Skip to content

[Feature]: Split call-actor into a read-only and a destructive tool #1447

Description

@jirispilka

Problem or motivation

call-actor is destructiveHint: true because it can run any Actor. Annotations are fixed per tool in tools/list, so the hint can't depend on which Actor is called. Claude always prompts for destructive tools (review criteria), so every call-actor call asks for approval. Most Actors only read: 85% of the 658 Actors labelled in the survey in #1446.

The same checklist rejects one tool that accepts both safe and unsafe HTTP methods, and asks for read and write to be separate tools. call-actor has the same shape. Context: the Slack thread, where jancurn proposed call-actor + call-actor-unsafe.

Proposed solution

  • call-actor: readOnlyHint: true. It runs only Actors classified read-only. Any other Actor fails with an error naming the second tool.
  • A second tool (name TBD, e.g. call-actor-unsafe): destructiveHint: true. It runs any Actor.
  • The tool descriptions, and possibly fetch-actor-details, tell the LLM which tool fits which Actor.

Classification:

Precedent: Zapier MCP ships execute_zapier_read_action and execute_zapier_write_action (docs).

Open questions

Alternatives considered

  • A parameter on call-actor that allows destructive Actors. Doesn't help: the hint is read from tools/list before the call, so the client still has to treat the tool as destructive.
  • Keep call-actor destructive. Every Actor run through call-actor keeps prompting.

Analysis prepared with Claude Code.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request.t-aiIssues owned by the AI team.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions