The eleven tools
file_ls · file_read · file_write · file_append · file_rm ·
file_rmdir · file_mkdir · file_cp · file_mv · file_stat ·
file_exists
The three scopes
A path outside those three prefixes is rejected. Writing to
/workspace/input/
is rejected with a message pointing at output or home. There is no /tmp,
and no access to a host filesystem.
/workspace/home/ is the agent’s own durable working directory — the same bytes
the agent sees from one conversation to the next. MCP and workflow callers never
get it; the tool descriptions they see do not mention it.
Shared with other tools
The same workspace is what Code Runner reads and writes when both capabilities are bound, and where Browser puts screenshots and PDFs. Write a CSV from Code Runner, read it back withfile_read.
Quotas
Session output is the only scope with a file-count quota. Agent home is the
only scope with a total-size cap, on top of its own per-file limit.
Cost
Metered per request, plus storage per GB-day. Session workspace storage is free; persistent storage is not. See noorle.com/pricing.Autonomy
ls, read, stat, and exists are Read tier. Everything else is Act
— so at Read-only autonomy an agent can inspect the workspace but not change it.
On MCP gateways
All Files tools are withheld from callers a gateway cannot identify. The workspace is derived from the gateway plus the authenticated user; an anonymous caller has none, so the tools do not appear intools/list and are not callable
by name. Authenticate the caller and they appear.
Next
- Code Runner
- Sandbox — a real filesystem when you need one