Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/docxology/codomyrmex/mcp_tool_specificationgit clone --depth 1 https://github.com/docxology/codomyrmexWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00546 |
| Opus 5 | $0.00000 | $0.00273 |
| Sonnet 5 | $0.00000 | $0.00109 |
| Haiku 4.5 | $0.00000 | $0.00055 |
Grade A, and why
MCP_TOOL_SPECIFICATION scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 57 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Agents MCP tool specification
This document mirrors the stable MCP surface implemented in
src/codomyrmex/agents/mcp_tools.py. Runtime dynamic tools are discovered
separately and are not represented as a fixed provider count here.
Agent tools
| Invocation | Required input | Behavior |
|---|---|---|
execute_agent |
agent_name, prompt |
Execute one registered agent request and return response metadata. |
list_agents |
none | Return registry descriptors and their declared capabilities. |
get_agent_memory |
session_id |
Return the most recent messages for a persisted agent session. |
The decorated runtime names are the function names above. Older names such as
execute_agent_request, list_available_agents, probe_agent_status, and
register_tool_with_agent are not registered by this module and must not be
used for capability routing.
Navigation tools
The navigation surface is read-only metadata. It does not construct clients, probe credentials, invoke handlers, or claim endpoint operability:
| Tool | Purpose |
|---|---|
list_agent_capabilities |
List bounded agent, module, and tool records. |
search_agent_capabilities |
Search the complete catalog without page-limit false negatives. |
get_agent_capability |
Resolve an exact or unambiguous capability ID. |
agent_operability_status |
Report implementation metadata without live probes. |
Use agent:<name>, module:<name>, or tool:<qualified-name> IDs. A status
of implementation_present means only that the client module can be located;
credentials, network access, and live service health remain unverified.
Operational and security contract
- Tool arguments are validated against their declared JSON Schema before a handler runs.
- MCP/PAI entrypoints apply trust classification and audit logging. Dynamic names containing mutation, VCS, deployment, or external-communication verbs require elevated trust.
- MCP filesystem paths are constrained to the current working tree by
default. Additional roots must be explicitly listed in
CODOMYRMEX_MCP_ALLOWED_ROOTS. - Confirmation tokens for destructive calls are one-use and bound to the exact validated argument payload.
- Dynamic discovery and static definitions use a first-registration-wins collision policy so a discovered handler cannot silently replace a stable contract.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 57 lines · 0 tokens per session scan A 149fd574f629
MCP_TOOL_SPECIFICATION is an agent published in the GitHub repository docxology/codomyrmex (11 stars, last pushed 2d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 546 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
AGENTS
The core Agents SDK, published to npm as agents. This is the most complex package in the monorepo.
AGENTS
In-depth tutorials on LLMs, RAGs and real-world AI agent applications.
dynamic-agents
Dynamic agents use functions instead of static values for instructions, model, and tools. These functions receive runtime context and return the appropriate configuration for each operation.
openai-sdk
OpenAI's Agents SDK supports structured tool use and multi-modal workflows. ContextForge can serve as a unified tool registry for OpenAI agents.
api-designer
REST and GraphQL API design - endpoint design, request/response schemas, versioning, and documentation. Use for designing new APIs or evolving existing ones.
accessibility-specialist
Accessibility expert: WCAG 2.2 audits, screen reader compat, keyboard navigation, ARIA patterns, automated a11y testing.