Local-first Agentic AI Runtime with Python reasoning loop, Rust orchestrator, daemon tools, and messenger connectors. Supports multiple messaging platforms (Discord, Telegram, WhatsApp) with approval cliff TUI for Red (destructive) actions.
LuminaGuard exposes 6 tools with basic STDIO transport. Tool definitions exist in agent/daemon/tools.py and agent/approval_client.py, but schemas and descriptions are minimal. All tools have descriptions (10-89 chars), but many lack parameter-level guidance. Input schemas are present but incomplete: parameters lack detailed type constraints, ranges, and validation rules. No output schemas are documented. Error handling is basic, no recovery guidance or actionable error messages visible. Security concerns: bash and delete_file are destructive but lack permission gates or dry-run support. No evidence of tool annotations (readOnlyHint, destructiveHint, idempotentHint). Composition is reasonable (each tool does one thing), but some tools (bash, web) are overly generic and lack constraints that would guide LLM selection and prevent misuse.
Execute shell commands with timeout and resource limits
Delete a file
Pattern matching across files with regex support, recursive search, case insensitivity, line numbers, and context lines
Read content from a file
HTTP client for fetching URLs and making API requests
Write content to a file
Marked DESTRUCTIVE but lacks confirmation mechanism, dry-run option, and permission gate. Violates pattern:confirmation-request and pattern:permission-gate.
bash tool is high-risk (DESTRUCTIVE) but has no command whitelist, no sandbox documentation, and no execution policy stated. LLM can run arbitrary shell commands with minimal constraint. Violates pattern:scope-declaration and pattern:permission-gate.
web tool name is vague ('web' instead of 'send_http_request' or 'fetch_url'). No URL validation (http vs https), no domain whitelist, no response size limit, no timeout range documented. Generic name invites LLM confusion with other tools. Violates pattern:tool.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 49 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 36 | - | v1 |
No output schemas documented for any tool. LLMs cannot predict response structure (fields, types, pagination). Violates pattern:tool and pattern:paginated-result. Example: grep has no schema showing whether results are paginated, what fields are in each match, or what 'total' count is.
write_file and delete_file lack confirmation or dry-run support. Agents can accidentally overwrite or delete files. No permission checks visible. Violates pattern:confirmation-request.
No tool annotations (readOnlyHint, destructiveHint, idempotentHint) visible in schema. Risk tags (DESTRUCTIVE, READ_ONLY, WRITE) are noted in the feature list but not exposed in tool definitions where LLMs can access them. Violates MCP 2026-07-28 spec alignment for tool annotations.
Parameters lack range constraints and format validation. Example: bash timeout is integer with no min/max (timeout=-1 or timeout=999999 could break); grep context is integer with no bounds; web method is string with no enum (POST vs POST vs post?). Violates pattern:constrained-input.
Error handling not documented. No guidance on retryable vs fatal errors, no actionable error messages shown, no recovery suggestions visible. Violates pattern:recovery-guide and pattern:error-classification.
grep tool offers context and recursive options but no pagination. If grep matches 10,000 lines, tool returns all of them, risking context window exhaustion. Violates pattern:paginated-result.