Skip to content

[AI Assistant] Classify tools by confirmation policy #4457

Description

@astandrik

Goal

Reduce unnecessary approval prompts while keeping explicit confirmation for tools that may change state.

Behavior

  • Explicitly classified safe tools, such as documentation search and current-time lookup, run without confirmation.
  • Potentially state-changing tools, including restarts and query execution, always require confirmation for each invocation.
  • Unknown or unclassified tools require confirmation by default.
  • Auto-approval rules and user preferences must not bypass mandatory confirmation for state-changing tools.

Acceptance criteria

  • The exposed tool catalog has an explicit confirmation policy.
  • Safe, state-changing, and unknown tools follow the same policy in all supported AI Assistant modes.
  • Tests cover automatic execution, mandatory confirmation, rejection, and attempts to bypass mandatory confirmation.

Reference

YDB-3538 — AI Assistant architecture

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions