Skip to content

feat(deepagents): add filesystem tool allowlist - #671

Merged
Hunter Lovell (hntrl) merged 12 commits into
mainfrom
hunter/fs-tools-allowlist
Jul 14, 2026
Merged

feat(deepagents): add filesystem tool allowlist#671
Hunter Lovell (hntrl) merged 12 commits into
mainfrom
hunter/fs-tools-allowlist

Conversation

@hntrl

Copy link
Copy Markdown
Member

Summary

Adds a tools allowlist option to createFilesystemMiddleware so callers can restrict which built-in filesystem tools are exposed to the model. The middleware now builds the filesystem system prompt from the tools that are actually visible on the request, avoiding instructions for tools that were filtered by the allowlist or backend capability checks.

Changes

  • Adds a public FsToolName type and tools option to FilesystemMiddlewareOptions.
  • Filters filesystem middleware tools at construction time when an explicit allowlist is provided, while preserving existing execute backend capability filtering.
  • Requires read_file in explicit allowlists because it is needed for filesystem workflows and large-result recovery.
  • Generates the filesystem tool prompt dynamically from visible filesystem tools, and only appends execute-specific instructions when execute is actually available.
  • Adds unit and integration coverage for allowlist behavior, prompt filtering, unsupported execute, and user-provided non-filesystem tools.

@vercel

vercel Bot commented Jul 13, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
deepagentsjs-ui Ready Ready Preview, Comment Jul 14, 2026 8:27pm

Request Review

@changeset-bot

changeset-bot Bot commented Jul 13, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 5c3d982

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
Name Type
deepagents Minor
deepagents-acp Patch
@deepagents/evals Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pkg-pr-new

pkg-pr-new Bot commented Jul 13, 2026

Copy link
Copy Markdown

Open in StackBlitz

deepagents-acp

npm i https://pkg.pr.new/deepagents-acp@671

deepagents

npm i https://pkg.pr.new/deepagents@671

@langchain/sandbox-standard-tests

npm i https://pkg.pr.new/@langchain/sandbox-standard-tests@671

@langchain/daytona

npm i https://pkg.pr.new/@langchain/daytona@671

@langchain/deno

npm i https://pkg.pr.new/@langchain/deno@671

@langchain/modal

npm i https://pkg.pr.new/@langchain/modal@671

@langchain/node-vfs

npm i https://pkg.pr.new/@langchain/node-vfs@671

@langchain/quickjs

npm i https://pkg.pr.new/@langchain/quickjs@671

commit: 5c3d982

@hntrl Hunter Lovell (hntrl) changed the title feat(filesystem): add filesystem tool allowlist feat(deepagents): add filesystem tool allowlist Jul 13, 2026

@open-swe open-swe Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Open SWE Review found 2 potential issues.

Open in WebView Open SWE trace

Comment thread libs/deepagents/src/middleware/fs.ts
Comment thread libs/deepagents/src/middleware/fs.ts

@open-swe open-swe Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Open SWE Review found 1 potential issue.

Open in WebView Open SWE trace

Comment thread libs/deepagents/src/agent.test.ts Outdated
@hntrl
Hunter Lovell (hntrl) merged commit 6ae9d1e into main Jul 14, 2026
22 checks passed
@hntrl
Hunter Lovell (hntrl) deleted the hunter/fs-tools-allowlist branch July 14, 2026 20:42
@github-actions github-actions Bot mentioned this pull request Jul 14, 2026
Colin Francis (colifran) pushed a commit that referenced this pull request Jul 16, 2026
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## deepagents@1.11.0

### Minor Changes

- [#671](#671)
[`6ae9d1e`](6ae9d1e)
Thanks [@hntrl](https://github.com/hntrl)! - feat(filesystem): add
allowlist for filesystem middleware tools

- [#669](#669)
[`4643148`](4643148)
Thanks [@hntrl](https://github.com/hntrl)! - feat(deepagents): add
structured system prompt configuration

- [#673](#673)
[`eb18c70`](eb18c70)
Thanks [@hntrl](https://github.com/hntrl)! - feat(backends): add delete
protocol support

Adds a `DeleteResult` type and optional backend `delete` method,
preserves delete through backend protocol adaptation, and implements
file deletion across the built-in state, store, filesystem, composite,
context hub, sandbox, and node-vfs backends.

### Patch Changes

- [#691](#691)
[`39a7049`](39a7049)
Thanks [@colifran](https://github.com/colifran)! - fix(deepagents):
backend adapter drops route prefixes

- [#672](#672)
[`cc26c41`](cc26c41)
Thanks [@hntrl](https://github.com/hntrl)! - fix(deepagents): allow
custom middleware to replace defaults by name
## deepagents-acp@0.1.19

### Patch Changes

- Updated dependencies
[[`39a7049`](39a7049),
[`6ae9d1e`](6ae9d1e),
[`cc26c41`](cc26c41),
[`4643148`](4643148),
[`eb18c70`](eb18c70)]:
  - deepagents@1.11.0
## @langchain/node-vfs@0.2.1

### Patch Changes

- [#673](#673)
[`eb18c70`](eb18c70)
Thanks [@hntrl](https://github.com/hntrl)! - feat(backends): add delete
protocol support

Adds a `DeleteResult` type and optional backend `delete` method,
preserves delete through backend protocol adaptation, and implements
file deletion across the built-in state, store, filesystem, composite,
context hub, sandbox, and node-vfs backends.
## @deepagents/evals@0.0.18

### Patch Changes

- Updated dependencies
[[`39a7049`](39a7049),
[`6ae9d1e`](6ae9d1e),
[`cc26c41`](cc26c41),
[`4643148`](4643148),
[`eb18c70`](eb18c70)]:
  - deepagents@1.11.0

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Hunter Lovell (hntrl) added a commit that referenced this pull request Jul 24, 2026
Adds a `tools` allowlist option to `createFilesystemMiddleware` so
callers can restrict which built-in filesystem tools are exposed to the
model. The middleware now builds the filesystem system prompt from the
tools that are actually visible on the request, avoiding instructions
for tools that were filtered by the allowlist or backend capability
checks.

- Adds a public `FsToolName` type and `tools` option to
`FilesystemMiddlewareOptions`.
- Filters filesystem middleware tools at construction time when an
explicit allowlist is provided, while preserving existing `execute`
backend capability filtering.
- Requires `read_file` in explicit allowlists because it is needed for
filesystem workflows and large-result recovery.
- Generates the filesystem tool prompt dynamically from visible
filesystem tools, and only appends execute-specific instructions when
`execute` is actually available.
- Adds unit and integration coverage for allowlist behavior, prompt
filtering, unsupported `execute`, and user-provided non-filesystem
tools.
Hunter Lovell (hntrl) pushed a commit that referenced this pull request Jul 24, 2026
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to main, this PR will
be updated.


# Releases
## deepagents@1.11.0

### Minor Changes

- [#671](#671)
[`6ae9d1e`](6ae9d1e)
Thanks [@hntrl](https://github.com/hntrl)! - feat(filesystem): add
allowlist for filesystem middleware tools

- [#669](#669)
[`4643148`](4643148)
Thanks [@hntrl](https://github.com/hntrl)! - feat(deepagents): add
structured system prompt configuration

- [#673](#673)
[`eb18c70`](eb18c70)
Thanks [@hntrl](https://github.com/hntrl)! - feat(backends): add delete
protocol support

Adds a `DeleteResult` type and optional backend `delete` method,
preserves delete through backend protocol adaptation, and implements
file deletion across the built-in state, store, filesystem, composite,
context hub, sandbox, and node-vfs backends.

### Patch Changes

- [#691](#691)
[`39a7049`](39a7049)
Thanks [@colifran](https://github.com/colifran)! - fix(deepagents):
backend adapter drops route prefixes

- [#672](#672)
[`cc26c41`](cc26c41)
Thanks [@hntrl](https://github.com/hntrl)! - fix(deepagents): allow
custom middleware to replace defaults by name
## deepagents-acp@0.1.19

### Patch Changes

- Updated dependencies
[[`39a7049`](39a7049),
[`6ae9d1e`](6ae9d1e),
[`cc26c41`](cc26c41),
[`4643148`](4643148),
[`eb18c70`](eb18c70)]:
  - deepagents@1.11.0
## @langchain/node-vfs@0.2.1

### Patch Changes

- [#673](#673)
[`eb18c70`](eb18c70)
Thanks [@hntrl](https://github.com/hntrl)! - feat(backends): add delete
protocol support

Adds a `DeleteResult` type and optional backend `delete` method,
preserves delete through backend protocol adaptation, and implements
file deletion across the built-in state, store, filesystem, composite,
context hub, sandbox, and node-vfs backends.
## @deepagents/evals@0.0.18

### Patch Changes

- Updated dependencies
[[`39a7049`](39a7049),
[`6ae9d1e`](6ae9d1e),
[`cc26c41`](cc26c41),
[`4643148`](4643148),
[`eb18c70`](eb18c70)]:
  - deepagents@1.11.0

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Hunter Lovell (hntrl) added a commit that referenced this pull request Jul 24, 2026
Adds a `tools` allowlist option to `createFilesystemMiddleware` so
callers can restrict which built-in filesystem tools are exposed to the
model. The middleware now builds the filesystem system prompt from the
tools that are actually visible on the request, avoiding instructions
for tools that were filtered by the allowlist or backend capability
checks.

- Adds a public `FsToolName` type and `tools` option to
`FilesystemMiddlewareOptions`.
- Filters filesystem middleware tools at construction time when an
explicit allowlist is provided, while preserving existing `execute`
backend capability filtering.
- Requires `read_file` in explicit allowlists because it is needed for
filesystem workflows and large-result recovery.
- Generates the filesystem tool prompt dynamically from visible
filesystem tools, and only appends execute-specific instructions when
`execute` is actually available.
- Adds unit and integration coverage for allowlist behavior, prompt
filtering, unsupported `execute`, and user-provided non-filesystem
tools.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant