Skip to content

Add restricted-agent examples to common.ai toolset guides - #74379

Merged
kaxil merged 1 commit into
apache:mainfrom
astronomer:toolset-restriction-examples
Oct 7, 2026
Merged

kaxil merged 1 commit into
apache:mainfrom
astronomer:toolset-restriction-examples

Conversation

@kaxil

@kaxil kaxil commented Oct 6, 2026

Copy link
Copy Markdown
Member

The toolset guides list their limiting parameters one by one. None showed them set together, or what the model sees when a limit refuses a call, so a reader could not tell how locked down an agent actually is. The SQL, hook, object storage, DataFusion and Agent Skills guides now each have a "Restricting the agent" section with three parts:

  • one example Dag that sets every limit the toolset offers, with a comment on each line;
  • the exact message the model gets back for each refused call;
  • the credential scoping that still holds if a toolset-level check has a gap.
Guide What the section shows
SQL allowed_tables, allowed_functions and read-only mode refusing queries; the error each budget raises when exhausted (max_retries, tool_calls_limit); and the database role refusing the same query when allowed_tables is unset
Hook allowed_methods and pinned_arguments refusing calls; a hook exception failing the task
Object storage refusals for .., schemes, absolute paths, images and oversized files, none of which use max_retries
DataFusion an unregistered table, a URL inside the SQL and a CREATE statement all refused
Agent Skills exclude_tools and exclude_resources hiding tools and files

Gotchas

Two behaviours surfaced while capturing these, and both pages now describe them as they are:

  • The pinned-argument message. The hook guide said a model-supplied pinned argument is refused with a message that the argument is fixed. For a method with named parameters, such as S3Hook.read_key, argument validation rejects it first with a generic Extra inputs are not permitted. The toolset's own "is fixed" message only fires when the method also takes **kwargs.
  • One correction for skills tools. AgentSkillsToolset has no max_retries, and pydantic-ai-skills sets 1 on its tools, so a second wrong resource name in a row fails the run. Raising the agent's retries does not change that. Exposing the setting is a separate code change.

Every quoted message was captured from a run against Postgres for the SQL example and an S3-compatible endpoint for the others. Each example Dag also ran end to end through AgentOperator with dag.test(), once with a scripted model and once with a real one, and every run finished in success. breeze build-docs common.ai, including the spell check, passes.

A companion PR adds an overview table to the toolsets index and an MCP .filtered() example. The two touch different parts of the same pages and merge cleanly in either order.

The SQL, hook, object storage, DataFusion and Agent Skills guides each gain a
"Restricting the agent" section: one example Dag that sets every limit the
toolset offers, followed by what the model gets back when a call is refused,
captured from a real run against Postgres and an S3 endpoint. Each section
ends with the credential scoping that holds when a toolset-level check does
not.

The hook guide also corrects how a model-supplied pinned argument is refused:
for a method with named parameters it fails argument validation, and the
toolset's own "is fixed" message applies only when the method also takes
**kwargs.

@vatsrahul1001 vatsrahul1001 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, Static checks failure not related to this PR. I have a fix for it #74390

@kaxil
kaxil merged commit 72d612c into apache:main Oct 7, 2026
82 of 83 checks passed
@kaxil
kaxil deleted the toolset-restriction-examples branch October 7, 2026 05:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants