In the previous chapter, Agent Definition & Discovery, we learned how to create a "Character Sheet" for an agent using Markdown. We learned that an agent is essentially a configuration of name, tools, and personality.
Now, we will look at the Specialized Built-in Agents. These are the "default characters" that ship with AgentTool. They aren't just examples; they are critical infrastructure designed to keep your code safe and high-quality.
Imagine a construction site where one person tries to be the Architect, the Builder, and the Safety Inspector all at the same time.
In AI development, a single "General Purpose" agent often rushes to write code without planning, or validates its own bugs as "correct."
To solve this, AgentTool uses a Role-Based Approach. We don't just ask an AI to "build a feature." We split the work:
AgentTool hardcodes these three specific personas directly into the system.
This is the default agent. It is balanced. It can read files, write files, search, and run commands.
This agent is Read-Only.
This agent is adversarial. It acts like a "QA Tester."
VERDICT: PASS or VERDICT: FAIL.While these agents are defined in code, conceptually, here is how they behave when activated.
When you ask the Plan Agent to "Design a login page," it cannot write the code file.
Input: "Plan the login feature." Agent Action:
Output: A text-based Markdown list of steps (The Blueprint).
After the builder finishes, the Verification Agent steps in.
Input: "Verify the login feature." Agent Action:
Output:
Check: Empty password
Result: Handled correctly (Error 400).
VERDICT: PASS
How does the system enforce these roles? It's not magic; it is a combination of Prompt Engineering and Tool Restrictions.
Let's see what happens when the Plan Agent tries to do something it shouldn't.
Let's look at the actual TypeScript definitions (simplified for clarity) to see how these restrictions are applied.
This agent acts as the baseline. It has access to all tools (['*']).
From built-in/generalPurposeAgent.ts:
export const GENERAL_PURPOSE_AGENT = {
agentType: 'general-purpose',
// Access to everything
tools: ['*'],
// The prompt encourages doing the work
getSystemPrompt: () => "You are an agent... Complete the task fully."
}
Notice the disallowedTools array. This is the safety mechanism. Even if the AI wants to write a file, the system refuses.
From built-in/planAgent.ts:
export const PLAN_AGENT = {
agentType: 'Plan',
// Explicitly block modification tools
disallowedTools: ['edit_file', 'write_file', 'rm'],
// The prompt reinforces the persona
getSystemPrompt: () => `
You are a software architect.
=== CRITICAL: READ-ONLY MODE ===
You are STRICTLY PROHIBITED from creating new files.
`
}
Explanation: The disallowedTools list tells the runtime (which we will cover in Chapter 3) to throw an error if these tools are requested.
This agent focuses on the output format. It must return a verdict.
From built-in/verificationAgent.ts:
const VERIFICATION_PROMPT = `
You are a verification specialist.
Your job is to try to break the implementation.
Output VERDICT: PASS or VERDICT: FAIL
`
export const VERIFICATION_AGENT = {
agentType: 'verification',
// Also blocked from editing project files (can only run tests)
disallowedTools: ['edit_file', 'write_file'],
getSystemPrompt: () => VERIFICATION_PROMPT
}
Explanation: The prompt is "adversarial." It explicitly tells the AI not to trust the code and to avoid "verification avoidance" (lazy testing).
In this chapter, we explored Specialized Built-in Agents.
disallowedTools arrays and specific system prompts.Now that we have our agents defined (Chapter 1) and understand the specialized built-in roles (Chapter 2), we need to understand how the system actually runs them.
Next Chapter: Agent Execution Runtime
Generated by Code IQ