mirror of
https://github.com/tiennm99/DocsGPT.git
synced 2026-10-03 11:11:58 +00:00
Enable code_executor and artifact_generator by default in chats (added to DEFAULT_CHAT_TOOLS) — they load via the synthetic-id path user- and conversation-scoped like scheduler, and persist artifacts (no user_tools FK). Make read_document an internal agent-builtin flagged workflow_only so it appears only in the workflow builder, not the classic agent picker or the Add-Tool catalog (reuses the builtin synthetic-id path; still run-scoped and authz-gated). Per decision, default-on code_executor runs sandboxed code without an approval prompt (the sandbox is the trust boundary); this is documented in settings and the threat model, and multi-tenant deployments should add per-tenant isolation (Daytona / gVisor / egress policy).