发布

  • feat(subagents): extend deferred MCP tool loading to subagents (#3432)

    frostbyte_neo 发布于 2026-06-08 15:17:22 +00:00 | 1005 次提交 在此版本后已推送到 main

    • feat(subagents): extend deferred MCP tool loading to subagents (#3341)

    Subagents now reuse the lead agent's deferred-tool path: when
    tool_search.enabled, MCP tool schemas are withheld from the model and
    surfaced by name in , fetched on demand via the
    generated tool_search helper. DeferredToolFilterMiddleware deterministically
    rewrites request.tools to hide the deferred schemas (the prompt section is
    discovery only, not enforcement).

    Consolidates the assembly into deerflow.tools.builtins.tool_search, now the
    single home for both assemble_deferred_tools (centralized fail-closed guard,
    replacing the lead-only private _assemble_deferred) and the relocated
    get_deferred_tools_prompt_section. Shared by every build path: lead agent,
    embedded client, and subagent executor.

    tool_search is appended after the subagent's name-level tool policy and is
    treated as infrastructure: its catalog is built from the already
    policy-filtered list, so it can never surface a tool the policy denied.

    Follow-up to #3370. Fixes #3341.

    • test(subagents): assert the real middleware builder emits a working deferred filter (#3341)

    The existing recipe test hand-constructs DeferredToolFilterMiddleware, so it
    cannot catch a regression in how build_subagent_runtime_middlewares (the call
    executor._create_agent actually makes) wires the deferred setup into the
    filter. Add a test that sources the filter from the real builder given a real
    setup and runs it through a graph: a wrong catalog hash would silently stop
    promotion, a dropped filter would stop hiding — both now caught.

    Running the full real middleware stack is intentionally avoided (the other
    runtime middlewares need sandbox/thread infra to execute, which would make the
    test flaky); their attachment + ordering before Safety stays locked in
    test_tool_error_handling_middleware.py.

    • test(subagents): keep executor tests config-free in CI

    • chore: trigger ci

    • Potential fix for pull request finding

    Co-authored-by: Copilot Autofix powered by AI 175728472+Copilot@users.noreply.github.com


    Co-authored-by: Willem Jiang willem.jiang@gmail.com
    Co-authored-by: Copilot Autofix powered by AI 175728472+Copilot@users.noreply.github.com

    下载附件