LLMs and retrieval · plan by default

/llm-tools

Design tool schemas, execution contracts, and failure handling

Use to design constrained agent tool interfaces; api-design defines general service contracts.

Make it your own.

In Claude Code, use the slash command and add your context. In Codex, select llm-tools from the just-vibe skill picker, then send the same brief.

Version 0.11.0 also supports /jv llm-tools, /just-vibe llm-tools and /jv:llm-tools in Claude. See shortcut setup and context examples.

Example · plan
/just-vibe:llm-tools Design narrow tool schemas with validated targets and idempotent execution.
edge · plan
/just-vibe:llm-tools Design a deployment tool that rejects unapproved production targets.
blocked · inspect
/just-vibe:llm-tools Review tool interfaces without exposing arbitrary shell or database execution.

What the agent does

  1. Define each tool’s typed input/output, target identity, permitted action and observable success. Separate planning or proposed arguments from executed effects; untrusted retrieved text cannot grant tool authority.
  2. Validate schema and business constraints before dispatch, resolve the actual target from authorized context and minimize returned sensitive data. Describe actionable errors without exposing credentials or treating arbitrary output as new instructions.
  3. For mutating calls, define request identity, idempotency, timeout ambiguity and result reconciliation. Cancellation or a missing response does not prove an external operation failed; check its identity before retrying.
  4. Test valid calls, invalid inputs, denied targets, unavailable tools, partial success and malicious tool output with controlled fakes. Verify state/effect counts as well as final answers and retain the distinction between simulated and live integration evidence.

Inputs

  • desired actions, schemas, execution APIs, permissions, and failure semantics.

Optional context: scope, references, constraints, successCriteria, environment, mode, budget.

Scope

Reads
Model-facing tool contracts and validated execution boundaries; implementation on request.
Writes
Inspect/plan: inspect or propose; save requested artifacts only. Apply: make the requested changes or execute the requested operation within its resolved target and limits. Local preparation does not authorize live, remote, destructive or paid actions; existing explicit session authorization still applies.
Mode
Plan tool contracts; apply for requested tool implementation and bounded local tests.
Prerequisites
Task definition, model/provider configuration, representative permitted data, versioned prompts/corpus where relevant, and explicit token/cost/latency limits for remote calls. Use current provider interfaces during implementation. Retrieved content and model-generated tool arguments remain untrusted.

Expected output

  • Tool schemas, executor design/code, error contract, and behavior fixtures.
  • Tool schema, enforcement boundary and invalid/unauthorized/partial-failure checks.

How the work is checked

  • Invalid or unauthorized arguments cannot execute; an uncertain external mutation is reconciled before retrying.

When to stop or clarify

  • A model-generated request is not user authorization. Do not expose arbitrary shell/database access as a convenience tool.

Handling missing context

Infer
Read current prompt/tool schemas, retrieval boundaries, installed SDK/provider config and permitted examples without reading secret values.
Assume
Use mocked calls for local contract tests when remote access is absent; do not infer model quality from mocks.
Ask
Ask for budget and permitted data/provider before a paid or external run if not already set; local prompt/tool implementation can proceed in apply mode.

Technical guidance

Evidence
Inspect tool schemas, target identifiers, execution authority, side effects and partial-failure semantics.
Method
Validate arguments and authorization in the executor, use stable operation IDs and reconcile timeouts before retries.
Pitfall
A schema-valid request can still target the wrong account; model text cannot grant permission to execute it.
Check
Test invalid targets, duplicate calls, timeout after success and malicious retrieved instructions with fake isolated executors.

Situational decisions

When a tool times out after an external mutation may have occurred: Return an operation ID and reconciliation path; do not let the model blindly repeat it.

When the request is for local preparation or implementation: Implement schema validation, authorization checks and duplicate/uncertain-call handling using synthetic effects before touching live tools.

The coding agent follows this workflow using its available tools. Installation does not grant service access or guarantee an outcome. Read the compatibility notes.

Keep exploring