Tool calling
OpenAI 形式のネイティブなツール呼び出しです。tools(最大 128 個の function 定義)と tool_choice を送ると、モデルの tool_calls が finish_reason: tool_calls で返ります。ツールを実行するのは常にエージェント側(あなたのマシン)で、サーバは何も実行しません。結果は role: tool の turn で送り返します。
{"model": "qwen3.8-flash-next-whitehacker",
"tools": [{"type": "function", "function": {"name": "read_file", "parameters": {"type": "object", "properties": {"path": {"type": "string"}}}}}],
"tool_choice": "auto",
"messages": [{"role": "user", "content": "Review src/auth.ts"}]}
→ "choices": [{"finish_reason": "tool_calls", "message": {"role": "assistant", "content": null,
"tool_calls": [{"id": "call_1", "type": "function", "function": {"name": "read_file", "arguments": "{\"path\":\"src/auth.ts\"}"}}]}}]
# then: {"role": "tool", "tool_call_id": "call_1", "content": "<file contents>"}
ツール定義の文字数は入力上限(524,288 文字)に含まれます。ホスト側の firewall は タスク種別 を assurance rung でゲートします: code-review / vulnerability-triage / remediation は identity rung から、payload-crafting / c2-tooling は契約 rung まで拒否。