "path": {
      "type": "string",
      "maxLength": 200000
    },
    "userAgent": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "text",
    "path",
    "userAgent"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "User-agent: *\nDisallow: /private",
  "path": "/private/a",
  "userAgent": "ExampleBot"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/seo.robots)

## seo.sitemap — Inspect sitemap URLs

Check crawlable canonical page coverage.

Status: implemented. Runtime: browser-or-local.

Only crawl authorized public pages within budgets. Metadata checks do not promise rankings or agent adoption.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "xml": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "xml"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "xml": "<urlset><url><loc>https://example.com</loc></url></urlset>"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/seo.sitemap)

## seo.meta — Validate page metadata

Check titles, descriptions and canonical consistency.

Status: implemented. Runtime: browser-or-local.

Only crawl authorized public pages within budgets. Metadata checks do not promise rankings or agent adoption.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "html": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "html"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "html": "<title>Example</title>"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/seo.meta)

## seo.hreflang — Audit reciprocal hreflang

Find incorrect locale references and missing reciprocity.

Status: implemented. Runtime: browser-or-local.

Only crawl authorized public pages within budgets. Metadata checks do not promise rankings or agent adoption.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "pages": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "maxProperties": 2000
      }
    }
  },
  "required": [
    "pages"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "pages": [
    {
      "url": "https://example.com/en",
      "alternates": {
        "en": "https://example.com/en",
        "fr": "https://example.com/fr"
      }
    }
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/seo.hreflang)

## seo.structured_data — Inspect JSON-LD blocks

Parse supplied HTML JSON-LD blocks and inspect context presence. Full vocabulary and visible-content validation are outside this profile.

Status: implemented. Runtime: browser-or-local.

Only crawl authorized public pages within budgets. Metadata checks do not promise rankings or agent adoption.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "html": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "html"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "html": "<script type=\"application/ld+json\">{\"@context\":\"https://schema.org\",\"@type\":\"WebPage\"}</script>"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/seo.structured_data)

## seo.llms_lint — Lint llms.txt and linked Markdown

Check concise discovery guidance and broken documentation links.

Status: implemented. Runtime: browser-or-local.

Only crawl authorized public pages within budgets. Metadata checks do not promise rankings or agent adoption.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "# Example\n\n> Agent tools\n\n## Tools\n- [Docs](https://example.com/agents)"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/seo.llms_lint)

## seo.utm — Build campaign tracking URLs

Measure an authorized human handoff campaign.

Status: implemented. Runtime: browser-or-local.

Only crawl authorized public pages within budgets. Metadata checks do not promise rankings or agent adoption.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "maxLength": 200000
    },
    "source": {
      "type": "string",
      "maxLength": 200000
    },
    "medium": {
      "type": "string",
      "maxLength": 200000
    },
    "campaign": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "url",
    "source",
    "medium",
    "campaign"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "url": "https://example.com",
  "source": "agent",
  "medium": "referral",
  "campaign": "tools"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/seo.utm)

## seo.sitemap_build — Generate canonical sitemap content

Prepare a sitemap from an approved route list.

Status: implemented. Runtime: browser-or-local.

Only crawl authorized public pages within budgets. Metadata checks do not promise rankings or agent adoption.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "urls": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    }
  },
  "required": [
    "urls"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "urls": [
    "https://example.com/agents"
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/seo.sitemap_build)

## a11y.contrast — Check color contrast

Verify text and background color combinations.

Status: implemented. Runtime: browser-or-local.

Static checks do not prove full accessibility; test keyboard use and assistive technology separately.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "foreground": {
      "type": "string",
      "maxLength": 200000
    },
    "background": {
      "type": "string",
      "maxLength": 200000
    },
    "largeText": {
      "type": "boolean"
    }
  },
  "required": [
    "foreground",
    "background"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "foreground": "#000000",
  "background": "#ffffff"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/a11y.contrast)

## a11y.headings — Inspect HTML heading order

Review page structure before publishing.

Status: implemented. Runtime: browser-or-local.

Static checks do not prove full accessibility; test keyboard use and assistive technology separately.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "html": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "html"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "html": "<h1>Title</h1><h3>Subsection</h3>"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/a11y.headings)

## a11y.labels — Check form label associations

Catch unlabelled inputs in generated interfaces.

Status: implemented. Runtime: browser-or-local.

Static checks do not prove full accessibility; test keyboard use and assistive technology separately.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "html": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "html"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "html": "<label for=\"x\">Name</label><input id=\"x\">"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/a11y.labels)

## a11y.table — Generate a semantically labelled table

Publish data with headers and a caption.

Status: implemented. Runtime: browser-or-local.

Static checks do not prove full accessibility; test keyboard use and assistive technology separately.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "caption": {
      "type": "string",
      "maxLength": 200000
    },
    "headers": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    },
    "rows": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "array",
        "maxItems": 2000
      }
    }
  },
  "required": [
    "caption",
    "headers",
    "rows"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "caption": "Results",
  "headers": [
    "Tool",
    "Status"
  ],
  "rows": [
    [
      "JSON",
      "Ready"
    ]
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/a11y.table)

## a11y.palette — Suggest high-contrast palette fallbacks

Measure palette contrast and suggest black or white when a target is missed. Report whether the target is met or attainable; does not optimize hue or preserve brand colors.

Status: implemented. Runtime: browser-or-local.

Static checks do not prove full accessibility; test keyboard use and assistive technology separately.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "background": {
      "type": "string",
      "maxLength": 200000
    },
    "colors": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    },
    "target": {
      "type": "number",
      "minimum": 1,
      "maximum": 21
    }
  },
  "required": [
    "background",
    "colors"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "background": "#ffffff",
  "colors": [
    "#aaaaaa"
  ],
  "target": 4.5
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/a11y.palette)

## a11y.static_audit — Run a bounded static accessibility audit

Catch machine-detectable issues in an authorized page.

Status: implemented. Runtime: browser-or-local.

Static checks do not prove full accessibility; test keyboard use and assistive technology separately.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "html": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "html"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "html": "<html><img src=\"x\"></html>"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/a11y.static_audit)

## a11y.keyboard_trace — Audit a recorded keyboard flow

Find focus traps and unreachable required controls.

Status: implemented. Runtime: browser-or-local.

Static checks do not prove full accessibility; test keyboard use and assistive technology separately.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "events": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "maxProperties": 2000
      }
    }
  },
  "required": [
    "events"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "events": [
    {
      "key": "Tab",
      "focusId": "a"
    },
    {
      "key": "Tab",
      "focusId": "a"
    }
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/a11y.keyboard_trace)

## publish.link_integrity — Validate an artifact link bundle

Ensure handoff links are scoped and unexpired.

Status: implemented. Runtime: browser-or-local.

Static checks do not prove full accessibility; test keyboard use and assistive technology separately.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "html": {
      "type": "string",
      "maxLength": 200000
    },
    "knownUrls": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    }
  },
  "required": [
    "html",
    "knownUrls"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "html": "<a href=\"/agents\">Agents</a>",
  "knownUrls": [
    "/agents"
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/publish.link_integrity)

## publish.bundle — Prepare a text bundle manifest

Validate portable relative file names, reject UNC/device/stream paths and ambiguous duplicates, then return supplied text files in a reviewable manifest. Creates no ZIP or filesystem artifacts.

Status: implemented. Runtime: browser-or-local.

Static checks do not prove full accessibility; test keyboard use and assistive technology separately.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "files": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "properties": {
          "name": {
            "type": "string",
            "maxLength": 200000,
            "minLength": 1
          },
          "text": {
            "type": "string",
            "maxLength": 200000
          }
        },
        "required": [
          "name",
          "text"
        ],
        "additionalProperties": false
      }
    }
  },
  "required": [
    "files"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "files": [
    {
      "name": "report.md",
      "text": "# Report"
    }
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/publish.bundle)

## dependency.semver — Test a semantic version range

Check whether a proposed dependency satisfies a range.

Status: implemented. Runtime: browser-or-local.

Inventory and advisories need observation dates; findings require reachability triage. No arbitrary scanning of third-party systems.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "version": {
      "type": "string",
      "maxLength": 200000
    },
    "range": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "version",
    "range"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "version": "1.2.3",
  "range": "^1.0.0"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/dependency.semver)

## security.csp — Inspect a Content Security Policy

Inspect a supplied CSP for broad sources and duplicate directives. The first occurrence of each directive wins; this bounded check does not simulate browser enforcement.

Status: implemented. Runtime: browser-or-local.

Inventory and advisories need observation dates; findings require reachability triage. No arbitrary scanning of third-party systems.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "policy": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "policy"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "policy": "default-src 'self'; object-src 'none'"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/security.csp)

## dependency.lock_diff — Compare dependency lockfiles

Audit package additions and version changes.

Status: implemented. Runtime: browser-or-local.

Inventory and advisories need observation dates; findings require reachability triage. No arbitrary scanning of third-party systems.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "before": {
      "type": "object",
      "maxProperties": 2000
    },
    "after": {
      "type": "object",
      "maxProperties": 2000
    }
  },
  "required": [
    "before",
    "after"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "before": {
    "packages": {
      "a": "1"
    }
  },
  "after": {
    "packages": {
      "a": "2"
    }
  }
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/dependency.lock_diff)

## dependency.sbom — Generate an inventory SBOM

Create an auditable package inventory.

Status: implemented. Runtime: browser-or-local.

Inventory and advisories need observation dates; findings require reachability triage. No arbitrary scanning of third-party systems.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "packages": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "maxProperties": 2000
      }
    },
    "name": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "packages"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "packages": [
    {
      "name": "example",
      "version": "1.0.0",
      "license": "MIT"
    }
  ],
  "name": "App"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/dependency.sbom)

## dependency.licenses — Inspect declared license allowlists

Compare caller-declared license identifiers with an exact allowlist; does not resolve SPDX expressions or provide legal advice.

Status: implemented. Runtime: browser-or-local.

Inventory and advisories need observation dates; findings require reachability triage. No arbitrary scanning of third-party systems.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "packages": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "maxProperties": 2000
      }
    },
    "allowed": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    }
  },
  "required": [
    "packages",
    "allowed"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "packages": [
    {
      "name": "example",
      "license": "MIT"
    }
  ],
  "allowed": [
    "MIT"
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/dependency.licenses)

## security.sri_verify — Verify subresource integrity

Confirm a downloaded script matches a supplied digest.

Status: implemented. Runtime: browser-or-local.

Inventory and advisories need observation dates; findings require reachability triage. No arbitrary scanning of third-party systems.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    },
    "integrity": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "text",
    "integrity"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "hello",
  "integrity": "sha256-example"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/security.sri_verify)

## security.sarif — Normalize static-analysis findings

Consume findings from supported scanners consistently.

Status: implemented. Runtime: browser-or-local.

Inventory and advisories need observation dates; findings require reachability triage. No arbitrary scanning of third-party systems.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "findings": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "maxProperties": 2000
      }
    },
    "toolName": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "findings"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "findings": [
    {
      "ruleId": "example",
      "message": "Review"
    }
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/security.sarif)

## security.diff_scan — Scan a supplied code diff for configured risks

Flag credential patterns and risky code constructs.

Status: implemented. Runtime: browser-or-local.

Inventory and advisories need observation dates; findings require reachability triage. No arbitrary scanning of third-party systems.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "+password=abcdefghijk"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/security.diff_scan)

## media.subtitle_convert — Convert subtitle formats

Convert validated plain SRT/WebVTT cues. Reject malformed input and warn that comments, cue settings and identifiers are omitted.

Status: implemented. Runtime: browser-or-local.

Bound codec time, memory and media duration; redact by verified regions; model output is a draft.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    },
    "format": {
      "type": "string",
      "enum": [
        "srt",
        "vtt"
      ]
    }
  },
  "required": [
    "text",
    "format"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "1\n00:00:01,000 --> 00:00:02,000\nHello",
  "format": "vtt"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/media.subtitle_convert)

## media.subtitle_validate — Validate subtitle timestamps

Validate 1–2,000 plain SRT/WebVTT cues with format-specific millisecond timestamps and nonempty text. Report all later cues overlapping earlier cues; style/region blocks are unsupported.

Status: implemented. Runtime: browser-or-local.

Bound codec time, memory and media duration; redact by verified regions; model output is a draft.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "1\n00:00:01,000 --> 00:00:02,000\nHello"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/media.subtitle_validate)

## media.subtitle_shift — Shift subtitle timestamps

Shift validated plain subtitle cues by a whole-millisecond offset. Preserve cue durations and warn that comments, cue settings and identifiers are omitted.

Status: implemented. Runtime: browser-or-local.

Bound codec time, memory and media duration; redact by verified regions; model output is a draft.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 200000
    },
    "seconds": {
      "type": "number",
      "minimum": -86400,
      "maximum": 86400
    }
  },
  "required": [
    "text",
    "seconds"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "text": "1\n00:00:01,000 --> 00:00:02,000\nHello",
  "seconds": 1
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/media.subtitle_shift)

## workflow.validate — Validate a bounded workflow graph

Detect cycles, unsupported operations and missing bindings.

Status: implemented. Runtime: browser-or-local.

Connector credentials live outside model context. External writes use least-privilege grants and explicit human authorization.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "steps": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "maxProperties": 2000
      }
    }
  },
  "required": [
    "steps"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "steps": [
    {
      "id": "read",
      "dependsOn": []
    },
    {
      "id": "validate",
      "dependsOn": [
        "read"
      ]
    }
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/workflow.validate)

## workflow.plan — Preview a typed workflow

Check dependencies and budgets before execution.

Status: implemented. Runtime: browser-or-local.

Connector credentials live outside model context. External writes use least-privilege grants and explicit human authorization.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "steps": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "object",
        "maxProperties": 2000
      }
    }
  },
  "required": [
    "steps"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "steps": [
    {
      "id": "read",
      "dependsOn": []
    },
    {
      "id": "validate",
      "dependsOn": [
        "read"
      ]
    }
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/workflow.plan)

## workflow.batch — Partition items into bounded batches

Group supplied items into batches for a caller-controlled workflow. This planning tool executes no batch operations.

Status: implemented. Runtime: browser-or-local.

Connector credentials live outside model context. External writes use least-privilege grants and explicit human authorization.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "items": {
      "type": "array",
      "maxItems": 2000
    },
    "batchSize": {
      "type": "integer",
      "minimum": 1,
      "maximum": 100
    }
  },
  "required": [
    "items",
    "batchSize"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "items": [
    1,
    2,
    3
  ],
  "batchSize": 2
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/workflow.batch)

## workflow.resume — Plan remaining workflow steps

Remove caller-labelled completed steps from a supplied plan. Does not persist or resume jobs; recheck grants before execution.

Status: implemented. Runtime: browser-or-local.

Connector credentials live outside model context. External writes use least-privilege grants and explicit human authorization.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "steps": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    },
    "completed": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    }
  },
  "required": [
    "steps",
    "completed"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "steps": [
    "read",
    "validate"
  ],
  "completed": [
    "read"
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/workflow.resume)

## integration.webhook_prepare — Prepare a reviewable webhook delivery

Show destination and payload before an authorized write.

Status: implemented. Runtime: browser-or-local.

Connector credentials live outside model context. External writes use least-privilege grants and explicit human authorization.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "maxLength": 200000
    },
    "payload": {
      "type": "object",
      "maxProperties": 2000
    }
  },
  "required": [
    "url",
    "payload"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "url": "https://example.com/webhook",
  "payload": {
    "event": "test"
  }
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/integration.webhook_prepare)

## integration.email_draft — Build a structured email draft

Prepare recipients, subject and body for human review.

Status: implemented. Runtime: browser-or-local.

Connector credentials live outside model context. External writes use least-privilege grants and explicit human authorization.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "to": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    },
    "subject": {
      "type": "string",
      "maxLength": 500
    },
    "body": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "to",
    "subject",
    "body"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "to": [
    "test@example.com"
  ],
  "subject": "Draft",
  "body": "Hello"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/integration.email_draft)

## integration.calendar_draft — Build a calendar-event draft

Resolve timezone and duration before a handoff.

Status: implemented. Runtime: browser-or-local.

Connector credentials live outside model context. External writes use least-privilege grants and explicit human authorization.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "title": {
      "type": "string",
      "maxLength": 200000
    },
    "start": {
      "type": "string",
      "maxLength": 200000
    },
    "end": {
      "type": "string",
      "maxLength": 200000
    },
    "zone": {
      "type": "string",
      "maxLength": 200000
    }
  },
  "required": [
    "title",
    "start",
    "end",
    "zone"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "title": "Meeting",
  "start": "2026-10-05T09:00:00-05:00",
  "end": "2026-10-05T10:00:00-05:00",
  "zone": "America/Bogota"
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/integration.calendar_draft)

## integration.connector_scopes — Compare supplied connector scope lists

Compare caller-supplied granted and required scopes. Does not authenticate, connect to, or independently inspect an external account.

Status: implemented. Runtime: browser-or-local.

Connector credentials live outside model context. External writes use least-privilege grants and explicit human authorization.

Input schema:
```json
{
  "type": "object",
  "properties": {
    "granted": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    },
    "required": {
      "type": "array",
      "maxItems": 2000,
      "items": {
        "type": "string",
        "maxLength": 200000
      }
    }
  },
  "required": [
    "granted",
    "required"
  ],
  "additionalProperties": false
}
```

Example:
```json
{
  "granted": [
    "read"
  ],
  "required": [
    "read",
    "write"
  ]
}
```

[Human documentation](https://www.toolcabana.com/agents/tools/integration.connector_scopes)
