Skip to main content

Read this reference

Availability rules: Normal mode exposes the registered set; state-changing tools ask for approval interactively. Plan mode uses a strict allowlist and denies every unknown or action-capable tool. Orchestrate mode adds delegation and native file editing tools: the parent may make basic edits, but delegates significant implementation and testing. Auto mode bypasses review for known-safe observations and guarded native workspace mutations, then model-reviews actions with remaining scope or safety risk. Yolo mode keeps the registered set but bypasses approvals. Optional tools appear only after their prerequisite is available.
All paths are workspace-relative; absolute paths and upward escapes are rejected. In plan mode, every target in a batch must qualify. The orchestrate parent can use write_file and edit_file for basic edits. Existing files need a prior read before write_file replaces them. Use edit_file for an exact replacement that fails safely when its old text is absent.

Execution and compute

Completed foreground subagent calls return token usage, runtime, step and tool-call counts, and bounded model/tool timing samples and cumulative durations. Overlapping calls can make cumulative tool time exceed wall time; detached acknowledgements do not contain this telemetry. process.spawn accepts waitForExit for one-call finite work, notifyOnExit (default true for detached processes), and one-shot literal notifyOnMatch for readiness or important output. Interactive notifications resume the model without a polling tool call and remain hidden from the user transcript. Persistent compute tools intentionally retain state during the session; use them for analysis that benefits from one continuous runtime rather than repeated shell invocations.

Coordination, memory, and recovery

Memory recall itself is automatic and read-only; memory_search is for explicit inspection or a different query. The dedicated Memory guide covers scope, storage, retrieval, and mutations. read_tool_result remains available in the terminal UI even when output truncation is currently disabled, so previously trimmed output can still be recovered. Headless runs stream their events/results directly and do not register the interactive clarification or result-paging tools.

Web and remote capabilities

Web fetch uses the strict URL policy. MCP servers are not a privileged bypass: once selected, their remote tools go through ordinary dispatch, approval, cancellation, and per-server concurrency controls.

Extensions running around the tools

Extensions subscribe to lifecycle seams around the agent loop. They are not tools the model invokes directly; they shape execution, visibility, persistence, and safety.
Toggleable extension choices persist in configuration and apply after the agent is rebuilt for the next run. Event streaming, safety gates, and the active UI wiring are intentionally not toggleable because disabling them would break the host contract.

What this CLI does not register

The workspace also includes an fs_admin_tools library bundle—copy_file, rename_file, delete_file, create_folder, and file_info—for restricted shell-less hosts. Orcacode does not register this bundle today. File information in the terminal agent comes from normal reading/searching, and filesystem administration remains available through the gated shell where appropriate.