kaxil opened a new pull request, #74379:
URL: https://github.com/apache/airflow/pull/74379

   The toolset guides list their limiting parameters one by one. None showed 
them set together, or what the model sees when a limit refuses a call, so a 
reader could not tell how locked down an agent actually is. The SQL, hook, 
object storage, DataFusion and Agent Skills guides now each have a "Restricting 
the agent" section with three parts:
   
   - one example Dag that sets every limit the toolset offers, with a comment 
on each line;
   - the exact message the model gets back for each refused call;
   - the credential scoping that still holds if a toolset-level check has a gap.
   
   | Guide | What the section shows |
   |---|---|
   | SQL | `allowed_tables`, `allowed_functions` and read-only mode refusing 
queries; the error each budget raises when exhausted (`max_retries`, 
`tool_calls_limit`); and the database role refusing the same query when 
`allowed_tables` is unset |
   | Hook | `allowed_methods` and `pinned_arguments` refusing calls; a hook 
exception failing the task |
   | Object storage | refusals for `..`, schemes, absolute paths, images and 
oversized files, none of which use `max_retries` |
   | DataFusion | an unregistered table, a URL inside the SQL and a `CREATE` 
statement all refused |
   | Agent Skills | `exclude_tools` and `exclude_resources` hiding tools and 
files |
   
   **Gotchas**
   
   Two behaviours surfaced while capturing these, and both pages now describe 
them as they are:
   
   - **The pinned-argument message.** The hook guide said a model-supplied 
pinned argument is refused with a message that the argument is fixed. For a 
method with named parameters, such as `S3Hook.read_key`, argument validation 
rejects it first with a generic `Extra inputs are not permitted`. The toolset's 
own "is fixed" message only fires when the method also takes `**kwargs`.
   - **One correction for skills tools.** `AgentSkillsToolset` has no 
`max_retries`, and `pydantic-ai-skills` sets 1 on its tools, so a second wrong 
resource name in a row fails the run. Raising the agent's `retries` does not 
change that. Exposing the setting is a separate code change.
   
   Every quoted message was captured from a run against Postgres for the SQL 
example and an S3-compatible endpoint for the others. Each example Dag also ran 
end to end through `AgentOperator` with `dag.test()`, once with a scripted 
model and once with a real one, and every run finished in success. `breeze 
build-docs common.ai`, including the spell check, passes.
   
   A companion PR adds an overview table to the toolsets index and an MCP 
`.filtered()` example. The two touch different parts of the same pages and 
merge cleanly in either order.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to