Direct Tools

session.tool(name, args) (and the typed helpers like glob, grep, readFile) run a host tool directly, with no model call in the loop. Use them for tests, migrations, and host-driven workflows where you want deterministic results instead of an agent turn.

Direct calls are host control-plane calls: the session treats the host as having already approved them, so permissionPolicy and confirmation prompts do not apply. Apply your own product authorization before invoking them, or use governedTool / governed_tool / GovernedTool when a host-coordinated call must still pass the session's permission and confirmation gates.

Rust
Node.js
Python
Go

Direct tools execute under the session workspace and should be treated as privileged host operations. Most calls (read, glob, grep) are purely deterministic; generate_object is the exception — it still calls the model to fill a schema-validated JSON object, but you drive it explicitly rather than through a free-form agent turn.

grep / Grep runs the search tool in grep mode. It returns the matching lines followed by a N match(es) in M file(s) summary line, or No matches found for pattern: ... when nothing matches; the examples print that last line.

readFile / read_file / ReadFile returns the read tool's view: each line is prefixed with a right-aligned line number and a tab, and long files end with a continuation hint. Strip the prefix before parsing file content.

A runnable version ships at sdk/node/examples/basic/test_generate_object.ts (Python: sdk/python/examples/test_generate_object.py). The Go direct-tool contract is covered by sdk/go/session_test.go.