An Electron-based terminal application with AI integration, file management, and extensible plugin system supporting various connection profiles and protocols
YAET provides 15 tools with explicit definitions in src-electron/adapter/ai/toolDefinitions.js. All tools have descriptions (ranging 35-234 characters, within the 10-1024 baseline) and structured input schemas with typed parameters. However, critical gaps exist: output schemas are entirely undocumented (no return type specifications visible), security concerns around credential exposure and command injection are not addressed in descriptions, and error handling is not documented. Naming is generally good (verb_noun conventions like 'scp_list_files', 'local_execute') but descriptions lack dependency hints and recovery guidance. Parameter descriptions are present but often minimal, many lack constraints (e.g., maxBytes range is only mentioned in scp_read_file description, not in schema constraints). No tool annotations (readOnlyHint, destructiveHint, idempotentHint) are declared despite tools having clear risk profiles (IRREVERSIBLE, DESTRUCTIVE). The tool set covers a legitimate domain (SSH/SFTP/FTP file operations + local command execution) but composition is weak, related operations are split across scp_* and ftp_* namespaces without clear guidance on when to use each.
List files in a remote directory via FTP using a saved profile
Read a remote text file via FTP using a saved profile. Binary files are rejected (use *_download_file). Large files are truncated (see truncated/totalBytes).
Write content to a remote file via FTP using a saved profile
Execute a command on the local machine directly (no profile needed)
Search available connection profiles. Returns only id, name and type — use the id with other tools via profileId. Hosts and all credentials stay in the main process and are never exposed.
Copy files or folders on a remote server via SFTP using a saved profile
Output schemas completely undocumented, agents cannot determine response structure, cannot plan downstream tool calls, cannot reliably extract IDs for chaining.
Error handling not documented, descriptions do not explain what errors can occur, which are retryable, or what recovery steps to take. local_execute, scp_write_file, scp_delete_files, and destructive tools lack recovery guidance.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | C | 62 | <=2025-11-25 | v2 |
Create a new folder on a remote server via SFTP using a saved profile
Delete files or folders on a remote server via SFTP using a saved profile
Download a remote file to local disk via SFTP. If localPath is provided, writes directly to that path and returns the local path. Otherwise returns base64 content.
List files in a remote directory via SFTP using a saved profile
Move files or folders on a remote server via SFTP using a saved profile
Read a remote text file via SFTP using a saved profile. Binary files are rejected (use *_download_file). Large files are truncated (see truncated/totalBytes).
Rename a file or folder on a remote server via SFTP using a saved profile
Search for files on a remote server via SFTP using a saved profile
Write content to a remote file via SFTP using a saved profile
WRITE and DESTRUCTIVE tools lack confirmation/dry-run patterns, scp_write_file, scp_delete_files, and destructive operations expose agents to accidental data loss. No method documented to preview changes before commit.
Tool annotations missing, no readOnlyHint, destructiveHint, or idempotentHint declared in tool definitions despite clear risk profiles (READ_ONLY, WRITE, DESTRUCTIVE, IRREVERSIBLE). Clients cannot introspect tool safety.
local_execute command parameter lacks injection safeguards documentation, no mention of shell escaping, length limits, or character restrictions. Critical security gap for a tool with IRREVERSIBLE risk.
Overwrite behavior undocumented across scp_write_file, scp_copy_files, scp_move_files, ftp_write_file, agents do not know if target already existing fails the call or silently overwrites. No guidance on idempotency.
SCP vs FTP tool duplication without decision guidance, scp_list_files/ftp_list_files, scp_read_file/ftp_read_file, scp_write_file/ftp_write_file are parallel but no description explains when to use each. Agents waste reasoning cycles choosing between them.
Result limits not documented, scp_list_files, ftp_list_files, scp_search_files descriptions do not state maximum result count or truncation behavior. Large directory listings could blow context window.
Parameter constraints incomplete, scp_read_file maxBytes clamped range is stated in description but not in JSON Schema (no 'minimum' / 'maximum'). Local_execute command parameter has no length or character restrictions. Agents cannot infer valid ranges.