Skip to content

feat: configurable tool allowlist, enabling a minimal bash-only harness - #113

Open
borko1945 wants to merge 2 commits into
0xku:mainfrom
borko1945:feat/configurable-tool-allowlist
Open

borko1945 wants to merge 2 commits into
0xku:mainfrom
borko1945:feat/configurable-tool-allowlist

Conversation

@borko1945

@borko1945 borko1945 commented Sep 21, 2026 •

Copy link
Copy Markdown

Summary

This is inspired by Deepseek harness mini mode - where the model has only bash as a tool. Models are pretty good with bash as this is part of their training. The model is more focused and dramatically reduces the initial context.

I am using it and so far so good.

The six built-in tools were hardcoded in DEFAULT_TOOLS, so there was no way to turn any of them off — [tools] extra could only ever add tools. This adds [tools] enabled as an allowlist, which makes it possible to run a leaner Kon (for example bash-only) without touching the code.

Changes

  • [tools] enabled — the built-in tools exposed to the agent, defaulting to the current six, so behaviour is unchanged out of the box.
  • resolve_tools() — one helper that merges enabled + extra + --extra-tools and reports unknown names, replacing the duplicated (and slightly divergent) logic in ui/app.py and headless.py.
  • turn.py fix — _finalize_tool_call_data() resolved tool calls against the global registry, so a tool that was not exposed to the model could still be executed if the model named it. It now resolves against the turn's active tools. This is a prerequisite for the allowlist to actually hold.
  • Dropped the now-unused DEFAULT_TOOLS/EXTRA_TOOLS constants; tools_by_name is the single registry and the defaults live in config.py + defaults/config.toml, matching how every other default is handled.

Example:

[tools]
enabled = ["bash"]
extra = []

Notes

  • Fully backward compatible. Configs without enabled inherit the shipped default, so existing users see the same six tools plus their extra. Verified against a real pre-existing config.
  • No config_version bump / migration needed — the key has a default and absence is handled, so no user config gets rewritten.
  • EXTRA_TOOLS previously doubled as the "is this a valid name?" check; validation is now tools_by_name, so unknown names in enabled are reported too. The warning text changed from unknown extra tool to unknown tool accordingly (one test line updated).
  • Removing DEFAULT_TOOLS/EXTRA_TOOLS from kon.tools.__all__ is technically a public-API change — happy to keep them as aliases if you'd prefer.
  • Adding a new tool is now one step shorter: implement it, add it to all_tools, and decide whether it belongs in enabled or extra.

Testing

ruff format, ruff check, pyright (0 errors) and pytest (806 passed, 1 skipped) all clean. New tests/test_tools_config.py covers the default set, trimming to bash-only, extending via extra/CLI, and unknown-name reporting; test_disabled_tool_is_not_executable covers the turn.py fix.

AI usage

The change was coded by Opus 4.8 under my command

borko1945 and others added 2 commits September 21, 2026 23:25
_finalize_tool_call_data looked the tool up in the global registry, so a
tool that was not exposed to the model could still be executed. Resolve
against the tools passed to the turn instead.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
The default six tools were hardcoded, so they could not be disabled. Add
[tools] enabled as an allowlist (defaulting to the current six) that is
merged with [tools] extra and --extra-tools by a shared resolve_tools()
helper, replacing the duplicated logic in the TUI and headless entry
points.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@borko1945 borko1945 changed the title feat: make the built-in tool set configurable via [tools] enabled feat: configurable tool allowlist, enabling a minimal bash-only harness Sep 21, 2026
@borko1945
borko1945 force-pushed the feat/configurable-tool-allowlist branch from e011d72 to 005fb32 Compare September 21, 2026 21:35

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant