{"_id":"@agentionai/marshall-tools","_rev":"18-ddfd9bf2cf786ae2efc6d5d2d2c74dc1","name":"@agentionai/marshall-tools","dist-tags":{"latest":"0.9.5"},"versions":{"0.3.0":{"name":"@agentionai/marshall-tools","version":"0.3.0","_id":"@agentionai/marshall-tools@0.3.0","maintainers":[{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"}],"dist":{"shasum":"53d051de30314d4e5f477ef2ce88764859ee554c","tarball":"https://registry.npmjs.org/@agentionai/marshall-tools/-/marshall-tools-0.3.0.tgz","fileCount":70,"integrity":"sha512-rQk092HQ9wrP8zXp08geBuaZFeF+jFMGHqrWNWsyJLAbZVsTEDs8z5c+VM8qBNicsbIJeRDxF53oAa8uefoe7w==","signatures":[{"sig":"MEQCIBrLKpHp4nJBY/XQjNoXOX9VsyTPJ8bKhArDaPSkOtTEAiBrp2+8s37IGsNfeAOTpzDTTqjyHBmcQ6uzCdPOul09ng==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":158124},"type":"module","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"318ef670ab00cfabbd63e1a573188267303f4d92","scripts":{"test":"node --import tsx/esm --test 'src/**/*.test.ts'","prepare":"tsc","typecheck":"tsc --noEmit"},"_npmUser":{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"},"_npmVersion":"10.9.2","description":"Reusable, safe-by-default tool implementations for the Marshall coding assistant. Provides Agention `Tool` instances for file operations, shell execution, a private scratch area, and GitHub — all scoped to a workspace directory with a human-in-the-loop ap","directories":{},"_nodeVersion":"22.14.0","dependencies":{"@agentionai/agents":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","typescript":"^5.7.0","@types/node":"^25.0.0"},"_npmOperationalInternal":{"tmp":"tmp/marshall-tools_0.3.0_1785671614802_0.07519773809289587","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@agentionai/marshall-tools","version":"0.4.0","_id":"@agentionai/marshall-tools@0.4.0","maintainers":[{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"}],"dist":{"shasum":"1941a4a363fe161ea831a919f9ad62d053d10142","tarball":"https://registry.npmjs.org/@agentionai/marshall-tools/-/marshall-tools-0.4.0.tgz","fileCount":94,"integrity":"sha512-VdCszLxVFy+kFb5tBRRpe3ZD1nV62qKmrxsUxzalz43LDeZvoFP2V9/x3TBXUXNBAkD9lHZyqzmQjitl8T0suw==","signatures":[{"sig":"MEUCIQCFtqCrsXVsl53FpedQmhCfWGqNtdsVuNZPTp6D5KwQNAIgGz4PkqYtnYtui+jp6BQwTn1s5hl2XSuIUtk7ZGDJdGU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":244297},"type":"module","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"f7c470723c346b1ff912d08ff4167ffdbae17625","scripts":{"test":"node --import tsx/esm --test 'src/**/*.test.ts'","prepare":"tsc","typecheck":"tsc --noEmit"},"_npmUser":{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"},"_npmVersion":"11.13.0","description":"Reusable, safe-by-default tool implementations for the Marshall coding assistant. Provides Agention `Tool` instances for file operations, shell execution, a private scratch area, and GitHub — all scoped to a workspace directory with a human-in-the-loop ap","directories":{},"_nodeVersion":"24.16.0","dependencies":{"@agentionai/agents":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","typescript":"^5.7.0","@types/node":"^25.0.0"},"_npmOperationalInternal":{"tmp":"tmp/marshall-tools_0.4.0_1785935293403_0.6271271680402546","host":"s3://npm-registry-packages-npm-production"}},"0.4.1":{"name":"@agentionai/marshall-tools","version":"0.4.1","_id":"@agentionai/marshall-tools@0.4.1","maintainers":[{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"}],"dist":{"shasum":"88bca37682160dcc908d0068293b3544c72ed3eb","tarball":"https://registry.npmjs.org/@agentionai/marshall-tools/-/marshall-tools-0.4.1.tgz","fileCount":94,"integrity":"sha512-g7dXRu/TANtnWXofhlzHH9kG1ZvyX8nQUtmFo+3SxtcYuoue3fAhccs94t4q+znzERr99qMmvOegM7fgZV7OXg==","signatures":[{"sig":"MEUCIFfZNO1sPiohMB2MFnJPqscL064+D5EV76EypvWMtTlqAiEA1K3D85Rf9VOTIAbXtOXQf+YlYUNCTEkuGAYbO4tfvLU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":247662},"type":"module","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"155e2195d7d6b31d57588eec335032c487e6562b","scripts":{"test":"node --import tsx/esm --test 'src/**/*.test.ts'","build":"tsc","prepare":"tsc","typecheck":"tsc --noEmit"},"_npmUser":{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"},"_npmVersion":"11.13.0","description":"Reusable, safe-by-default tool implementations for the Marshall coding assistant. Provides Agention `Tool` instances for file operations, shell execution, a private scratch area, and GitHub — all scoped to a workspace directory with a human-in-the-loop ap","directories":{},"_nodeVersion":"24.16.0","dependencies":{"@agentionai/agents":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","typescript":"^5.7.0","@types/node":"^25.0.0"},"_npmOperationalInternal":{"tmp":"tmp/marshall-tools_0.4.1_1785967501443_0.45593308498985974","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@agentionai/marshall-tools","version":"0.5.0","_id":"@agentionai/marshall-tools@0.5.0","maintainers":[{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"}],"dist":{"shasum":"815830cdbed4a4844af58267550911baee341b27","tarball":"https://registry.npmjs.org/@agentionai/marshall-tools/-/marshall-tools-0.5.0.tgz","fileCount":102,"integrity":"sha512-dfZ7UO+V2ep9lTzmyQKffDV1ymVu2J7AEJaDW7ditc4W3Gdg0Hj8uUCJWmWeawiHuU+jILPbALIt7kyKPiG71Q==","signatures":[{"sig":"MEQCID57cwHbE5r4Ishx5btOoAqynAzVTfVEV3MOkEKESGVoAiBYt230nDkNX/UIhQ8gwjnFnOXLB0oPnuQqT7oqjphceg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":256089},"type":"module","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"d4e00eb7d63ff2ecc1be7c4077d0c93d78d3042f","scripts":{"test":"node --import tsx/esm --test 'src/**/*.test.ts'","build":"tsc","prepare":"tsc","typecheck":"tsc --noEmit"},"_npmUser":{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"},"_npmVersion":"11.13.0","description":"Reusable, safe-by-default tool implementations for the Marshall coding assistant. Provides Agention `Tool` instances for file operations, shell execution, a private scratch area, and GitHub — all scoped to a workspace directory with a human-in-the-loop ap","directories":{},"_nodeVersion":"24.16.0","dependencies":{"@agentionai/agents":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","typescript":"^5.7.0","@types/node":"^25.0.0"},"_npmOperationalInternal":{"tmp":"tmp/marshall-tools_0.5.0_1786105323833_0.9134291957418923","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@agentionai/marshall-tools","version":"0.6.0","_id":"@agentionai/marshall-tools@0.6.0","maintainers":[{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"}],"dist":{"shasum":"fd8e257bde35d292e8f7087d2fa06da2f980a74a","tarball":"https://registry.npmjs.org/@agentionai/marshall-tools/-/marshall-tools-0.6.0.tgz","fileCount":70,"integrity":"sha512-lVxSrYV2QgMpqGBPrXNkJRJ9WMoPLYkNb5hrAHmwKJ1pKmgpwCwgICMTYqIPmR4y6pbgxBpreMsJezRVfDAbNg==","signatures":[{"sig":"MEUCICaQUZmJE4+ICS5dET2swzlS2bSURwSOaZdCQsNjz1UZAiEA1TJWPzQuXL/msnPKNvb8RKyMgVNqra+W6F19DJWwBA8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":178346},"type":"module","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"d4d5e88fe6f9f5db01c3b2693bc880746935f481","scripts":{"test":"node --import tsx/esm --test 'src/**/*.test.ts'","build":"tsc -p tsconfig.build.json","prepare":"tsc -p tsconfig.build.json","typecheck":"tsc --noEmit"},"_npmUser":{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"},"_npmVersion":"10.9.2","description":"Reusable, safe-by-default tool implementations for the Marshall coding assistant. Provides Agention `Tool` instances for file operations, shell execution, a private scratch area, and GitHub — all scoped to a workspace directory with a human-in-the-loop ap","directories":{},"_nodeVersion":"22.14.0","dependencies":{"@agentionai/agents":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","typescript":"^5.7.0","@types/node":"^25.0.0"},"_npmOperationalInternal":{"tmp":"tmp/marshall-tools_0.6.0_1786223769817_0.8237549397627264","host":"s3://npm-registry-packages-npm-production"}},"0.6.1":{"name":"@agentionai/marshall-tools","version":"0.6.1","_id":"@agentionai/marshall-tools@0.6.1","maintainers":[{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"}],"dist":{"shasum":"57626c4c7e8e54d79a49293467054556bba44a80","tarball":"https://registry.npmjs.org/@agentionai/marshall-tools/-/marshall-tools-0.6.1.tgz","fileCount":70,"integrity":"sha512-sSmEtQBGCe5mXJWdqa3UCia833KdH3E3IXya/DyapF7R4GkKfUuCh1kmEsf689I9rbi285DKhJg/g1T7Q1Xydg==","signatures":[{"sig":"MEUCIQDCPiDYZfccArhrGS5CBaQZFBBNkm1s02YR7wqT8ngPOwIgSi61RJxF/nInvrDynq8sfVQJ/qz1sSxuRgURCVywRLE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":178400},"type":"module","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"f2f90a37ae6d4e83dbe856e0ac85a93bef9e4503","scripts":{"test":"node --import tsx/esm --test 'src/**/*.test.ts'","build":"node -e \"fs.rmSync('dist',{recursive:true,force:true})\" && tsc -p tsconfig.build.json","prepack":"npm run build","typecheck":"tsc --noEmit"},"_npmUser":{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"},"_npmVersion":"10.9.2","description":"Reusable, safe-by-default tool implementations for the Marshall coding assistant. Provides Agention `Tool` instances for file operations, shell execution, a private scratch area, and GitHub — all scoped to a workspace directory with a human-in-the-loop ap","directories":{},"_nodeVersion":"22.14.0","dependencies":{"@agentionai/agents":"1.6.0-beta.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","typescript":"^5.7.0","@types/node":"^25.0.0"},"_npmOperationalInternal":{"tmp":"tmp/marshall-tools_0.6.1_1786485070610_0.017582559172949708","host":"s3://npm-registry-packages-npm-production"}},"0.6.3":{"name":"@agentionai/marshall-tools","version":"0.6.3","_id":"@agentionai/marshall-tools@0.6.3","maintainers":[{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"}],"dist":{"shasum":"4c4c11072aa7f6ecbc51f74564b742fbe42176f3","tarball":"https://registry.npmjs.org/@agentionai/marshall-tools/-/marshall-tools-0.6.3.tgz","fileCount":70,"integrity":"sha512-Ebiaq+6fLsmQOIV/ZMVQ9Ecz8X6yl6CB32ZWujKG9vEAw0RfoRi1BgFUSb/QDOoCwzCUE414lib0LwSl+raYSg==","signatures":[{"sig":"MEUCIQDoCJseSksKY+HBsK7kHUzxXRtAvFYXzP8JsQPmJHV2lAIgdiqBrcvVgl4UIwy4nf5LAi14+v/I56tE6uc1eY6gfqo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":179311},"type":"module","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"db1470bd5bf508bafa5146e2622e70a1644131d6","scripts":{"test":"node --import tsx/esm --test 'src/**/*.test.ts'","build":"node -e \"fs.rmSync('dist',{recursive:true,force:true})\" && tsc -p tsconfig.build.json","prepack":"npm run build","typecheck":"tsc --noEmit"},"_npmUser":{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"},"_npmVersion":"10.9.2","description":"Reusable, safe-by-default tool implementations for the Marshall coding assistant. Provides Agention `Tool` instances for file operations, shell execution, a private scratch area, and GitHub — all scoped to a workspace directory with a human-in-the-loop ap","directories":{},"_nodeVersion":"22.14.0","dependencies":{"@agentionai/agents":"1.7.0-beta.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","typescript":"^5.7.0","@types/node":"^25.0.0"},"_npmOperationalInternal":{"tmp":"tmp/marshall-tools_0.6.3_1786641084057_0.9000667806913216","host":"s3://npm-registry-packages-npm-production"}},"0.6.4":{"name":"@agentionai/marshall-tools","version":"0.6.4","_id":"@agentionai/marshall-tools@0.6.4","maintainers":[{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"}],"dist":{"shasum":"b62b04b8f60ef6be81cd2031e8ab5889716c855b","tarball":"https://registry.npmjs.org/@agentionai/marshall-tools/-/marshall-tools-0.6.4.tgz","fileCount":70,"integrity":"sha512-M+drggqBoAOYXbSjhuCxZ0ozir6g91JF7t6AyL67oooebh1leRjc8rD04AlnuuXjG8MlRZgFz9EkNJ14uTp0UA==","signatures":[{"sig":"MEYCIQCFx9FhhhiJzpNFbybAo7Qr6SOIAzrQHUELlge3FDuRkwIhAKg9d87FznFmUKV8SSuKCztQ21jCbATN/qkUIozZWQ+r","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":184425},"type":"module","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"171b18cea563ece0ea2fdd1faa9196d956fb1133","scripts":{"test":"node --import tsx/esm --test 'src/**/*.test.ts'","build":"node -e \"fs.rmSync('dist',{recursive:true,force:true})\" && tsc -p tsconfig.build.json","prepack":"npm run build","typecheck":"tsc --noEmit"},"_npmUser":{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"},"_npmVersion":"10.9.2","description":"Reusable, safe-by-default tool implementations for the Marshall coding assistant. Provides Agention `Tool` instances for file operations, shell execution, a private scratch area, and GitHub — all scoped to a workspace directory with a human-in-the-loop ap","directories":{},"_nodeVersion":"22.14.0","dependencies":{"@agentionai/agents":"1.7.0-beta.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","typescript":"^5.7.0","@types/node":"^25.0.0"},"_npmOperationalInternal":{"tmp":"tmp/marshall-tools_0.6.4_1786827499851_0.6820055706024539","host":"s3://npm-registry-packages-npm-production"}},"0.6.5":{"name":"@agentionai/marshall-tools","version":"0.6.5","_id":"@agentionai/marshall-tools@0.6.5","maintainers":[{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"}],"dist":{"shasum":"99fee178503c343605ce00745666d3bd772c74c0","tarball":"https://registry.npmjs.org/@agentionai/marshall-tools/-/marshall-tools-0.6.5.tgz","fileCount":70,"integrity":"sha512-gVm9xs4K+QmN2c81EAKL6mNYxvuGGRml0H71M1NNKCjatBdMCoNuxA7wp+ZwJuqkJOWcD1JMxZXaZdc3sbI8jg==","signatures":[{"sig":"MEQCIErCLQT1iCl5hCJf0g0MDJViNvsMmRexHJKYSwSDlcedAiA+eeQa4dg7nQxony39wgrxgRneNIB9BqMj5onrncClag==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":189050},"type":"module","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"99c6d39cd8855bf92661cd08bd9b7e36c9a86778","scripts":{"test":"node --import tsx/esm --test 'src/**/*.test.ts'","build":"node -e \"fs.rmSync('dist',{recursive:true,force:true})\" && tsc -p tsconfig.build.json","prepack":"npm run build","typecheck":"tsc --noEmit"},"_npmUser":{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"},"_npmVersion":"10.9.2","description":"Reusable, safe-by-default tool implementations for the Marshall coding assistant. Provides Agention `Tool` instances for file operations, shell execution, a private scratch area, and GitHub — all scoped to a workspace directory with a human-in-the-loop ap","directories":{},"_nodeVersion":"22.14.0","dependencies":{"@agentionai/agents":"1.10.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","typescript":"^5.7.0","@types/node":"^25.0.0"},"_npmOperationalInternal":{"tmp":"tmp/marshall-tools_0.6.5_1787000648739_0.661185290904931","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@agentionai/marshall-tools","version":"0.7.0","_id":"@agentionai/marshall-tools@0.7.0","maintainers":[{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"}],"dist":{"shasum":"2ad510deb2d0c76b808d3ee593915109d27a210c","tarball":"https://registry.npmjs.org/@agentionai/marshall-tools/-/marshall-tools-0.7.0.tgz","fileCount":78,"integrity":"sha512-YHvuMauZu+hwWBkgs0KQJff0MEt/ZuLQSD6648MaF7jQREtMMcfAp62PqpV1V+foWmrhqzW1oMcUmaThrBs40g==","signatures":[{"sig":"MEYCIQCQxhEiQdm9Cq23NDvBfx9lBNre/CnOBWxtBQz48LEVhAIhAPh3gCJdp4w0ThTzXWRYiWnci//uIxHUU5DGcFkz/iD9","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":225038},"type":"module","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"504c369d46db99051dd34ce57da90dd11ecb2db0","scripts":{"test":"node --import tsx/esm --test 'src/**/*.test.ts'","build":"node -e \"fs.rmSync('dist',{recursive:true,force:true})\" && tsc -p tsconfig.build.json","prepack":"npm run build","typecheck":"tsc --noEmit"},"_npmUser":{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"},"_npmVersion":"10.9.2","description":"Reusable, safe-by-default tool implementations for the Marshall coding assistant. Provides Agention `Tool` instances for file operations, shell execution, a private scratch area, and GitHub — all scoped to a workspace directory with a human-in-the-loop ap","directories":{},"_nodeVersion":"22.14.0","dependencies":{"@agentionai/agents":"1.10.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","typescript":"^5.7.0","@types/node":"^25.0.0"},"_npmOperationalInternal":{"tmp":"tmp/marshall-tools_0.7.0_1787086059687_0.3399098048364355","host":"s3://npm-registry-packages-npm-production"}},"0.7.1":{"name":"@agentionai/marshall-tools","version":"0.7.1","_id":"@agentionai/marshall-tools@0.7.1","maintainers":[{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"}],"dist":{"shasum":"66cd1d9f0698a53281798bb5a586c561e2e8c86f","tarball":"https://registry.npmjs.org/@agentionai/marshall-tools/-/marshall-tools-0.7.1.tgz","fileCount":98,"integrity":"sha512-cWLeyVVEp6vxXAg9GpfCwYvCyh4HetccWjZbmZv8ndYfv5IdEMujrY75TIvB98NwuJMJAYkAXYFd0X7mC7VhGQ==","signatures":[{"sig":"MEYCIQDgjvzZkSHbQyDNaeLCZQIXcJATXdfNsA830CR2mDM3AQIhAP61yWT+TeBT0fn5KzkqXBTU9btmsQFP76GrEI7vTvh/","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":261147},"type":"module","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"a2591111a4aad8d60de07272c22542e5855d1924","scripts":{"test":"node --import tsx/esm --test 'src/**/*.test.ts'","build":"node -e \"fs.rmSync('dist',{recursive:true,force:true})\" && tsc -p tsconfig.build.json","prepack":"npm run build","typecheck":"tsc --noEmit"},"_npmUser":{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"},"_npmVersion":"11.13.0","description":"Reusable, safe-by-default tool implementations for the Marshall coding assistant. Provides Agention `Tool` instances for file operations, shell execution, a private scratch area, and GitHub — all scoped to a workspace directory with a human-in-the-loop ap","directories":{},"_nodeVersion":"24.16.0","dependencies":{"@agentionai/agents":"1.11.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","typescript":"^5.7.0","@types/node":"^25.0.0"},"_npmOperationalInternal":{"tmp":"tmp/marshall-tools_0.7.1_1787245171054_0.7315649087712532","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"@agentionai/marshall-tools","version":"0.8.0","_id":"@agentionai/marshall-tools@0.8.0","maintainers":[{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"}],"dist":{"shasum":"b11ea8b0385d2af42e7cf8e38ad9308d19000253","tarball":"https://registry.npmjs.org/@agentionai/marshall-tools/-/marshall-tools-0.8.0.tgz","fileCount":102,"integrity":"sha512-WxJYSEO98RLBQNiVdLxALd6T8venpnRiZzgcIOf8c4mLMVtuxxffho15Una4MLpp1aGSTjCoSpDUQ7HXrPfZog==","signatures":[{"sig":"MEYCIQC0ARz4NfMfsX8C6ONpc3BJoqzXfYRF/lU2CHhzk838EQIhAINI7JYuTMwFUdjP1YSJM1J81g3Xxg5LwRCHOj59XLfr","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":319050},"type":"module","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"5ec4d87b5377c0caf0f8fad294bceb300b39b4ea","scripts":{"test":"node --import tsx/esm --test 'src/**/*.test.ts'","build":"node -e \"fs.rmSync('dist',{recursive:true,force:true})\" && tsc -p tsconfig.build.json","prepack":"tsc -p tsconfig.build.json","typecheck":"tsc --noEmit"},"_npmUser":{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"},"_npmVersion":"11.13.0","description":"Reusable, safe-by-default tool implementations for the Marshall coding assistant. Provides Agention `Tool` instances for file operations, shell execution, a private scratch area, and GitHub — all scoped to a workspace directory with a human-in-the-loop ap","directories":{},"_nodeVersion":"24.16.0","dependencies":{"@agentionai/agents":"1.11.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","typescript":"^5.7.0","@types/node":"^25.0.0"},"_npmOperationalInternal":{"tmp":"tmp/marshall-tools_0.8.0_1788558529078_0.48645277868214976","host":"s3://npm-registry-packages-npm-production"}},"0.9.0":{"name":"@agentionai/marshall-tools","version":"0.9.0","_id":"@agentionai/marshall-tools@0.9.0","maintainers":[{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"}],"dist":{"shasum":"94b526f05951c84950bf8f81127be747350fae2e","tarball":"https://registry.npmjs.org/@agentionai/marshall-tools/-/marshall-tools-0.9.0.tgz","fileCount":102,"integrity":"sha512-GQIfCYtQrheWBPJ+AedTUyKwZZli5x5PxXSUW/bCgQXIdlNskWpXq+abcA+I+1d6AyEmfPq6LU8h4C6it80Vpw==","signatures":[{"sig":"MEQCIFkuWucIBdONv4ftsZakK/SGG7YG2iTmqZhZ16ocCxUPAiA2gd3bKvZiN0Zy/TMIoTpOTx4KPoKQXvhFyhaS8VQ7ng==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":336890},"type":"module","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"826e9ae64e746c9a995f265eb867e00b3a0e7ba9","scripts":{"test":"node --import tsx/esm --test 'src/**/*.test.ts'","build":"node -e \"fs.rmSync('dist',{recursive:true,force:true})\" && tsc -p tsconfig.build.json","prepack":"tsc -p tsconfig.build.json","typecheck":"tsc --noEmit"},"_npmUser":{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"},"_npmVersion":"10.9.2","description":"Reusable, safe-by-default tool implementations for the Marshall coding assistant. Provides Agention `Tool` instances for file operations, shell execution, a private scratch area, and GitHub — all scoped to a workspace directory with a human-in-the-loop ap","directories":{},"_nodeVersion":"22.14.0","dependencies":{"@agentionai/agents":"1.11.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","typescript":"^5.7.0","@types/node":"^25.0.0"},"_npmOperationalInternal":{"tmp":"tmp/marshall-tools_0.9.0_1788695520757_0.724447368109921","host":"s3://npm-registry-packages-npm-production"}},"0.9.1":{"name":"@agentionai/marshall-tools","version":"0.9.1","_id":"@agentionai/marshall-tools@0.9.1","maintainers":[{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"}],"dist":{"shasum":"c89fc093c26a3c6bc2e3f788f1da2c00f7df58db","tarball":"https://registry.npmjs.org/@agentionai/marshall-tools/-/marshall-tools-0.9.1.tgz","fileCount":102,"integrity":"sha512-0iYI0FFkjPcZPAJf59oAvVrwQya0e0bk0HLiZwxGIc/mKMRkfY3STsRSuLes+AEpnPVJ7p4Wd1+B+/ZrYVgwTw==","signatures":[{"sig":"MEUCIC0Ydi+1whV+amKFc74ziDusDOFr7RsPqX3afFtLwvM8AiEAuhVL/3YA7vZCXRxn0XfK79YikkjvlXvQ0iUBy3gyXt4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":336890},"type":"module","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"7ddc34ae64b1fedaa55d51a1095e86af59f5fa61","scripts":{"test":"node --import tsx/esm --test 'src/**/*.test.ts'","build":"node -e \"fs.rmSync('dist',{recursive:true,force:true})\" && tsc -p tsconfig.build.json","prepack":"tsc -p tsconfig.build.json","typecheck":"tsc --noEmit"},"_npmUser":{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"},"_npmVersion":"10.9.2","description":"Reusable, safe-by-default tool implementations for the Marshall coding assistant. Provides Agention `Tool` instances for file operations, shell execution, a private scratch area, and GitHub — all scoped to a workspace directory with a human-in-the-loop ap","directories":{},"_nodeVersion":"22.14.0","dependencies":{"@agentionai/agents":"1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","typescript":"^5.7.0","@types/node":"^25.0.0"},"_npmOperationalInternal":{"tmp":"tmp/marshall-tools_0.9.1_1788724838760_0.05886271580018265","host":"s3://npm-registry-packages-npm-production"}},"0.9.2":{"name":"@agentionai/marshall-tools","version":"0.9.2","_id":"@agentionai/marshall-tools@0.9.2","maintainers":[{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"}],"dist":{"shasum":"8b2914430fdcfdb54b6e8440a1553fabdaea76a4","tarball":"https://registry.npmjs.org/@agentionai/marshall-tools/-/marshall-tools-0.9.2.tgz","fileCount":102,"integrity":"sha512-VD5UMfJKCSQJa/Hv7FmhU4h+m/REmXbZ3aCUDCd89UtxSUlrQG53fvWH9oT3W+gqgoa1pI2pRVtF+Sg0z1epZA==","signatures":[{"sig":"MEYCIQClhCzMAbyONQUjmuxI2oqfT29CGnIFpoc5nmXG53rV/QIhAMzAM1i8oB1hcsrRTBB9TozlVtCvVz2iHy8fY5x9GLYX","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":339174},"type":"module","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"8a593626df3eb6b87825c09dfe244f38053e2a41","scripts":{"test":"node --import tsx/esm --test 'src/**/*.test.ts'","build":"node -e \"fs.rmSync('dist',{recursive:true,force:true})\" && tsc -p tsconfig.build.json","prepack":"tsc -p tsconfig.build.json","typecheck":"tsc --noEmit"},"_npmUser":{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"},"_npmVersion":"11.13.0","description":"Reusable, safe-by-default tool implementations for the Marshall coding assistant. Provides Agention `Tool` instances for file operations, shell execution, a private scratch area, and GitHub — all scoped to a workspace directory with a human-in-the-loop ap","directories":{},"_nodeVersion":"24.16.0","dependencies":{"@agentionai/agents":"1.12.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","typescript":"^5.7.0","@types/node":"^25.0.0"},"_npmOperationalInternal":{"tmp":"tmp/marshall-tools_0.9.2_1788774487055_0.646198239708837","host":"s3://npm-registry-packages-npm-production"}},"0.9.3":{"name":"@agentionai/marshall-tools","version":"0.9.3","_id":"@agentionai/marshall-tools@0.9.3","maintainers":[{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"}],"dist":{"shasum":"b545a048484ed66b476ae008cac149431fd39f82","tarball":"https://registry.npmjs.org/@agentionai/marshall-tools/-/marshall-tools-0.9.3.tgz","fileCount":102,"integrity":"sha512-Q8JniCevqc8up6pSanBwsevVgHWzd8XLmwojNU+TVJTy7fz+Eilw/7JOY7sPWqEEdf44sFnlnoWlBTgFmOXO7A==","signatures":[{"sig":"MEUCIDm95bPmCBj9y+/Q2xK3kY3P9XKUd6qZJ8b0dAim9iDkAiEA+lq3+ehFZRYcpbzLq2tzwwbbZKf6EWthsjrOYAn1AHY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":342985},"type":"module","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"178f4c00ac8ca6b02ff3b5ef2a3e3919a20d0a77","scripts":{"test":"node --import tsx/esm --test 'src/**/*.test.ts'","build":"node -e \"fs.rmSync('dist',{recursive:true,force:true})\" && tsc -p tsconfig.build.json","prepack":"tsc -p tsconfig.build.json","typecheck":"tsc --noEmit"},"_npmUser":{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"},"_npmVersion":"11.13.0","description":"Reusable, safe-by-default tool implementations for the Marshall coding assistant. Provides Agention `Tool` instances for file operations, shell execution, a private scratch area, and GitHub — all scoped to a workspace directory with a human-in-the-loop ap","directories":{},"_nodeVersion":"24.16.0","dependencies":{"@agentionai/agents":"1.15.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","typescript":"^5.7.0","@types/node":"^25.0.0"},"_npmOperationalInternal":{"tmp":"tmp/marshall-tools_0.9.3_1789081906982_0.7411469200109353","host":"s3://npm-registry-packages-npm-production"}},"0.9.4":{"name":"@agentionai/marshall-tools","version":"0.9.4","_id":"@agentionai/marshall-tools@0.9.4","maintainers":[{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"}],"dist":{"shasum":"8134eae54bb971eee75c7a5cc79f5e574e904d88","tarball":"https://registry.npmjs.org/@agentionai/marshall-tools/-/marshall-tools-0.9.4.tgz","fileCount":102,"integrity":"sha512-QezUwvoBUAlQ+JuHnKUKv/8A6RNmZsabacSsP9k5lzofRHcBaAc441FF1PTlkMbGPntiZc7hyg9ojudLbeddsg==","signatures":[{"sig":"MEUCIBgdr+ebF7VFU2zz5bZ01L0VGyOaRydyelnvr2hHMbwRAiEAvxRk09CYLtCmTD1HHeX3YvedqQ3WZh1PVAlYw7hUOhA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQD2g/89FNCFpvaJkZBNID63d39T4Agcd+k9SHpLIJxjQAIgN0qBWkC8nWZzSvvny34BMryIlMi0lmvNqRLbPR5GYwI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":344785},"type":"module","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"67cbd4781b1d12222af49ee80281e1f9aa1771d6","scripts":{"test":"node --import tsx/esm --test 'src/**/*.test.ts'","build":"node -e \"fs.rmSync('dist',{recursive:true,force:true})\" && tsc -p tsconfig.build.json","prepack":"tsc -p tsconfig.build.json","typecheck":"tsc --noEmit"},"_npmUser":{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"},"_npmVersion":"11.13.0","description":"Reusable, safe-by-default tool implementations for the Marshall coding assistant. Provides Agention `Tool` instances for file operations, shell execution, a private scratch area, and GitHub — all scoped to a workspace directory with a human-in-the-loop ap","directories":{},"_nodeVersion":"24.16.0","dependencies":{"@agentionai/agents":"1.16.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","typescript":"^5.7.0","@types/node":"^25.0.0"},"_npmOperationalInternal":{"tmp":"tmp/marshall-tools_0.9.4_1790530012897_0.31684436692364515","host":"s3://npm-registry-packages-npm-production"}},"0.9.5":{"_id":"@agentionai/marshall-tools@0.9.5","dist":{"shasum":"05f59d51312a097de5c5797eb733e816e2bd70bf","tarball":"https://registry.npmjs.org/@agentionai/marshall-tools/-/marshall-tools-0.9.5.tgz","fileCount":102,"integrity":"sha512-T1vUywxhO7jVJgkPABW/swEyXRU86y8NIvWhihej1tDs36Mah/s+L0V6Sfe1Fpc/3kqKi0TBOcb0lqvvw7XPkg==","signatures":[{"sig":"MEUCIQDAGadn1yQwUj224SrZSOe+BF5E2uwCJJPKVrX2+FZZGwIgegPg9+2cn6tWpl0R86oSON43uo7Kq9TN7isD1nqaIvU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCOnt7kOTG28GGEF3cKcVDp3rvIQY9OwN2TX2PpKKBRfgIhAIPboLqWJ0K9pBSOpYZZc/M0L/e+r6PH/OlKCfJDqjBy"}],"unpackedSize":344785},"name":"@agentionai/marshall-tools","type":"module","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"d4a5410ece38fdccf52dea0c5655148cba040fdf","scripts":{"test":"node --import tsx/esm --test 'src/**/*.test.ts'","build":"node -e \"fs.rmSync('dist',{recursive:true,force:true})\" && tsc -p tsconfig.build.json","prepack":"tsc -p tsconfig.build.json","typecheck":"tsc --noEmit"},"version":"0.9.5","_npmUser":{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"},"_npmVersion":"11.13.0","description":"Reusable, safe-by-default tool implementations for the Marshall coding assistant. Provides Agention `Tool` instances for file operations, shell execution, a private scratch area, and GitHub — all scoped to a workspace directory with a human-in-the-loop ap","directories":{},"maintainers":[{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"}],"_nodeVersion":"24.16.0","dependencies":{"@agentionai/agents":"1.17.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","typescript":"^5.7.0","@types/node":"^25.0.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/marshall-tools_0.9.5_1790532320333_0.2744190536517732"}}},"time":{"created":"2026-08-02T11:53:34.702Z","modified":"2026-09-27T18:05:20.632Z","0.3.0":"2026-08-02T11:53:34.943Z","0.4.0":"2026-08-05T13:08:13.551Z","0.4.1":"2026-08-05T22:05:01.632Z","0.5.0":"2026-08-07T12:22:03.967Z","0.6.0":"2026-08-08T21:16:09.945Z","0.6.1":"2026-08-11T21:51:10.837Z","0.6.3":"2026-08-13T17:11:24.187Z","0.6.4":"2026-08-15T20:58:20.015Z","0.6.5":"2026-08-17T21:04:08.887Z","0.7.0":"2026-08-18T20:47:39.828Z","0.7.1":"2026-08-20T16:59:31.238Z","0.8.0":"2026-09-04T21:48:49.277Z","0.9.0":"2026-09-06T11:52:00.911Z","0.9.1":"2026-09-06T20:00:38.912Z","0.9.2":"2026-09-07T09:48:07.182Z","0.9.3":"2026-09-10T23:11:47.204Z","0.9.4":"2026-09-27T17:26:52.997Z","0.9.5":"2026-09-27T18:05:20.422Z"},"description":"Reusable, safe-by-default tool implementations for the Marshall coding assistant. Provides Agention `Tool` instances for file operations, shell execution, a private scratch area, and GitHub — all scoped to a workspace directory with a human-in-the-loop ap","maintainers":[{"name":"laurent.zuijdwijk","email":"laurent.zuijdwijk@gmail.com"}],"readme":"# @agentionai/marshall-tools\n\nReusable, safe-by-default tool implementations for the Marshall coding assistant. Provides Agention `Tool` instances for file operations, shell execution, a private scratch area, and GitHub — all scoped to a workspace directory with a human-in-the-loop approval gate on every state-changing action.\n\n**Dependency rule:** this package imports only `@agentionai/agents` and Node built-ins. It never imports the engine, CLI, or `vscode`. That boundary is what lets a second consumer (e.g. a VS Code extension) reuse it unchanged.\n\n---\n\n## Structure\n\n```\nsrc/\n├── types.ts               ToolConfig, ApprovalFn, Limits, CommandPolicy, ToolSpec\n├── primitives/            Safety building blocks — no Agention dependency\n│   ├── resolve.ts         resolveInWorkspace: path jail + symlink check\n│   ├── atomic-write.ts    atomicWrite: temp-file + rename\n│   ├── capped-read.ts     cappedRead: size-capped file reads\n│   ├── spawn.ts           spawnSandboxed: scrubbed env, timeout, process-group kill\n│   └── background.ts      createBackgroundJobs: detached jobs that outlive a turn\n└── factories/             Agention Tool instances built on the primitives\n    ├── approval.ts        withApproval: wraps any ToolSpec with an awaited approval gate\n    ├── file-tools.ts      createFileTools → read_file, list_dir, search, write_file, edit_file\n    ├── shell-tool.ts      createShellTool → run_shell\n    ├── job-tools.ts       createJobTools → shell_output, shell_kill, shell_list\n    ├── scratch-tools.ts   createScratchTools → note_write/read/list, log_append/read\n    └── github-tools.ts    createGitHubTools → gh_list_issues, gh_view_issue, gh_list_prs,\n                                               gh_view_pr, gh_diff, gh_create_pr, gh_comment\n```\n\n---\n\n## Config\n\nEvery factory takes a `ToolConfig` — the engine constructs it and injects real values; the tools themselves never read env vars or hard-code paths.\n\n```ts\ninterface ToolConfig {\n  workspaceRoot: string;       // all file paths are jailed here\n  approval: ApprovalFn;        // (request) => Promise<'approve' | 'deny' | 'always'>\n  signal?: AbortSignal;        // threads through to shell processes\n  commandPolicy?: CommandPolicy;\n  limits?: Limits;\n}\n\ninterface Limits {\n  maxFileBytes?: number;       // default 256 KiB\n  maxOutputBytes?: number;     // default 64 KiB per shell stream\n  timeoutMs?: number;          // default 120 s\n  maxSearchResults?: number;   // default 200\n}\n\ntype CommandPolicy =\n  | { mode: 'allowlist'; patterns: RegExp[] }\n  | { mode: 'denylist';  patterns: RegExp[] }\n  | { mode: 'none' };\n```\n\n---\n\n## Tools\n\n### File tools — `createFileTools(config)`\n\n| Tool | Approval | Description |\n|------|----------|-------------|\n| `read_file` | no | Read a file with line numbers. Supports `startLine`/`endLine` for large files. |\n| `list_dir` | no | List files and directories (non-recursive). |\n| `search` | no | Regex search across files. Returns `file:line: content`. |\n| `write_file` | **yes** | Atomic write (temp + rename). File must be read first if it already exists. |\n| `edit_file` | **yes** | Find-and-replace (oldString must appear exactly once). File must be read first. |\n\n**Write guard:** `write_file` and `edit_file` reject writes to existing files that haven't been read in the current session. This prevents blind overwrites.\n\n**`read_file` output format:**\n```\n# src/index.ts  (lines 1–42 of 42)\n 1 | import React from 'react'\n 2 |\n...\n```\n\n### Shell tool — `createShellTool(config)`\n\n| Tool | Approval | Description |\n|------|----------|-------------|\n| `run_shell` | **yes** | Run a command via `sh -c` inside `workspaceRoot`. |\n\nSandbox properties:\n- `cwd` locked to `workspaceRoot`\n- Environment scrubbed to an allowlist (PATH, HOME, USER, LANG, git/gh vars)\n- Killed (process group) on timeout or `AbortSignal`\n- stdout/stderr capped at `maxOutputBytes`\n- Command checked against `commandPolicy` before execution\n\nDefault denylist blocks: `rm -rf /`, `curl|sh`, `wget|sh`, `npm publish`, `git push --force`, `dd if=`, `mkfs`, `shutdown/reboot/halt`.\n\n### Background jobs — `createJobTools(config)`\n\nPresent only when a `BackgroundJobs` registry is injected as `config.jobs`. With one, `run_shell` also accepts `background: true`, which starts the command detached and returns a job id immediately instead of waiting.\n\n| Tool | Approval | Description |\n|------|----------|-------------|\n| `shell_output` | no | Output from a job since the last read, plus its status. |\n| `shell_kill` | no | Stop a running job. |\n| `shell_list` | no | Every job in the session with status and runtime. |\n\nStarting one still goes through `run_shell`'s approval gate and command policy — the prompt says the command will outlive the turn. Reading and stopping are ungated: reads are inert, and stopping a job is inside the blast radius already approved when it started.\n\n```ts\nconst jobs = createBackgroundJobs({ onExit: (job) => notify(job) });\nconst tools = [createShellTool({ ...config, jobs }), ...createJobTools({ ...config, jobs })];\n```\n\nTwo things differ from `spawnSandboxed`, both following from lifetime:\n\n- **The registry is session-scoped and injected, never owned by the factory.** `config.signal` is aborted at the end of every turn, so a job wired to it would be killed exactly when it was meant to keep running. Backgrounded commands therefore ignore `signal` entirely — **whoever creates the registry must call `killAll()` when the session ends**, or detached processes outlive the program.\n- **Output overflow drops the oldest bytes, not the newest.** A one-shot command's output is capped from the front; the interesting end of a dev server's log is the tail. Each job keeps two capped views: `read(id)` returns what has arrived since the last read, `tail(id)` the most recent slice regardless of reads.\n\n`onExit` fires only for jobs that end on their own. `kill` and `killAll` are silent — a caller that asked a process to stop already knows it stopped.\n\nA job also gets a ceiling of its own, `limits.backgroundTimeoutMs` (default 30 min), separate from the foreground `timeoutMs`.\n\n### Scratch tools — `createScratchTools(config)`\n\nNo approval required — these write to `.marshall/` inside the workspace, which is the agent's private space.\n\n| Tool | Description |\n|------|-------------|\n| `note_write` | Write/update a named markdown note in `.marshall/notes/`. |\n| `note_read` | Read a note by name. |\n| `note_list` | List all saved notes. |\n| `log_append` | Append a timestamped entry to `.marshall/session.log`. |\n| `log_read` | Read the session log (optional `tail: N` for last N lines). |\n\n### GitHub tools — `createGitHubTools(config)`\n\nUses the `gh` CLI (must be installed and authenticated). All calls go through `spawnSandboxed`.\n\n| Tool | Approval | Description |\n|------|----------|-------------|\n| `gh_list_issues` | no | List issues (`state`, `label`, `limit`). |\n| `gh_view_issue` | no | View issue body and comments. |\n| `gh_list_prs` | no | List pull requests (`state`, `limit`). |\n| `gh_view_pr` | no | View PR description and review comments. |\n| `gh_diff` | no | Show PR diff. |\n| `gh_create_pr` | **yes** | Create a PR (`title`, `body`, `base`, `draft`). |\n| `gh_comment` | **yes** | Post a comment on an issue or PR. |\n\n---\n\n## Approval gate\n\n`withApproval(spec, approvalFn, buildRequest)` wraps any `ToolSpec` and returns a `Tool` whose `execute` awaits the approval function before proceeding.\n\n```ts\n// Injected by the engine — no TTY dependency in this package\nconst approval: ApprovalFn = (request) => client.requestApproval(request);\n```\n\nOn denial the agent receives: `Action denied by user. Tool \"X\" was not executed. Do not retry this exact action without rephrasing your approach.`\n\nThe approval function is injectable so tools can be unit-tested without a real TTY:\n\n```ts\nconst autoApprove: ApprovalFn = async () => 'approve';\nconst tools = createFileTools({ workspaceRoot, approval: autoApprove });\n```\n\n---\n\n## Safety scope\n\nThe path jail and sandboxed spawn are **containment** boundaries, not hard security boundaries:\n\n- File tools **cannot** read or write outside `workspaceRoot`, including via `..` traversal or symlinks that resolve outside the root.\n- Shell commands **can** still reach the network or absolute paths outside the workspace — the sandbox is a policy boundary, not OS-level isolation.\n- True network/process isolation (Docker, microVM) is out of scope but the tool interface is designed so only the executor behind `spawnSandboxed` needs to change to support it.\n","readmeFilename":"README.md"}