CtrlK
BlogDocsLog inGet started
Tessl Logo

claude-api-client-tools

This skill should be used when the user asks to implement, audit, or harden application-side handlers for Anthropic-defined Claude API client tools: memory, bash, text editor, or computer use; including sandboxing, path containment, command/action allowlists, session state, idempotency, tool_result construction, and execution evidence. Do not use it for Claude Code permissions, Anthropic server tools, MCP, Claude Code headless CLI, Agent SDK automation, or the generic Messages API tool loop.

SKILL.md
Quality
Evals
Security

Claude API Client Tools

Own the application-side implementation contract for Anthropic-defined memory, bash, text editor, and computer-use tools. Anthropic supplies each tool's model-facing schema; the application authorizes and executes requests, owns state, and returns correlated results. [DOC]

Boundary

  • Use this skill for the handler, sandbox, path/command/action policy, session lifecycle, idempotency, result, and evidence layer of the four client tools. [CONFIG]
  • Route generic tool_use/tool_result loop ordering, stop handling, budgets, and multi-tool correlation to claude-api-tool-runtime. [CONFIG]
  • Route custom tool descriptions and user-defined JSON schemas to tool-use-design. [CONFIG]
  • Route Claude Code CLI or Agent SDK automation to headless-sdk-automation, and MCP servers to mcp-engineering. [CONFIG]
  • Route Files API/PDF inputs to claude-api-files-documents, context/cache/compaction to claude-api-context-management, and Anthropic-executed tools to claude-api-server-tools. [CONFIG]
  • Treat Claude Code permissions, Anthropic-executed server tools, MCP, and a shell opened directly by a user or harness as separate security and execution surfaces. [CONFIG]

Contract

  • Acceptance: produce or audit a plan that preserves exact tool identity, omits user-supplied input_schema, executes only in the application, enforces tool-specific policy, owns state explicitly, classifies retry safety, returns one matching tool_result, and emits redacted evidence. [DOC][INFERENCIA]
  • Limits: this skill does not claim that an Anthropic-defined schema authorizes an operation; schema validity and application authorization are independent gates. [INFERENCIA]
  • Evidence: ground tool types, names, parameters, commands, actions, and beta requirements only in the four normalized files pinned by references/official-source-map.md; mark unverified model/version details as coverage_gap. [CONFIG]
  • Fail-closed: reject unknown tool versions, roots, commands, actions, session transitions, retries, or result mappings until policy resolves them. [INFERENCIA]

Required Inputs

  • Selected tool IDs and target model/API version. [SUPUESTO]
  • Application handler names and execution environment. [SUPUESTO]
  • Allowed roots, commands, domains, actions, and human-confirmation classes. [INFERENCIA]
  • Session ownership, restart semantics, timeouts, resource/output limits, and retry policy. [INFERENCIA]
  • Evidence retention/redaction requirements and tool_result error shape. [INFERENCIA]

Procedure

  1. Load references/official-source-map.md and verify the selected tool type/name against the local official corpus. [CÓDIGO]
  2. Load references/client-tools-contract.md; separate model-facing integrated schema from application execution policy. [CONFIG]
  3. Define the common application boundary: state, result correlation, idempotency, redaction, and evidence. [INFERENCIA]
  4. Apply the selected tool policy: memory root containment, editor roots and unique edits, bash isolation and command allowlist, or computer isolation/action/confirmation policy. [DOC][INFERENCIA]
  5. Review references/edge-cases.md plus references/guardian-gap-contracts.md for command, lifecycle, version, output, consent, coordinate, and retention failures. [CONFIG]
  6. Materialize templates/client-tool-plan.json and run scripts/validate_client_tool_plan.py. [CÓDIGO]
  7. Apply assets/client-tool-checklist.md, then run scripts/check.sh. [CÓDIGO]

Hard Rules

  • Use memory_20250818/memory, bash_20250124/bash, text_editor_20250728/str_replace_based_edit_tool, or computer_20251124/computer only when verified for the target model and headers. [DOC]
  • Do not attach a custom input_schema to these Anthropic-defined tools; their schemas are integrated and not application-editable. [DOC]
  • The application executes every file, shell, and computer action. Claude requests an operation but does not gain ambient access. [DOC]
  • The Platform bash client tool is an application-owned API handler, not general shell access and not a Claude Code permission named Bash. [CONFIG]
  • Canonicalize every memory/editor path and enforce containment after resolution; lexical prefix checks alone are insufficient. [DOC][INFERENCIA]
  • Run bash in an isolated least-privilege environment with explicit executable policy, timeout, process-group cleanup, resource limits, output limits, and secret redaction. [DOC]
  • Run computer use in an isolated environment with network/action policy and human confirmation for consequential or consent-bearing actions. [DOC]
  • Keep application-environment storage distinct from Anthropic's real-time processing of screenshot/action requests; apply the verified API retention contract and preserve a coverage_gap for unverified ZDR or deletion guarantees. [DOC]
  • Keep state in the application. The Messages API does not carry a shell, display, filesystem, or memory store between requests. [DOC][INFERENCIA]
  • Never retry a mixed or non-idempotent operation without an explicit no-retry decision or replay-safe key strategy. [INFERENCIA]
  • Return one tool_result correlated by tool_use_id; set is_error: true for rejected or failed execution and preserve sanitized evidence. [DOC]

Outputs Expected

  • A validated client-tool plan using assets/client-tool-plan.schema.json. [CÓDIGO]
  • Tool-specific policy decisions and state/restart semantics. [INFERENCIA]
  • Idempotency/retry classification and correlated result/error protocol. [INFERENCIA]
  • Evidence fields, redaction policy, residual risks, and coverage_gap entries. [CONFIG]

Resources

  • references/official-source-map.md
  • references/client-tools-contract.md
  • references/validator-contract.md
  • references/edge-cases.md
  • references/guardian-gap-contracts.md
  • assets/client-tool-plan.schema.json
  • assets/client-tool-checklist.md
  • templates/client-tool-plan.json
  • agents/producer.md and agents/verifier.md
  • examples/example-invalid-input.md and examples/example-invalid-output.md
  • scripts/validate_client_tool_plan.py
  • scripts/check.sh

Packet

Capas del packet, cargables bajo demanda (disciplina ICM: una capa por vez, nunca todas juntas): references/ guías de profundidad (cargar UNA por etapa) · knowledge/ cuerpo de conocimiento · prompts/ prompts listos · examples/ salida de ejemplo · agents/ subagentes del packet · templates/ plantilla de output · scripts/ automatización local · assets/ recursos estáticos.

Repository
JaviMontano/claude-plugins
Last updated
First committed

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.