Tool Inventory · Two-Layer Dispatch × Language Intelligence

CodePapr exposes 25 merged tools to the LLM, routed to 61 fine-grained execution engines. Code intelligence tightly integrates LSP semantic analysis and AST syntax trees, offering automated fallback tolerance, pre-write syntax checks, and post-write diagnostic feedback for high-precision autonomous coding.

LSP-backed AST-backed LSP + AST Hybrid Text / System Multimodal / Reasoning
25
LLM-Visible Merged Tools
graph subagent-only
61
Fine-Grained Handlers
workspace / shell / browser
15
Native LSP Languages
Rust backend drivers
17
AST Syntax Support
tree-sitter parsers
11
Regex Fallback Langs
6
Core Read/Write Tools
integrated with LSP/AST
01

File Operations Core I/O

read / write / edit / patchgrep / glob / list
AST Syntax Pre-checkAuto-attached LSP Diagnostics
Read, Write & Edit Direct Content Manipulation
READ
read workspace_read_fileText + AST
Reads project files. Supports startLine / endLine slicing and aroundLine context windows; accepts a symbol parameter for AST-targeted definition extraction; large files automatically attach a lightweight symbol outline.
Route: read → workspace_read_file (Tauri command) → JSON-RPC fs/readTextFile → codepapr-server → codepapr-core::workspace_fs. If symbol is passed, AST locates the exact line range; output is truncated safely (>60k chars folded in middle, >100k offloaded to disk with 2k preview, 150k hard cap).
WRITE
write workspace_write_fileText + AST/LSP
Creates or overwrites files. Runs an AST syntax pre-check prior to disk writes (blocks newly introduced syntax errors), verifies consistency via immediate re-read, and returns fresh LSP diagnostics directly in the tool result.
Route: write → workspace_write_file (Tauri command) → JSON-RPC fs/writeTextFile → codepapr-server → codepapr-core::workspace_fs. Pre-check compares before/after syntax errors, rejecting regressions; triggers lsp_open_document to refresh diagnostics, then sends a JSON-RPC notification (workspace-files-changed) back through the Tauri event bus to invalidate stale graph caches.
EDIT
edit workspace_apply_patchText + AST/LSP
Precise single-file SEARCH/REPLACE. Strict literal matching eliminates fuzzy drift; on multiple matches, it errors out explicitly reporting each match's line number and enclosing symbol; includes AST pre-checks and post-write LSP diagnostics.
Route: edit → workspace_apply_patch. Byte-exact String.indexOf matching. Ambiguities resolve symbols via AST to produce actionable disambiguation errors; returns fresh LSP diagnostics for the modified file (max 20MB).
PATCH
patch workspace_apply_diffText + AST/LSP
Multi-file atomic SEARCH/REPLACE. All patches must match cleanly before any changes are written to disk; any failure rolls back the entire batch. Shares the exact literal matching, ambiguity reporting, AST checks, and LSP diagnostics with edit.
Route: patch → workspace_apply_diff. Pre-checks ambiguity against live buffer content → applies sequential diffs → runs per-file AST verification & writes → emits batch mutation updates.
Search & Traversal Pattern Matching & Outlines
GREP
grep workspace_search_textText + LSP
Primary entry point for searching code content (defaults to regex with smart-case and contextLines). Setting semantic: true switches to LSP workspace symbol search, gracefully degrading to regex if LSP is inactive.
Route: Defaults to workspace_search_text; semantic: true routes to workspace_workspace_symbol. Falls back to regex with degraded: true when LSP is absent.
GLOB
glob workspace_search_filesPlain Text
Finds files by glob patterns (e.g., **/*.test.ts). The dispatch layer converts glob syntax to optimized regex expressions for high-performance scanning.
Route: glob → globToRegex → workspace_search_files.
LIST
list workspace_list_filesText + AST
Browses directory trees (default depth 2, max 6), automatically attaching top-level AST symbol summaries (functions, classes, interfaces) for each discovered code file to quickly grasp project architecture.
Route: list → workspace_list_files (Tauri command) → JSON-RPC fs/listFiles → codepapr-server → codepapr-core directory scan + concurrent AST top-level symbol extraction into symbolsByFile.
IMG
read_image workspace_read_imageMultimodal
Reads local image files (PNG/JPEG/WebP/GIF) into Base64 strings for vision models (5MB max). Dynamically hidden from the model when multimodal capabilities are disabled.
Route: read_image → workspace_read_image (Tauri command) → JSON-RPC fs/readFile → codepapr-server → codepapr-core native I/O. Stripped from toolsets unless the current slot has vision enabled (explicit profile setting wins; unconfigured known text-only models default off; a vision-capable fast slot is used as fallback).
02

Code Intelligence LSP & AST Analysis

lsp / lsp_edit / diagnosticsgraph (subagent)
LSP → AST Fallbacksource & confidence tags
Semantic Navigation & Editing Precise Symbol Operations
LSP
lsp 9 Navigation ActionsLSP → AST
Read-only semantic code navigation: goToDefinition, findReferences, hover, documentSymbol, workspaceSymbol, goToImplementation, prepareCallHierarchy, incomingCalls, outgoingCalls. LSP-first; automatically falls back to AST project graphs when LSP is unavailable.
Route: Dispatches to corresponding LSP handlers; on timeout (30s) or uninitialized servers, falls back to AST symbol queries with source: "ast", confidence: "medium".
LEDIT
lsp_edit rename / code_action / formatLSP Semantics
Semantic code transformation complementary to literal editing: safe cross-file symbol renaming (rename), quickfixes and organizing imports (code_action, e.g., source.organizeImports), and batch formatting (format).
Route: Calculates WorkspaceEdits via LSP textDocument/rename before committing, ensuring atomic multi-file consistency.
DIAG
diagnostics File Review / Project ChecksLSP Diagnostics
Queries LSP diagnostics for a specific file or runs project-wide lint/typechecks via project: true. Note: file writing tools already return real-time diagnostics; this tool is designed for explicit verification and full-project audits.
Route: Single-file queries use JSON-RPC lsp/diagnostics (codepapr-server → codepapr-core::lsp; short-circuits on fresh diagnostics, 2s timeout guard); project-wide mode aggregates issues across active language providers.
Global Architecture & Deep Analysis Explore Subagent Exclusive
GRAPH
graph 14 Analysis Actions · Explore ExclusiveAST Project Graph
Cross-module dependency and impact analysis engine. Features 8 architectural queries (overview, lookup, dependency, entrypoints, impact, implementations, smart_context, etc.) and 6 static analyzers (dead code, circular dependencies, type hierarchy, refactoring suggestions, test impact). Soft-hidden from Main Agent and delegated to Explore.
Constructs unified project graphs from AST and LSP edges; includes a 60-second build cache with in-flight deduplication, cleared automatically on file mutations. Also acts as the fallback backend for lsp queries.
03

Command & Process Execution Layer

bashforeground / background / process control
Direct Shell Executionworkdir & lifecycle control
BASH
bash workspace_run_shell_commandSystem Process
Executes terminal commands in the project root or specified workdir. action: "run" blocks for completion; background: true starts long-running processes and returns PIDs; list / stop / stop_all manage background jobs. File searches should use grep instead of bash grep/rg.
Route: Foreground execution routes to workspace_run_shell_command; background jobs route to workspace_start_shell_background_command with process supervision and automatic teardown.
04

Version Control Git Workspace

8 ActionsIsolated Workspace
Safety SnapshotsAutomated backup branches on destructive ops
GIT
git status / diff / log / branch / stage / commit / restore / resetGit Manager
Built-in Git operations workspace. Supports staging, committing, diffing, and branch switching; automatically creates safety snapshots and backup branches prior to destructive operations like reset or restore.
Dispatches to fine-grained workspace_git_* handlers. Reset actions enforce target parameters and backup branch prefixes with undo snapshot rollback protection.
05

Web & Browser External Data & DOM

webfetch / websearch / browser
Embedded BrowserDOM interactions & screenshots
WEB
webfetch / websearch Web Scraping & SearchNetwork I/O
webfetch: Fetches webpage content and converts it into clean Markdown; setting save: true downloads raw or binary resources to .CodePapr/downloads/. websearch: Connects to SearXNG for real-time technical search.
webfetch routes to web_fetch_url or web_download_file; websearch queries the backend search aggregator directly.
BRWS
browser 9 Interactive ActionsEmbedded Browser
Desktop sandboxed browser automation: open, navigate, reload, close, click, type, read (DOM extraction), screenshot, and get (state retrieval).
Built on Tauri embedded Webviews, supporting selector-based clicks, form fills, and visual page verification for automated web debugging.
06

Project Memory File & Curator

.CodePapr/MEMORY.md · memory curator (internal, no tools)
File + curatorCross-session memory, injected in full every turn
MEM
.CodePapr/MEMORY.mdProject memory file
A single Markdown file in the workspace (three sections: user preferences & constraints / tech stack & environment / architecture & known facts), hard-capped at 120 lines / ~4000 tokens. The built-in memory curator maintains it at two checkpoints — delivery (dual-signal gate) and pre-compaction (unconditional, 20s timeout) — with mechanical gates for secrets, injection, dangerous commands, size, and memory-washing.
The Agent has no memory_* tools and direct file writes are rejected; every turn reads the file into session bootstrap (effective the next turn after saving). The panel (Context inspector → Memory) is that file's editor: budget bar + save + curator status line.
07

App & Auxiliary Runtime Helpers

app_render / app_publish / skill / question / todo
Sandboxed RenderingInteractive application panel
APP
app_render / app_list / app_start / app_stop / app_deleteApp Mode
app_render: Opens interactive apps already written under .CodePapr/apps/<appId>/ (sandboxed iframe with Papr SDK); paired with app_* tools to manage application lifecycle. Files must be written with write/edit/patch; app_render only mounts.
app_render is strictly disabled for subagents to prevent recursive rendering loops; pass appId only. Permissions, agents, and backend processes live in manifest.json. app_list is App-mode only: duplicate checks and running state. The coding Agent discovers publish targets from session context, not from list.
PUSH
app_publishAgent→App Push
app_publish: Pushes content to an app/plugin channel (kanban boards, progress panels, canvases). Events are atomically appended to inbox:<channel> in the app's db.sqlite (concurrency-safe); when the app is mounted they are also delivered live via papr://event (received by papr.events.on); when unmounted they additionally enter a short (~30s) live queue so an app opening moments later (e.g. auto-revealed) still receives them live. Available in all modes except Ask.
How the Agent knows what to push: do not call app_list. That tool is App-mode only (duplicate checks / backend lifecycle). The coding Agent reads session context "## Enabled plugins", which lists enabled overlays that declared inbox plus fullscreen apps that declared inbox. Follow that appId / channel / example. Self-refreshing widgets without inbox (tickers, clocks) stay out of context — do not publish to them.

Once inbox is declared, only those channels are accepted (unknown channels are rejected with the valid list). inbox:* keys are written only by app_publish — the app side is read-only. Payload capped at 256KB; last 200 events kept per channel. Examples are truncated before they enter context so the catalog stays short.
AUX
skill / question / todo / local_time_nowSession Helpers
skill loads modular capability instructions; question presents structured multi-choice prompts to the user in Plan mode; todo tracks task lists; local_time_now returns the local timestamp.
skill routes to skill_load; question returns structured UI selection cards; availability across modes (Ask/Plan/Agent) is governed by strict whitelists.
08

Agent Tool Matrix Role-Based Whitelists

Main Agent + 3 Subagents + 2 Internal Agents
Principle of Least PrivilegeStrict Role Isolation
Main Agent Primary Orchestrator · Full Read/Write/Execute
MAIN
Main Agent Full CapabilitiesAll-in-One
Holds all reading, writing, and execution tools except graph. Uses list for project directory outlines, lsp for symbol navigation, and delegates deep dependency or architectural queries to Explore via task. Mutating tools are intercepted in Ask read-only mode; question is enabled in Plan mode.
graph is soft-hidden from the LLM prompt (registered internally for UI panels and Explore). Ask mode enforces write guards via MUTATING_TOOL_NAMES.
Subagents Isolated Sessions · Whitelist Filtered
EXPL
Explore Code Exploration & Architecture · 8 Read-Only ToolsRead-Only
Tool set: read / read_image / list / graph / glob / lsp / diagnostics / grep. Exclusively granted graph capabilities for dependency mapping, impact evaluation, and symbol discovery without write permissions.
Registered with exposeGraphToLlm: true to unmask the graph tool; read_image is dynamically stripped when multimodal support is disabled.
SCOUT
Scout Web Research & Documentation · 4 ToolsWeb Only
Tool set: websearch / webfetch / browser / read_image. Specializes in researching external technical documentation, browsing web pages, and downloading reference materials without accessing project source code.
Downloads external resources safely into .CodePapr/downloads/ via webfetch save: true for subsequent consumption by the main agent.
MNTR
Mentor Architecture & Algorithm Guidance · Pure ReasoningZero Tools
Configured with zero tools ({}). Operates strictly on the conversation context reported by the main agent to provide architectural design, algorithmic choices, and debugging strategies without tool competition or latency overhead.
Configured with an empty whitelist {}; if information is insufficient, it instructs the main agent to gather required facts.
Internal Agents Runtime Direct Execution · Not Exposed to Tasks
VRFY
Verifier Goal Verifier · 4 Read-Only ToolsVerification
Tool set: read / grep / glob / list. Autonomous verifier for Goal loops: reviews execution histories and directly inspects output files to impartially evaluate goal completion without confirmation bias.
Driven by GoalRunner with a dedicated budget: max 6 tool turns, 3-minute timeout, independent token limits, and thinking mode disabled.
CMPT
Compactor Context Compactor · Pure ReasoningZero Tools
Configured with zero tools ({}). Intervenes when conversation history approaches threshold limits, condensing goals, constraints, completed tasks, and pending items into a structured recovery snapshot JSON.
Isolated from skills/memory injections with cancellation signal handling; automatically falls back to rule-based compaction if fast models are unavailable.

End-to-End Execution Pipeline

Taking edit precise search/replace as an example: from LLM call to safe disk persistence.
L0LLM Invocationedit(search, replace)
→
L1Merge LayerType & permission validation
→
L2Dispatch RouteRemaps to apply_patch
→
L3Pre-checkRe-reads file, pinpoints symbols
→
L4Literal Edit & ASTLiteral replace, blocks new errors
→
L5JSON-RPC Writefs/writeTextFile → codepapr-server
→
L6Host Persistencecodepapr-core::workspace_fs writes
→
L7Verify & SyncReturns diagnostics via JSON-RPC notification, clears cache