MCP_TOOL_SPECIFICATION

A reference for the standard MCP tools exposed by Codomyrmex. MCP is a way for an agent to call tools and read structured information from another program.

In plain words
What is it for?
Use it to run registered agents, list their capabilities, read agent session memory, and inspect available agent or module metadata.
Why use it?
It clarifies each tool's required input and avoids relying on outdated tool names or unsupported behavior.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/docxology/codomyrmex/mcp_tool_specification
Clone the repo
git clone --depth 1 https://github.com/docxology/codomyrmex
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 546 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.00546
Opus 5 $0.00000 $0.00273
Sonnet 5 $0.00000 $0.00109
Haiku 4.5 $0.00000 $0.00055

Measured 2d ago against content hash 149fd574f629, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

MCP_TOOL_SPECIFICATION scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

docs/modules/agents/MCP_TOOL_SPECIFICATION.md · 57 lines

How it starts

The opening of the file, as written. The whole thing — 57 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Agents MCP tool specification

This document mirrors the stable MCP surface implemented in src/codomyrmex/agents/mcp_tools.py. Runtime dynamic tools are discovered separately and are not represented as a fixed provider count here.

Agent tools

Invocation Required input Behavior
execute_agent agent_name, prompt Execute one registered agent request and return response metadata.
list_agents none Return registry descriptors and their declared capabilities.
get_agent_memory session_id Return the most recent messages for a persisted agent session.

The decorated runtime names are the function names above. Older names such as execute_agent_request, list_available_agents, probe_agent_status, and register_tool_with_agent are not registered by this module and must not be used for capability routing.

The navigation surface is read-only metadata. It does not construct clients, probe credentials, invoke handlers, or claim endpoint operability:

Tool Purpose
list_agent_capabilities List bounded agent, module, and tool records.
search_agent_capabilities Search the complete catalog without page-limit false negatives.
get_agent_capability Resolve an exact or unambiguous capability ID.
agent_operability_status Report implementation metadata without live probes.

Use agent:<name>, module:<name>, or tool:<qualified-name> IDs. A status of implementation_present means only that the client module can be located; credentials, network access, and live service health remain unverified.

Operational and security contract

  • Tool arguments are validated against their declared JSON Schema before a handler runs.
  • MCP/PAI entrypoints apply trust classification and audit logging. Dynamic names containing mutation, VCS, deployment, or external-communication verbs require elevated trust.
  • MCP filesystem paths are constrained to the current working tree by default. Additional roots must be explicitly listed in CODOMYRMEX_MCP_ALLOWED_ROOTS.
  • Confirmation tokens for destructive calls are one-use and bound to the exact validated argument payload.
  • Dynamic discovery and static definitions use a first-registration-wins collision policy so a discovered handler cannot silently replace a stable contract.

Read the full file on GitHub · 57 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 57 lines · 0 tokens per session scan A 149fd574f629

Subscribe to this mod's changes

MCP_TOOL_SPECIFICATION is an agent published in the GitHub repository docxology/codomyrmex (11 stars, last pushed 2d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 546 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.