stellar_agent_toolsets/lib.rs
1//! Toolset format parsing and capability-manifest validation.
2//!
3//! ## What this crate does
4//!
5//! Parses and validates a toolset directory's `TOOLSET.md` (agentskills format)
6//! and the wallet capability manifest carried in the frontmatter `metadata`
7//! map. The result is either a validated, typed [`Toolset`] value or a typed
8//! [`ToolsetFormatError`] refusal.
9//!
10//! This crate also provides the pre-canonicalisation argument validation guard
11//! [`validate_toolset_tool_args`], which must be called at BOTH toolset dispatch
12//! sites before `serde_json::from_value::<TypedArgs>`. The guard and its
13//! constants ([`TOOLSET_ARGS_MAX_DEPTH`], [`TOOLSET_ARGS_MAX_NODES`],
14//! [`ARGS_KEY_DENYLIST`]) are defined here so both the MCP dispatcher and the
15//! CLI execution path can consume them without an MCP dependency.
16//!
17//! This crate is the FORMAT + PARSE/VALIDATE substrate only. It performs no
18//! install, no signing, no runtime enforcement, no MCP/CLI registration, and no
19//! network I/O.
20//!
21//! ## Primary consumers
22//!
23//! - Toolset install/uninstall components — call [`parse_toolset`] before verifying
24//! the publisher key.
25//! - Capability enforcement and MCP/CLI registration — consume the
26//! [`CapabilitySet`] and [`Toolset::allowed_tools`] produced here.
27//! - MCP dispatcher — calls [`validate_toolset_tool_args`] at both ungated and
28//! gated dispatch sites.
29//!
30//! ## What this crate does NOT do
31//!
32//! - Install, uninstall, tarball handling, or publisher-signature verification.
33//! - Runtime capability enforcement against agent tool invocations.
34//! - First-invoke gate or attestation gate.
35//! - Executable `scripts/` execution or sandboxing.
36//!
37//! ## Sibling crates
38//!
39//! - `stellar-agent-core` — profile management, policy engine, audit log.
40//! - `stellar-agent-network` — RPC transport, signing, keyring storage.
41//! - `stellar-agent-mcp` — MCP dispatcher that calls [`validate_toolset_tool_args`].
42
43#![forbid(unsafe_code)]
44#![deny(missing_docs)]
45
46pub mod args_error;
47pub mod capability;
48pub mod error;
49pub mod parse;
50pub mod sanitise;
51pub mod validate;
52
53pub use args_error::ToolsetArgsError;
54pub use capability::{Capability, CapabilitySet};
55pub use error::ToolsetFormatError;
56pub use parse::{Toolset, parse_toolset};
57pub use sanitise::sanitise_display;
58pub use validate::{
59 ARGS_KEY_DENYLIST, TOOLSET_ARGS_MAX_DEPTH, TOOLSET_ARGS_MAX_NODES, validate_toolset_tool_args,
60};
61
62/// Public test-helper for parsing a capability value string into a
63/// [`CapabilitySet`].
64///
65/// Only available under `#[cfg(any(test, feature = "test-helpers"))]`.
66/// Sibling crates use this in tests to build `CapabilitySet` values without
67/// depending on internal crate details.
68#[cfg(any(test, feature = "test-helpers"))]
69pub use capability::parse_capability_value_pub;