tool__basetool_

A software abstraction that gives an AI agent a defined way to use outside capabilities, such as web search, databases, code execution, or service APIs. An agent is a program that uses an AI model to complete tasks.

In plain words
What is it for?
It helps agents fetch current information, search knowledge bases, run Python code, and interact with external services such as booking or management APIs.
Why use it?
An AI model alone may have outdated knowledge and cannot directly access current information or perform external actions. Tools provide controlled ways to obtain data or carry out operations.

Cursor rule

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/altaidevorg/rules-for-ai/tool__basetool_
Clone the repo
git clone --depth 1 https://github.com/altaidevorg/rules-for-ai
Per session 0 Nothing until a file matches its globs; then the whole rule loads.
When invoked 4,733 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.04733
Opus 5 $0.00000 $0.02367
Sonnet 5 $0.00000 $0.00947
Haiku 4.5 $0.00000 $0.00473

Measured 2d ago against content hash 3ee497315302, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

tool__basetool_ scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

examples/google-adk/tool__basetool_.mdc · 335 lines

How it starts

The opening of the file, as written. The whole thing — 335 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Chapter 7: Tool (BaseTool)

In the previous chapter, we explored BaseLlm, the abstraction enabling agents to leverage the generative power of Large Language Models. However, LLMs alone have limitations – their knowledge is often frozen in time, and they cannot directly interact with the outside world or execute specific tasks beyond text generation. This chapter introduces the Tool abstraction (BaseTool), which empowers agents to overcome these limitations by providing defined capabilities.

Motivation and Use Case

Imagine an Agent (BaseAgent / LlmAgent) tasked with answering "What's the current weather in Tokyo?". Without external access, the LLM could only provide information based on its training data, which might be outdated. To provide a real-time answer, the agent needs a capability to fetch current weather data.

Similarly, an agent might need to:

  • Search the web for recent news (google_search).
  • Look up information in a specific database or knowledge base (VertexAiSearchTool, BaseRetrievalTool).
  • Execute a piece of Python code (built_in_code_execution).
  • Interact with an external service via its API (e.g., booking a flight, managing calendar events) (RestApiTool).
  • Delegate a sub-task to another specialized agent (AgentTool).

The Tool abstraction provides a standardized way to define, declare, and execute these diverse capabilities, making them available for the LLM to use intelligently.

Central Use Case: A user asks an LlmAgent, "Find recent articles about advancements in solar panel efficiency and summarize them." The agent, equipped with a google_search tool, identifies the need for external information. The underlying BaseLlmFlow orchestrates the process:

  1. The LLM generates a request to use the google_search tool with a query like "recent advancements solar panel efficiency".
  2. The framework identifies the corresponding GoogleSearchTool instance.
  3. The tool's logic (which might be built-in model functionality or a client-side implementation) executes the search.
  4. The search results are returned to the LLM.
  5. The LLM processes the results and generates the final summary for the user.

Read the full file on GitHub · 335 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 335 lines · 0 tokens per session scan A 3ee497315302

Subscribe to this mod's changes

tool__basetool_ is a cursor rule published in the GitHub repository altaidevorg/rules-for-ai (2 stars, last pushed 1y ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 4,733 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.