# Claude Code Tool reference

> Claude Code: Built-in tools, permission rules, hook matchers, Bash/Edit/Grep/Agent behavior, and extending tools with MCP.

URL: https://docs.passion8.cc/en/docs/claude-code/tools
Language: en
Publisher: Passion8

Claude Code tool names appear in permissions, hook matchers, [subagent](https://docs.passion8.cc/en/docs/claude-code/subagents) `tools`, skill `allowed-tools`, and CLI flags. Understanding the names is essential to reliable permission and automation rules.

## Common built-in tools

| Tool | Purpose | Permission behavior |
| --- | --- | --- |
| `Read` | Read files | Governed by Read deny/allow |
| `Edit` | Exact replacement in a file | Usually requires approval |
| `Write` | Create or overwrite files | Usually requires approval |
| `Bash` | Run shell commands | Usually requires approval |
| `PowerShell` | Run PowerShell on Windows or when enabled | Usually requires approval |
| `Glob` | Find filenames | Normally no prompt |
| `Grep` | Search contents with ripgrep | Normally no prompt, subject to Read path rules |
| `LSP` | Definitions, references, type diagnostics | Normally no prompt |
| `Agent` | Start a subagent | Launch normally has no prompt; internal tools retain checks |
| `Monitor` | Monitor commands, logs, or WebSockets in the background | Usually requires approval |
| `WebFetch` | Read web pages | Usually requires approval |
| `WebSearch` | Search the web | Usually requires approval |
| `Skill` | Invoke a skill | Depends on skill and rules |
| `Workflow` | Run a dynamic workflow | Usually requires approval |

MCP tool names use `mcp__server__tool`. A `mcp__*` rule can target all MCP tools.

## Permission rule formats

| Format | Tools covered | Example |
| --- | --- | --- |
| `Bash(pattern)` | Bash, Monitor | `Bash(npm run *)` |
| `PowerShell(pattern)` | PowerShell | `PowerShell(Get-ChildItem *)` |
| `Read(path)` | Read, Grep, Glob, LSP | `Read(./docs/**)` |
| `Edit(path)` | Edit, Write, NotebookEdit | `Edit(./src/**)` |
| `Skill(name *)` | Skill | `Skill(deploy *)` |
| `Agent(name)` | Agent | `Agent(Explore)` |
| `WebFetch(domain:host)` | WebFetch | `WebFetch(domain:docs.example.com)` |
| `WebSearch` | WebSearch | `WebSearch` |

An Edit allow rule usually also grants reads for the same path. Hook matchers use plain tool names, such as `Edit|Write|Bash`, not permission patterns such as `Edit(./src/**)`.

## Bash behavior

| Rule | Detail |
| --- | --- |
| Each call starts a separate process | Exported variables do not automatically persist to the next command |
| cd can persist in the main session | Within the project or additionally authorized directories |
| Subagents do not inherit Bash cwd | Each uses its own working directory |
| Default timeout is about two minutes | Claude can request longer; environment variables can configure it |
| Long output is truncated | Full output may be saved in session files for later reading |
| Long-running tasks can run in the background | Inspect or stop them with `/tasks` |

For persistent variables, configure the shell before launching Claude, or use `CLAUDE_ENV_FILE` / a SessionStart hook.

## Edit behavior

Edit performs exact string replacement, not a fuzzy patch. It checks:

| Check | Meaning |
| --- | --- |
| Read-before-edit | The session must have read the file, without an external change since |
| Match | old_string must match exactly |
| Uniqueness | Usually one match; otherwise provide more context or replace_all |

Reading through Bash does not always count. Simple `cat`, `sed -n`, `head`, or `tail` may qualify, while pipes, redirects, and scripted reads usually do not. Prefer Read when in doubt.

## Grep, Glob, and LSP

| Tool | Notes |
| --- | --- |
| Glob | Finds names, sorts by modification time, and may include gitignored files |
| Grep | Uses ripgrep, respects .gitignore by default, and follows rg regex syntax |
| LSP | Requires the language's code-intelligence plugin |

In large repositories, locate symbols with Grep/LSP before reading a few key files. This reduces context usage and improves cache reuse.

## Agent tool

Agent launches [subagents](https://docs.passion8.cc/en/docs/claude-code/subagents) with separate context windows and caches. They return final results to the main session.

| Scenario | Recommendation |
| --- | --- |
| Broad research | Isolate file reads in a subagent |
| Result needed immediately | Foreground subagent |
| Independent parallel work | Background subagent or /batch |
| Sensitive tools | Restrict tools or disallowedTools in subagent frontmatter |

Launching a subagent normally does not prompt, but its Bash/Edit/Write operations still follow permissions. Use [worktrees](https://docs.passion8.cc/en/docs/claude-code/worktrees) to isolate file changes.

## Extend tools with MCP

Built-in tools handle editing and local execution. Use MCP for external systems:

| Need | Approach |
| --- | --- |
| Databases, Sentry, Linear, GitHub | Connect an MCP server |
| Many tools | Use supported tool search or split servers |
| Restrict an MCP tool | `deny: ["mcp__server__tool"]` |
| Observe calls | Match `mcp__server__tool` in a hook |

See [MCP integration](https://docs.passion8.cc/en/docs/claude-code/mcp).

## Official references

- [Tools reference](https://code.claude.com/docs/en/tools-reference.md)
- [Configure permissions](https://code.claude.com/docs/en/permissions.md)
- [Hooks reference](https://code.claude.com/docs/en/hooks.md)
