---
title: "Core tools"
description: "The tools an agent can call, and their boundaries."
---

The agent observes and changes the world through a small set of tools. Each one is authorized independently.

## Five base tools

| Tool | Purpose | Risk |
| --- | --- | --- |
| `search` | Find files by name or content | Low |
| `read` | Read file contents | Low |
| `write` | Create or overwrite a file | Medium |
| `exec` | Run a command | High |
| `list` | List a directory tree | Low |

## Symbol index

The `symbols` tool reads a code symbol index to locate functions, types and variables quickly. It is based on language parsing rather than text matching, so it beats grep.

## Subagents

`spawn_agent` lets the main agent hand a subtask to a fresh agent instance to work in parallel, then collect the result. See [Subagents](/en/docs/using-bi/subagents).

## Boundaries

Whatever tool it calls, paths never cross the workspace root. Command execution is likewise bound by [permission rules](/en/docs/configuration/permissions) — more tools does not mean more power.
