Agent tools
Named tools the cloud agent calls on your machine — files, search, shell, git, web, MCP — with your permission.
The agent is not a chat overlay. It calls tools. You see the trail in the transcript. Ask, Allow safe, and Allow all decide what actually runs. Plan and Ask modes block mutating tools.
Files and edits
- Read — open a file (offset/limit for large files; jpeg/png/gif/webp images)
- Write — create or overwrite
- StrReplace — exact in-place patch
- ApplyPatch — structured patch envelope
- Delete — remove a file (recycle bin unless permanent)
- EditNotebook — Jupyter cells
Search
- Grep — ripgrep over the workspace
- Glob — find files by pattern
- Ls — list a directory
- SemanticSearch — search by meaning, not exact text
Shell, git, and diagnostics
- Shell — stateful PTY session (ConPTY on Windows, Unix PTY elsewhere). Await waits on long jobs.
- Git — status, log, diff, stage, commit, and push when allowed
- ReadLints — LSP / diagnostics
- TodoWrite / ReadTodos — structured task list for a run
- SwitchMode / CreatePlan — mode changes and plan artifacts
Web, MCP, and GUI
- WebSearch / WebFetch — public pages
- GetMcpTools / CallDynamicTool — servers you wired in mcp.json
- ComputerUse — GUI actions, strongest on Windows
Task
Task launches a local subagent. Types: explore, shell, generalPurpose, debug, browser-use, computerUse, eyeban-guide, plus custom agents under .eyeban/agents. See Subagents.
Guardrails
Sandbox Off / Soft / Restricted wraps Shell. Nothing is silent. There is no cloud VM agent and no plugin store.