example_tools

A practical guide to configuring the built-in tools available to agents. It uses real examples for tools such as HTTP requests and Slack notifications and points to the full configuration reference.

In plain words
What is it for?
Setting up read-only HTTP health checks, Slack alert messages, and other built-in tools using YAML examples from the project.
Why use it?
It provides working configuration patterns and explains important settings, reducing guesswork when adding tools to an agent role.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/vladkesler/initrunner/example_tools
Clone the repo
git clone --depth 1 https://github.com/vladkesler/initrunner
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 4,948 The whole file, excluding the scripts and references it only reads on demand.
Security scan C 2 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.04948
Opus 5 $0.00000 $0.02474
Sonnet 5 $0.00000 $0.00990
Haiku 4.5 $0.00000 $0.00495

Measured 2d ago against content hash b8abe955c4bc, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade C, and why

example_tools scanned grade C with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Recursive force deletehighDestructive command

rm -rf with a variable or a broad path is one typo away from removing the wrong tree.

> `allowed_commands` is an allowlist — only these binaries can be invoked. `require_confirmation: false` is safe here because the commands are read-only status checks. For write operations, keep the default `true`. The s

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

- curl
docs/agents/example_tools.md · 544 lines

How it starts

The opening of the file, as written. The whole thing — 544 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Tool Examples — Practical Cookbook

This guide shows how to configure each built-in tool type using real examples from examples/roles/. For the full configuration reference (all fields, defaults, types), see tools.md. For writing custom tools and plugins, see tool_creation.md.

Each section shows the relevant YAML snippet, explains key configuration choices, and links to the complete example file.


HTTP Tool — Uptime Monitoring

Make GET requests to a base URL and check endpoint health.

tools:
  - http:
      base_url: https://api.example.com
      allowed_methods:
        - GET
      headers:
        Accept: application/json

allowed_methods: [GET] restricts the agent to read-only requests — it cannot POST, PUT, or DELETE. The base_url is prepended to every path the agent passes to http_request().


Slack Tool — Alert Notifications

Post messages to Slack channels via an incoming webhook.

tools:
  - slack:
      webhook_url: "${SLACK_WEBHOOK_URL}"
      default_channel: "#ops-alerts"
      username: Uptime Monitor
      icon_emoji: ":satellite:"

webhook_url uses ${VAR} syntax — the env var is resolved at runtime. This keeps secrets out of version control. default_channel, username, and icon_emoji set the appearance of posted messages.


SQL Tool — Database Queries

Query a SQLite database with engine-level write protection.

tools:
  - sql:
      database: ./sample.db
      read_only: true
      max_rows: 100

read_only: true enables PRAGMA query_only=ON at the SQLite engine level — no regex filtering, the engine itself rejects writes. max_rows caps result sets to prevent large outputs from consuming context window.

Read the full file on GitHub · 544 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 544 lines · 0 tokens per session scan C b8abe955c4bc

Subscribe to this mod's changes

example_tools is an agent published in the GitHub repository vladkesler/initrunner (41 stars, last pushed 4d ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 4,948 tokens. A static security scan graded it C with 2 findings (recursive force delete, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.