Tool reference
Built-in tools, permission rules, hook matchers, Bash/Edit/Grep/Agent behavior, and extending tools with MCP.
Claude Code tool names appear in permissions, hook matchers, subagent tools, skill allowed-tools, and CLI flags. Understanding the names is essential to reliable permission and automation rules.
#Common built-in tools
| Tool | Purpose | Permission behavior |
|---|---|---|
Read | Read files | Governed by Read deny/allow |
Edit | Exact replacement in a file | Usually requires approval |
Write | Create or overwrite files | Usually requires approval |
Bash | Run shell commands | Usually requires approval |
PowerShell | Run PowerShell on Windows or when enabled | Usually requires approval |
Glob | Find filenames | Normally no prompt |
Grep | Search contents with ripgrep | Normally no prompt, subject to Read path rules |
LSP | Definitions, references, type diagnostics | Normally no prompt |
Agent | Start a subagent | Launch normally has no prompt; internal tools retain checks |
Monitor | Monitor commands, logs, or WebSockets in the background | Usually requires approval |
WebFetch | Read web pages | Usually requires approval |
WebSearch | Search the web | Usually requires approval |
Skill | Invoke a skill | Depends on skill and rules |
Workflow | Run a dynamic workflow | Usually requires approval |
MCP tool names use mcp__server__tool. A mcp__* rule can target all MCP tools.
#Permission rule formats
| Format | Tools covered | Example |
|---|---|---|
Bash(pattern) | Bash, Monitor | Bash(npm run *) |
PowerShell(pattern) | PowerShell | PowerShell(Get-ChildItem *) |
Read(path) | Read, Grep, Glob, LSP | Read(./docs/**) |
Edit(path) | Edit, Write, NotebookEdit | Edit(./src/**) |
Skill(name *) | Skill | Skill(deploy *) |
Agent(name) | Agent | Agent(Explore) |
WebFetch(domain:host) | WebFetch | WebFetch(domain:docs.example.com) |
WebSearch | WebSearch | WebSearch |
An Edit allow rule usually also grants reads for the same path. Hook matchers use plain tool names, such as Edit|Write|Bash, not permission patterns such as Edit(./src/**).
#Bash behavior
| Rule | Detail |
|---|---|
| Each call starts a separate process | Exported variables do not automatically persist to the next command |
| cd can persist in the main session | Within the project or additionally authorized directories |
| Subagents do not inherit Bash cwd | Each uses its own working directory |
| Default timeout is about two minutes | Claude can request longer; environment variables can configure it |
| Long output is truncated | Full output may be saved in session files for later reading |
| Long-running tasks can run in the background | Inspect or stop them with /tasks |
For persistent variables, configure the shell before launching Claude, or use CLAUDE_ENV_FILE / a SessionStart hook.
#Edit behavior
Edit performs exact string replacement, not a fuzzy patch. It checks:
| Check | Meaning |
|---|---|
| Read-before-edit | The session must have read the file, without an external change since |
| Match | old_string must match exactly |
| Uniqueness | Usually one match; otherwise provide more context or replace_all |
Reading through Bash does not always count. Simple cat, sed -n, head, or tail may qualify, while pipes, redirects, and scripted reads usually do not. Prefer Read when in doubt.
#Grep, Glob, and LSP
| Tool | Notes |
|---|---|
| Glob | Finds names, sorts by modification time, and may include gitignored files |
| Grep | Uses ripgrep, respects .gitignore by default, and follows rg regex syntax |
| LSP | Requires the language's code-intelligence plugin |
In large repositories, locate symbols with Grep/LSP before reading a few key files. This reduces context usage and improves cache reuse.
#Agent tool
Agent launches subagents with separate context windows and caches. They return final results to the main session.
| Scenario | Recommendation |
|---|---|
| Broad research | Isolate file reads in a subagent |
| Result needed immediately | Foreground subagent |
| Independent parallel work | Background subagent or /batch |
| Sensitive tools | Restrict tools or disallowedTools in subagent frontmatter |
Launching a subagent normally does not prompt, but its Bash/Edit/Write operations still follow permissions. Use worktrees to isolate file changes.
#Extend tools with MCP
Built-in tools handle editing and local execution. Use MCP for external systems:
| Need | Approach |
|---|---|
| Databases, Sentry, Linear, GitHub | Connect an MCP server |
| Many tools | Use supported tool search or split servers |
| Restrict an MCP tool | deny: ["mcp__server__tool"] |
| Observe calls | Match mcp__server__tool in a hook |
See MCP integration.
#Official references
Support
Need help?
For setup, billing, or model issues, email us. Check the status page for uptime.
WeChat / QQ support is available at the bottom right.

