Repository navigation
Add restricted-agent examples to common.ai toolset guides - #74379
Merged
Merged
Conversation
The SQL, hook, object storage, DataFusion and Agent Skills guides each gain a "Restricting the agent" section: one example Dag that sets every limit the toolset offers, followed by what the model gets back when a call is refused, captured from a real run against Postgres and an S3 endpoint. Each section ends with the credential scoping that holds when a toolset-level check does not. The hook guide also corrects how a model-supplied pinned argument is refused: for a method with named parameters it fails argument validation, and the toolset's own "is fixed" message applies only when the method also takes **kwargs.
This was referenced Oct 6, 2026
vatsrahul1001
approved these changes
Oct 7, 2026
vatsrahul1001
left a comment
Contributor
There was a problem hiding this comment.
LGTM, Static checks failure not related to this PR. I have a fix for it #74390
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The toolset guides list their limiting parameters one by one. None showed them set together, or what the model sees when a limit refuses a call, so a reader could not tell how locked down an agent actually is. The SQL, hook, object storage, DataFusion and Agent Skills guides now each have a "Restricting the agent" section with three parts:
allowed_tables,allowed_functionsand read-only mode refusing queries; the error each budget raises when exhausted (max_retries,tool_calls_limit); and the database role refusing the same query whenallowed_tablesis unsetallowed_methodsandpinned_argumentsrefusing calls; a hook exception failing the task.., schemes, absolute paths, images and oversized files, none of which usemax_retriesCREATEstatement all refusedexclude_toolsandexclude_resourceshiding tools and filesGotchas
Two behaviours surfaced while capturing these, and both pages now describe them as they are:
S3Hook.read_key, argument validation rejects it first with a genericExtra inputs are not permitted. The toolset's own "is fixed" message only fires when the method also takes**kwargs.AgentSkillsToolsethas nomax_retries, andpydantic-ai-skillssets 1 on its tools, so a second wrong resource name in a row fails the run. Raising the agent'sretriesdoes not change that. Exposing the setting is a separate code change.Every quoted message was captured from a run against Postgres for the SQL example and an S3-compatible endpoint for the others. Each example Dag also ran end to end through
AgentOperatorwithdag.test(), once with a scripted model and once with a real one, and every run finished in success.breeze build-docs common.ai, including the spell check, passes.A companion PR adds an overview table to the toolsets index and an MCP
.filtered()example. The two touch different parts of the same pages and merge cleanly in either order.