Safety: A Safety Tag Attached to Every Contract
The Tool interface includes several methods specifically for permission and safety decisions. They are the connection point between the tool system and the permission system (see Section B: Permissions & Security):
| Method | Return value | Who asks this question |
|---|---|---|
isReadOnly(input) | boolean | Permission system: read-only operations can bypass some restrictions |
isDestructive(input) | boolean | Permission system: irreversible operations need stricter confirmation |
isConcurrencySafe(input) | boolean | Agent Loop: decides whether this tool can run concurrently with others |
checkPermissions(input, context) | PermissionResult | Permission system: the tool's own dedicated permission check logic |
validateInput(input, context) | ValidationResult | Agent Loop: input validity check before execution |
The relationship between checkPermissions and generic permission rules: generic rules check first (configs like Bash(git *)), then the tool's own checkPermissions runs tool-specific checks. Both gates must pass before execution.