Custom Tools

Turn a Python function into a native agent tool that Praxis writes, tests in an isolated sandbox, and publishes for your agents to call.

A custom tool is a Python function that becomes a native agent tool, one your agents call exactly like a built-in. Reach for it when an agent needs a small piece of logic that does not warrant a whole external service: a calculation, a formatted lookup, or a call to an internal API. To bring in a whole external system instead, connect it as a remote MCP server (see Connect a Tool).


Build and publish a tool

You do not fill in a form to create a custom tool. You describe what you want in chat, and Praxis writes and ships it through four stages:

  1. Draft. Praxis writes the function and saves it as a draft. It checks the code before saving and refuses to store anything unsafe.
  2. Test. Praxis runs the draft in the sandbox against test input you provide, then tells you whether it passed and what it returned.
  3. Publish. Once you are satisfied with the test, Praxis publishes the tool, which makes it available to attach to agents.
  4. Attach. Praxis attaches the tool to the agents that should use it.

Editing a published tool's code returns it to draft, so you test and publish again before the change goes live. Each edit raises the tool's version.


How the sandbox keeps a tool safe

Every custom tool runs in an isolated sandbox, in its own process separate from Praxis, with a clean environment and no access to Praxis's own credentials or workspace. Two checks keep a tool contained:

  • Screened before it is saved. Praxis statically reads the code and rejects dangerous operations: running shell commands or subprocesses, dynamic code execution such as eval and exec, and wildcard imports. A tool may import only from an allowlist, the standard building blocks like JSON, dates, and HTTP, plus common libraries such as requests, boto3, and pandas that a tool opts into.
  • Bounded while it runs. Each run has a time limit and a memory limit, 30 seconds and 256 MB by default, and is stopped if it goes over.

If a tool needs a secret, it declares the credential it requires by name, and Praxis makes that value available to the function only while it runs. Custom tools draw on the same encrypted credentials as connected servers, referenced by name and never pasted into code. See Reference credentials securely.

Every tool call runs server-side under your organization's identity and is audited, the same model that governs everything else Praxis does. See How Praxis works.


Manage your custom tools

You build, test, publish, edit, and delete custom tools by asking Praxis in chat. Settings > Custom Tools is where you see them: each tool's status, its inputs, the credentials it needs, its time and memory limits, its last test result, and its recent usage. A tool appears here once Praxis creates it.

From this page you also put a published tool in an agent's hands: pick the agent and choose Attach, or detach a tool from the same list, without going back to chat. Attach only the tools an agent's job needs, so each agent carries a focused tool set. Attachments are set per agent, alongside the rest of an agent's setup in Build your own agent.

🚧

Deleting a custom tool is permanent and removes it from every agent that used it. Ask Praxis to delete a tool by name.