Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 9 additions & 0 deletions .changeset/core-tools-integrations-remove.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
---
"executor": patch
---

**Add `integrations.remove` to the core tools so an agent can drop a catalog integration**

`integrations.list` advertises `canRemove` per integration, but nothing on the agent surface could act on it: removal existed only on the HTTP API and the web console, so an agent that could add an integration could never take one back out. Cleaning up a catalog meant clicking through the UI once per integration.

The core-tools plugin now contributes `integrations.remove`, taking the `slug` reported by `integrations.list` and cascading to every connection under the integration and the tools those produced. It is approval-gated, being strictly more destructive than `connections.remove`. The `removed` flag is honest rather than always-true: `false` means no catalog row matched, so an already-absent slug and a built-in namespace like `executor` are distinguishable from a real removal, and an integration pinned with `canRemove: false` is refused with `IntegrationRemovalNotAllowedError` instead of silently surviving.
27 changes: 27 additions & 0 deletions packages/core/sdk/src/core-tools.ts
Original file line number Diff line number Diff line change
Expand Up @@ -51,6 +51,8 @@ const IntegrationsListOutput = Schema.Struct({
integrations: Schema.Array(IntegrationOutput),
});

const IntegrationRemoveInput = Schema.Struct({ slug: Schema.String });

const DetectInput = Schema.Struct({ url: Schema.String });
const DetectOutput = Schema.Struct({
results: Schema.Array(
Expand Down Expand Up @@ -331,6 +333,7 @@ const OAuthCancelInput = Schema.Struct({

// Standard-schema versions for the tool() builder.
const IntegrationsListOutputStd = schemaToStandard(IntegrationsListOutput);
const IntegrationRemoveInputStd = schemaToStandard(IntegrationRemoveInput);
const DetectInputStd = schemaToStandard(DetectInput);
const DetectOutputStd = schemaToStandard(DetectOutput);
const ConnectionsListInputStd = schemaToStandard(ConnectionsListInput);
Expand Down Expand Up @@ -559,6 +562,30 @@ export const coreToolsPlugin = definePlugin((options: CoreToolsPluginOptions = {
})),
})),
}),
tool({
name: "integrations.remove",
description:
"Remove an integration from the workspace catalog by slug, dropping every connection under it and every tool those produced. `removed: false` means no catalog row matched: the slug was already gone, or it names a built-in namespace that is not catalog-backed. Integrations whose `canRemove` is false are refused.",
inputSchema: IntegrationRemoveInputStd,
outputSchema: RemovedOutputStd,
// Strictly more destructive than `connections.remove`, which is
// already approval-gated: this cascades to every connection under the
// integration and takes the catalog row with it, so re-adding means
// re-importing the definition, not just reconnecting an account.
annotations: { requiresApproval: true },
execute: (input: typeof IntegrationRemoveInput.Type, { ctx }) =>
Effect.gen(function* () {
const slug = IntegrationSlug.make(input.slug);
// `core.integrations.get` reads catalog ROWS only, so a built-in
// static namespace reports absent here. Checking first is what
// keeps `removed` honest — the underlying remove is a silent
// no-op for a slug it can't find.
const existing = yield* ctx.core.integrations.get(slug);
if (existing === null) return { removed: false };
yield* ctx.core.integrations.remove(slug);
return { removed: true };
}),
}),
tool({
name: "connections.list",
description:
Expand Down
70 changes: 70 additions & 0 deletions packages/core/sdk/src/executor.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,7 @@ const memoryProvider = (): CredentialProvider => {
};

const INTEG = IntegrationSlug.make("demo");
const PINNED = IntegrationSlug.make("demo-pinned");
const TEMPLATE = AuthTemplateSlug.make("apiKey");
const CONN = ConnectionName.make("main");

Expand Down Expand Up @@ -94,6 +95,15 @@ const demoPlugin = definePlugin(() => ({
description: "Demo",
config: {},
}),
/** A catalog row the host pins in place (`canRemove: false`), the shape
* `integrations.remove` has to refuse rather than drop. */
seedPinned: () =>
ctx.core.integrations.register({
slug: PINNED,
description: "Demo (pinned)",
config: {},
canRemove: false,
}),
storagePut: (owner: "org" | "user", key: string, value: string) =>
ctx.storage.put(owner, key, value),
storageList: () => ctx.storage.list(),
Expand Down Expand Up @@ -347,6 +357,66 @@ describe("createExecutor", () => {
}),
);

it.effect("removes catalog integrations through the built-in Executor tools", () =>
Effect.gen(function* () {
const executor = yield* makeTestExecutor({
plugins: [demoPlugin] as const,
coreTools: {},
});
yield* executor.demo.seed();
yield* executor.demo.seedPinned();
yield* executor.execute(
ToolAddress.make("executor.coreTools.connections.create"),
{
owner: "org",
name: String(CONN),
integration: String(INTEG),
template: String(TEMPLATE),
from: { provider: "memory", id: "secret-token" },
},
{ onElicitation: "accept-all" },
);

const remove = ToolAddress.make("executor.coreTools.integrations.remove");

// Removing the integration cascades to the connections under it.
const removed = yield* executor.execute(
remove,
{ slug: String(INTEG) },
{ onElicitation: "accept-all" },
);
expect(removed).toEqual({ removed: true });
const listed = yield* executor.integrations.list();
expect(listed.map((integration) => String(integration.slug))).not.toContain(String(INTEG));
expect(yield* executor.connections.list()).toHaveLength(0);

// An already-absent slug and a built-in namespace both report honestly
// instead of claiming a removal that never happened.
expect(
yield* executor.execute(remove, { slug: String(INTEG) }, { onElicitation: "accept-all" }),
).toEqual({ removed: false });
expect(
yield* executor.execute(remove, { slug: "executor" }, { onElicitation: "accept-all" }),
).toEqual({ removed: false });

// A pinned integration is refused, and survives the attempt.
const refused = yield* Effect.result(
executor.execute(remove, { slug: String(PINNED) }, { onElicitation: "accept-all" }),
);
expect(Result.isFailure(refused)).toBe(true);
if (!Result.isFailure(refused)) return;
expect(Predicate.isTagged(refused.failure, "ToolInvocationError")).toBe(true);
expect(
Predicate.isTagged(
(refused.failure as { readonly cause?: unknown }).cause,
"IntegrationRemovalNotAllowedError",
),
).toBe(true);
const afterRefusal = yield* executor.integrations.list();
expect(afterRefusal.map((integration) => String(integration.slug))).toContain(String(PINNED));
}),
);

it.effect("surfaces failed tool sync diagnostics through connection tools", () =>
Effect.gen(function* () {
const executor = yield* makeTestExecutor({
Expand Down
Loading