use super::{COMMAND, Classified, Effect, Request, Root};
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
pub(super) enum Known {
ReadFile,
LoadSkill,
Message,
Dispatch,
ApplyPatch,
Cd,
Bash,
Python,
Remember,
SearchHistory,
ReadToolOutput,
WriteSummary,
MarkForDeletion,
Clients,
}
impl Known {
pub(super) fn of(name: &str) -> Option<Known> {
match name {
"read_file" => Some(Known::ReadFile),
"load_skill" => Some(Known::LoadSkill),
"message" => Some(Known::Message),
"dispatch" => Some(Known::Dispatch),
"apply_patch" => Some(Known::ApplyPatch),
"cd" => Some(Known::Cd),
"bash" => Some(Known::Bash),
"python" => Some(Known::Python),
"remember" => Some(Known::Remember),
"search_history" => Some(Known::SearchHistory),
"read_tool_output" => Some(Known::ReadToolOutput),
"write_summary" => Some(Known::WriteSummary),
"mark_for_deletion" => Some(Known::MarkForDeletion),
"clients" => Some(Known::Clients),
_ => None,
}
}
}
pub(super) fn row(
known: Known,
request: &Request,
root: &Root,
policy: &super::super::policy::Policy,
) -> Classified {
match known {
Known::ReadFile => Classified::new(Effect::Read, "reads a file"),
Known::SearchHistory => Classified::new(
Effect::Read,
"searches the conversation's own history, which it observes and does not touch",
),
Known::ReadToolOutput => Classified::new(
Effect::Read,
"pages this agent's own captured tool output, which it reads and does not touch",
),
Known::Remember => Classified::new(
Effect::TargetWrite,
"proposes one durable fact onto a staged branch the operator accepts or drops",
),
Known::LoadSkill => Classified::new(
Effect::TargetWrite,
"writes a skill body into the agent worktree",
),
Known::Message => Classified::new(
Effect::TargetWrite,
"deposits into another agent's inbox through the world's own gated verb",
),
Known::WriteSummary => Classified::new(
Effect::TargetWrite,
"writes the conversation's own summary onto the compactor branch",
),
Known::MarkForDeletion => Classified::new(
Effect::TargetWrite,
"stages the conversation's own files for deletion inside its worktree, where git still holds them",
),
Known::Dispatch => Classified::new(
Effect::Process,
"mints an agent, under the harness's own budget and depth gates",
),
Known::Python => Classified::new(
Effect::OpenWorld,
"runs a program the model authored, whose reach no input field states",
),
Known::Clients => clients(&request.field("op")),
Known::ApplyPatch => super::operand::patch(&request.field("input"), root),
Known::Cd => super::operand::move_to(&request.field("path"), root),
Known::Bash => super::super::bash::classify(&request.field(COMMAND), root, policy),
}
}
fn clients(op: &str) -> Classified {
if op == "load" {
Classified::new(
Effect::TargetWrite,
"loads a client's tool into this agent's own loaded set",
)
} else {
Classified::new(Effect::Read, "reads the workspace's client roster")
}
}