An agent handed every tool at once spends its context reading descriptions it will never use, and a large catalogue makes the right tool harder to pick. This release lets an agent start small and ask for what it needs, and it brings the rest of the MCP surface, prompts and resources, to the platform's own agents with the same controls that apply to an external client.
Tools disclosed on request
- Deferred tools. A tool can be registered as available on request: the agent sees its name, grouped by family, and loads it through
tool_searchby exact name or keyword when the task calls for it. - No cost to searching. A search does not consume the agent's iteration budget, and the tools it loads stay available for the rest of the conversation.
- Stable for caching. The tool list is sent in the same order on every call, so a provider's prompt cache keeps working as the conversation grows.
The whole MCP surface, inside the platform
- Procedures as tools. Each MCP prompt a session lists is offered to the agent as a tool named after its slash command, so the agent follows a written procedure instead of improvising over the tool list.
- Only when it can finish. A procedure is offered only when the caller may use every tool it sequences; a procedure that would stop halfway is never handed to the model.
- Resources through the same gates. MCP resources reach an agent as two tools, listing and reading, routed through the registry so the same world, role and provider checks apply.
- Visible to the user. The chat assistant gains a Tools view listing exactly what it can call, served from the same source the agent uses.
Nothing widens what an agent may do: every tool, procedure and resource is still admitted by the caller's own grants, and a deferred tool is subject to the same checks as one loaded up front.