Built-in Capabilities

Before building custom tools, know the powers models bring in the box: code execution, live web access, computer use, file systems — each a superpower with a sharp edge.

▶ Watch this reel

What you'll learn

  1. Code execution
  2. Web search & fetch
  3. Computer & browser use
  4. File system access

Remember this

Code execution sandbox

Web search & fetch

Computer / browser use

File system tools

Code: Capability stack: what to enable, in order of caution

# Enable in this order — each step adds power AND guardrail work:

# 1 · SANDBOXED CODE EXECUTION   (start here)
#    e2b / daytona / local container
#    no-net, read-only mounts, 30s timeout, 512MB RAM

# 2 · FILE TOOLS on a workspace  (add when artifacts matter)
#    path-scope (slide 4), ext allow-list, size caps

# 3 · WEB SEARCH + FETCH         (add for freshness)
#    search API w/ quota · fetch w/ truncation + ToS care

# 4 · BROWSER/COMPUTER USE       (last resort, most guarded)
#    dedicated account · human-confirm irreversibles · step budgets

# Anti-pattern: enabling 2-4 BEFORE 1's sandbox exists.
# Generated code + unrestricted files = exfiltration path.