kaxil opened a new pull request, #74379: URL: https://github.com/apache/airflow/pull/74379
The toolset guides list their limiting parameters one by one. None showed them set together, or what the model sees when a limit refuses a call, so a reader could not tell how locked down an agent actually is. The SQL, hook, object storage, DataFusion and Agent Skills guides now each have a "Restricting the agent" section with three parts: - one example Dag that sets every limit the toolset offers, with a comment on each line; - the exact message the model gets back for each refused call; - the credential scoping that still holds if a toolset-level check has a gap. | Guide | What the section shows | |---|---| | SQL | `allowed_tables`, `allowed_functions` and read-only mode refusing queries; the error each budget raises when exhausted (`max_retries`, `tool_calls_limit`); and the database role refusing the same query when `allowed_tables` is unset | | Hook | `allowed_methods` and `pinned_arguments` refusing calls; a hook exception failing the task | | Object storage | refusals for `..`, schemes, absolute paths, images and oversized files, none of which use `max_retries` | | DataFusion | an unregistered table, a URL inside the SQL and a `CREATE` statement all refused | | Agent Skills | `exclude_tools` and `exclude_resources` hiding tools and files | **Gotchas** Two behaviours surfaced while capturing these, and both pages now describe them as they are: - **The pinned-argument message.** The hook guide said a model-supplied pinned argument is refused with a message that the argument is fixed. For a method with named parameters, such as `S3Hook.read_key`, argument validation rejects it first with a generic `Extra inputs are not permitted`. The toolset's own "is fixed" message only fires when the method also takes `**kwargs`. - **One correction for skills tools.** `AgentSkillsToolset` has no `max_retries`, and `pydantic-ai-skills` sets 1 on its tools, so a second wrong resource name in a row fails the run. Raising the agent's `retries` does not change that. Exposing the setting is a separate code change. Every quoted message was captured from a run against Postgres for the SQL example and an S3-compatible endpoint for the others. Each example Dag also ran end to end through `AgentOperator` with `dag.test()`, once with a scripted model and once with a real one, and every run finished in success. `breeze build-docs common.ai`, including the spell check, passes. A companion PR adds an overview table to the toolsets index and an MCP `.filtered()` example. The two touch different parts of the same pages and merge cleanly in either order. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
