Ecosystem Tools
A static snapshot of the canonical tool names the EEM agent registers at startup. Names use snake_case (git_diff, prometheus_query, psql_query) and pass verbatim to tools/call. Authoritative source is EEMCanonicalToolNames.swift.
Overview
Tools register as a single set from
ExecToolsBundle.allTools(). There is no per-bundle
enrollment surface; capability gating is per-agent and per-tool,
not per-bundle. For the live runtime list, call
eem_list_tools; to resolve a specific endpoint, call
eem_resolve_endpoint.
Approval-gated and destructive tools are flagged inline. The
authoritative flags live in
EEMCanonicalToolDescriptors; consult that source
before relying on annotations here.
Last verified: 2026-05-20 against
EEMCanonicalToolNames.expected (217 tools).
Git
git_branch_create, Create a branchgit_branch_list, List branchesgit_diff, Show working tree diffgit_log, Show commit historygit_merge, Merge a branchgit_tag_list, List tags
GitHub
gh_pr_create, Create a pull requestgh_pr_list, List pull requests
Observability
prometheus_query, Execute a PromQL queryprometheus_labels, List Prometheus label namesgrafana_dashboard_list, List Grafana dashboards
Alertmanager
alertmanager_alert_list, List active alertsalertmanager_silence_create, Create a silence
HTTP / REST
http_get, Perform an HTTP GET requesthttp_post, Perform an HTTP POST requesthttp_put, Perform an HTTP PUT requesthttp_patch, Perform an HTTP PATCH requesthttp_delete, Perform an HTTP DELETE request
Database
psql_query, Execute a PostgreSQL querypsql_tables, List PostgreSQL tablesmysql_query, Execute a MySQL queryredis_get, Read a Redis keyredis_keys_scan, Scan Redis keyspace by pattern
Least privilege is the last line of defense: the
database tools run tenant-supplied SQL under owner approval, in a session
pinned read-only, with statement chaining rejected. A read-only session
blocks writes and schema changes, but it does not block server-side program
execution or file egress (PostgreSQL COPY ... TO PROGRAM,
MySQL SELECT ... INTO OUTFILE / LOAD_FILE()) --
those are gated only by the privileges of the role the tool connects as. Point
the credential at a dedicated, read-only, least-privilege role that holds
SELECT on the intended tables and nothing else. See
Least-privilege
database role.
Infrastructure as Code
terraform_plan, Generate a Terraform planterraform_apply, Apply Terraform changes (destructive, approval-gated)terraform_output, Read Terraform outputsterraform_state_list, List resources in Terraform statekustomize_build, Render a kustomize overlay
All four terraform tools refuse without
workspace_dirs: declare the absolute
directories the workspace owns on the
iac workspace, for example
workspace_dirs: ["/srv/terraform/prod"], or
terraform_plan, terraform_apply,
terraform_output and
terraform_state_list all refuse every call.
Each call must name a directory at or below a
declared one; the argument is required and must be
absolute, because an omitted one used to run terraform in
whichever directory the agent process was started in and
nothing took that default's place. See
Infrastructure
as code scope.
These tools run terraform. There is no
OpenTofu support: nothing in the bundle invokes
tofu.
terraform_apply always runs
apply -auto-approve -input=false -no-color. There
is no plan gate in front of it and no scope key that adds one;
what gates it is the approval policy for its destructive risk
class. terraform_plan changes no infrastructure but does
write plan.tfout into the directory it runs in,
which is one more reason that directory must be one the
workspace declared.
Vault / Secrets
vault_secret_list, List secrets at a pathvault_secret_metadata, Read secret metadatavault_token_lookup, Inspect a Vault token
Read-only. The EEM inventory does not include a Vault write tool.
etcd
etcd_get, Read a keyetcd_member_list, List cluster membersetcd_endpoint_health, Check endpoint health
Read-only. The EEM inventory does not include an etcd write tool.
Container Runtime
container_image_inspect, Inspect a container imagecontainer_image_list, List container imagescontainer_image_pull, Pull a container imagecontainer_image_rm, Remove a container image (destructive)container_inspect, Inspect a containercontainer_logs, Stream container logscontainer_ps, List running containerscontainer_restart, Restart a container (destructive)container_rm, Remove a container (destructive)container_start, Start a containercontainer_stats, Show container resource usagecontainer_stop, Stop a container (destructive)crictl_inspect, Inspect a CRI containercrictl_ps, List CRI containersvirsh_list, List libvirt domains
The container_* tools drive one of three
runtimes: podman, docker, or
Apple's container CLI. All three are
supported on macOS; Linux hosts have
podman and docker. The
crictl_* and virsh_* tools
are unaffected by the runtime setting.
A workspace picks its runtime with the
runtime scope key:
auto (the default), podman,
docker, or container.
auto takes the first runtime installed on
the agent's host. On macOS the order is
container, docker,
podman; on Linux it is
podman, docker, and Apple's
container is not considered there at all.
Apple's container is the Mac's native
runtime, so auto prefers it. On a Mac that
has Docker Desktop or podman as well, auto
selects Apple's runtime: it has no
restart sub-command, so
container_restart refuses there, and it
returns differently shaped JSON. Pin
runtime: docker or
runtime: podman to drive the other one.
A named runtime that is not installed is refused. The
error names the runtime and the host; the tool does not
fall back to another runtime, so a workspace pinned to
podman never runs against
docker.
container_restart is unavailable on Apple's
container runtime, which has no
restart command. Use
container_stop followed by
container_start; that sequence is not an
exact restart, so the tool does not perform it for you.
Every other container_* tool works on all
three runtimes. container_image_rm passes
its force flag through to each runtime's
own: on docker and podman that removes an image
containers still reference, and on Apple's runtime it
ignores images that are not found.
Each tool returns the selected runtime's own output. The runtimes do not agree on JSON shape, and these tools do not reconcile them.
The workspace decides which containers and images the
mutating tools may touch. allowed_containers
narrows container_start,
container_stop,
container_restart and
container_rm;
allowed_images narrows
container_image_pull and
container_image_rm. Both are patterns
matched against the identifier exactly as the call
passes it: an ID is never resolved to a name, because
that answer belongs to the runtime and can change
between the question and the delete. The read-only
tools are not narrowed by either.
allowed_registries narrows
container_image_pull to the registry the
reference itself names. While it is set, a reference
that names none is refused: what a bare
nginx resolves to is the runtime's own
configuration rather than part of the reference, so
write docker.io/library/nginx. The check
governs this tool's pull, and nothing else -- an image
already on the host, or pulled by something other than
these tools, is outside it.
All three keys narrow rather than grant, so a workspace that declares none of them keeps every container tool it has today. See Config Files for the scope reference.
The agent advertises the container_* tools
only when at least one runtime is installed on its
host, so a host with none does not offer them.
Log Aggregation
loki_query, Execute a LogQL queryelasticsearch_search, Search Elasticsearch indiceselasticsearch_cluster_health, Report Elasticsearch cluster health
Incident Management
pagerduty_incident_list, List PagerDuty incidentspagerduty_incident_acknowledge, Acknowledge a PagerDuty incident
Opsgenie is supported as a notification channel only, not as a EEM tool.
Slack
slack_channel_history, Read Slack channel historyslack_post_message, Post a Slack message
Linux Host Diagnostics
linux_chmod, Change file mode (destructive)linux_chown, Change file ownership (destructive)linux_cp, Copy fileslinux_cpu_info, Read CPU informationlinux_directory_list, List directory entrieslinux_directory_size, Compute directory sizelinux_disk_usage, Report disk usagelinux_dns_resolve, Resolve a hostnamelinux_env_print, Print environment variableslinux_file_hash, Hash a filelinux_file_read, Read a filelinux_file_stat, Stat a filelinux_find_files, Find files by patternlinux_host_overview, Summarize host statelinux_hostname, Read system hostnamelinux_ip_address_show, Show IP addresseslinux_ip_route_show, Show IP routeslinux_journalctl_read, Read systemd journallinux_mv, Move or rename a file (destructive)linux_ping_host, Ping a hostlinux_process_kill, Send a signal to a process (destructive)linux_process_list, List processeslinux_ss_sockets, List sockets via sslinux_systemctl_disable, Disable a systemd unit (destructive)linux_systemctl_enable, Enable a systemd unit (destructive)linux_systemctl_list_units, List systemd unitslinux_systemctl_reload, Reload a systemd unitlinux_systemctl_restart, Restart a systemd unit (destructive)linux_systemctl_start, Start a systemd unitlinux_systemctl_status, Read systemd unit statuslinux_systemctl_stop, Stop a systemd unit (destructive)linux_tar_create, Create a tar archivelinux_tar_extract, Extract a tar archive (destructive)linux_traceroute, Trace a network routelinux_uptime, Read system uptimedmesg, Read kernel ring bufferlsof, List open filesss, Show socket statisticsstrace, Trace system calls
Twelve of these tools need
allowed_paths and stop working without
it. linux_file_read,
linux_file_stat,
linux_file_hash,
linux_directory_list,
linux_directory_size,
linux_find_files,
linux_chmod, linux_chown,
linux_cp, linux_mv,
linux_tar_create and
linux_tar_extract take an absolute host
path from the caller. A key that bounds such a path
grants nothing while it is absent, so a workspace that
declares none of them refuses all twelve. Declare the
directories the workspace is for:
allowed_paths: ["/srv/app", "/var/log"].
The other linux tools take no path and are unaffected.
Every path argument must resolve inside a declared
root. A relative path is refused rather than guessed
at, and a symlink below a root is refused rather than
followed, so nothing inside a root can point out of
it. linux_cp, linux_mv,
linux_tar_create and
linux_tar_extract take two paths and both
are checked: a source inside a root and a destination
outside one is refused. A destination that does not
exist yet is still bounded -- the spelling has to land
inside a root, and any directory above it that does
exist has to be a real directory rather than a link.
denied_paths carves patterns back out,
and a denial beats an allowance. A pattern is matched
against the whole absolute path, and one with no slash
is also matched against the file name alone, so
*.pem means pem files anywhere under the
roots while /etc/* means that directory.
Absent, it narrows nothing.
allowed_commands is a list of BINARY
names -- systemctl,
journalctl, df -- and it
decides which of these tools may run at all. Each tool
is checked against the one binary it is built to
invoke, so the entries are names rather than paths and
a tool whose binary is not listed is refused before it
starts. It does NOT inspect what a command line
contains, and in particular it places no limit on
shell_exec_irreversible: that tool's
argument is a string bash -lc re-parses,
where a; b, $(b), a function
and an alias all defeat a first-token check, so a
filter there would promise a narrowing it cannot
deliver. Absent, the key narrows nothing.
What none of these keys bounds is what a binary does
once it is running. tar resolves an
archive member named ../../etc/passwd
itself, and that happens after the tool has handed the
argv over. Bounding target_path bounds
the directory we pass, not the archive's contents. See
Config
Files for the scope reference.
Destructive Shell
shell_exec_irreversible, Execute an arbitrary shell command on the agent host. Destructive and approval-gated; intended only as an escape hatch when no scoped tool covers the operation. Prefer the scopedlinux_*,container_*, ork8s_*tools whenever possible.
A runas is refused unless the workspace
the call resolves to names the account under
shell_runas_user. The key fails closed: a
workspace that declares no accounts permits no
runas at all. Omitting the argument is
unaffected -- the command then runs as the agent's own
user, which is a deployment choice rather than a scope
one, because this tool does not switch identity.
Nothing narrows the command itself.
allowed_commands is a binary allowlist
over the linux_* tools and does not reach
here: the argument is a string
bash -lc re-parses, so a first-token
check would be defeated by a; b,
$(b), a shell function or an alias. What
governs this tool is the owner approval with typed
confirmation, its irreversible risk class, and whether
the agent ships the shell domain at all.
TLS / Certificate
tls_connect, Open a TLS connection and report handshakecertificate_expiry, Report certificate expiry for a hostopenssl_verify, Verify a certificate chain via openssl
AWS
aws_cloudwatch_get_metric_stats, Read CloudWatch metric statisticsaws_ec2_describe_instances, Describe EC2 instancesaws_ec2_describe_security_groups, Describe EC2 security groupsaws_ec2_reboot_instances, Reboot EC2 instances (destructive)aws_ec2_start_instances, Start EC2 instancesaws_ec2_stop_instances, Stop EC2 instances (destructive)aws_eks_list_clusters, List EKS clustersaws_iam_list_users, List IAM usersaws_logs_tail, Tail CloudWatch Logsaws_rds_describe_db_instances, Describe RDS instancesaws_s3_cp, Copy objects to or from S3aws_s3_list_buckets, List S3 buckets
Azure
az_aks_list, List AKS clustersaz_aks_nodepool_list, List AKS node poolsaz_keyvault_list, List Key Vaultsaz_monitor_metrics_list, List Azure Monitor metricsaz_resource_group_list, List resource groupsaz_sql_server_list, List Azure SQL serversaz_storage_account_list, List storage accountsaz_vm_list, List virtual machinesaz_vm_power_state, Read VM power stateaz_vm_start, Start a virtual machineaz_vm_stop, Stop a virtual machine (destructive)az_vm_restart, Restart a virtual machine (destructive)
GCP
gcloud_compute_instances_list, List Compute Engine instancesgcloud_compute_instances_start, Start a Compute Engine instancegcloud_compute_instances_stop, Stop a Compute Engine instance (destructive)gcloud_compute_networks_list, List VPC networksgcloud_container_clusters_list, List GKE clustersgcloud_iam_list_service_accounts, List IAM service accountsgcloud_logging_read, Read Cloud Logging entriesgcloud_projects_list, List GCP projectsgcloud_pubsub_list_topics, List Pub/Sub topicsgcloud_redis_instances_list, List Memorystore Redis instancesgcloud_sql_instances_list, List Cloud SQL instancesgcloud_storage_buckets_list, List Cloud Storage buckets
OpenStack
openstack_flavor_list, List flavorsopenstack_flavor_show, Show a flavoropenstack_floatingip_create, Allocate a floating IPopenstack_floatingip_delete, Release a floating IP (destructive)openstack_image_list, List imagesopenstack_image_upload, Upload an imageopenstack_image_delete, Delete an image (destructive)openstack_keypair_list, List keypairsopenstack_keypair_create, Create a keypairopenstack_keypair_delete, Delete a keypair (destructive)openstack_network_list, List networksopenstack_router_list, List routersopenstack_router_create, Create a routeropenstack_router_delete, Delete a router (destructive)openstack_security_group_list, List security groupsopenstack_server_list, List serversopenstack_server_show, Show a serveropenstack_server_create, Create a serveropenstack_server_delete, Delete a server (destructive)openstack_server_reboot, Reboot a server (destructive)openstack_server_resize, Resize a server (destructive)openstack_server_start, Start a serveropenstack_server_stop, Stop a server (destructive)openstack_stack_list, List Heat stacksopenstack_stack_show, Show a Heat stackopenstack_stack_create, Create a Heat stackopenstack_stack_delete, Delete a Heat stack (destructive)openstack_subnet_list, List subnetsopenstack_volume_list, List volumesopenstack_volume_create, Create a volumeopenstack_volume_delete, Delete a volume (destructive)openstack_volume_attach, Attach a volumeopenstack_volume_extend, Extend a volumeopenstack_volume_snapshot_list, List volume snapshotsopenstack_volume_snapshot_create, Create a volume snapshot
Kubernetes
k8s_get_namespaces, List namespacesk8s_get_nodes, List nodesk8s_get_pods, List podsk8s_get_deployments, List deploymentsk8s_get_services, List servicesk8s_get_ingress, List ingressesk8s_get_configmaps, List configmapsk8s_get_secrets, List secretsk8s_get_events, List eventsk8s_describe_pod, Describe a podk8s_logs, Read pod logsk8s_exec, Execute a command in a pod (approval-gated)k8s_label_pod, Label a podk8s_annotate_pod, Annotate a podk8s_apply_manifest, Apply an inline manifestk8s_apply_from_file, Apply a manifest from a filek8s_delete_pod, Delete a pod (destructive)k8s_delete_resource, Delete an arbitrary resource (destructive)k8s_cordon_node, Cordon a node (destructive)k8s_uncordon_node, Uncordon a nodek8s_drain_node, Drain a node (destructive)k8s_scale_deployment, Scale a deploymentk8s_restart_deployment, Restart a deployment (destructive)k8s_rollout_status, Read rollout statusk8s_rollout_history, Read rollout historyk8s_rollout_undo, Roll back a deployment (destructive)k8s_top_cluster, Cluster-wide resource usagek8s_top_nodes, Per-node resource usagek8s_top_pods, Per-pod resource usagek8s_wait, Wait on a resource condition
Helm / ArgoCD
helm_list, List Helm releaseshelm_history, Show Helm release historyargocd_app_list, List ArgoCD applicationsargocd_app_sync, Sync an ArgoCD application
Agentic Primitives
auto_fork_branch, Fork an execution branchemit_execution_artifact, Emit an execution artifactrecall_execution_memory, Recall prior execution memorysave_execution_memory, Persist execution memoryrequest_operator_decision, Request an operator decision (approval-gated)request_subplan, Request a subplanrerank_operational_context, Rerank operational contextx_deep_think, Research pipeline primitive (EEM tool name; the router-side tool isx_research_run)
EEM Self-Introspection
eem_list_tools, Live list of registered toolseem_resolve_endpoint, Resolve an endpoint by nameeem_self_diagnose, Run agent self-diagnosiseem_test_credential, Test a stored credential