wireSchemas() already advertised only run_code under mode: 'code', but the executor resolved every call through get(), which returns the full visible map plus the reserved transport. A model could name a native tool directly and bypass run_code entirely. Route the execution-path lookups through a new private resolveExecution() that applies the mode collapse at the operation boundary: model-direct calls under 'code' may only name run_code (UNKNOWN_TOOL otherwise), while SDK sub-dispatches (parent token set) keep every visible tool. get()/schemas() public semantics are unchanged. The denial happens at createExecution, before the extensible policy pipeline — pre-execute listeners, approval ask, and guards never observe a call that is deterministically denied. A collapsed call honors the pre-dispatch cancellation contract, routes aborted results through the visible tool's finalizeContent, and captures the finalizer before argument materialization. Under code mode, a system-prompt/assemble listener filters out tool:* guidance sections that told the model to call native tools directly. The tools:sdk section and SDK types remain so programs can still use all tools through run_code. Fixes #1815
core/ — product API spine
English | 中文
The session log, system-prompt assembly, tool registry, agent vocabulary, deployment-default model selection, and concrete loop that form the harness's default control spine. These are product packages — the stable surface plugins and consumers build against.
| Package | Role | ctx key |
|---|---|---|
scope/ |
Scoped-context registration primitive | library — no ctx key |
session/ |
Event-sourced session log and in-memory store | ctx.sessions |
system-prompt/ |
Prompt and tool-schema assembly registry | ctx.systemPrompt |
tools/ |
Scoped tool registry and execution pipeline | ctx.tools |
agent/ |
Agent interface, registry, and event vocabulary | ctx.agents |
agent-default-model/ |
Default model selection shared by Agent entry points | ctx.agentDefaultModel |
agent-loop/ |
Default concrete agent driver | ctx.agentLoop |
scope supplies the shared scoping primitive. agent owns the public contract, while agent-loop is its default implementation; extension plugins depend on the seam so the driver remains swappable. agent-default-model owns the deployment selection an Agent entry point uses only when a session has no selection of its own.
Runnable compositions belong to examples/agent-spine-demo; this group owns only the swappable spine pieces.
The subsystem reference — the package-by-package loop map, the Agent handle and its delivery/interception contracts — is docs/subsystems/core.md; the default runnable composition is examples/agent-spine-demo.