Skip to content

Tools and workspace

Rho uses the current working directory as the workspace and as the base for relative file paths and shell commands. Start the interactive TUI or automation command from the repository or directory you want Rho to use as its main work context.

File paths can point outside that directory with parent components such as ../ or with absolute paths. Read Security and workspace boundaries before you rely on permission modes as a sandbox.

Built-in tools

Core workspace tools on every platform:

ToolRole
list_dirList directory entries
read_fileRead text, documents, and images
writeCreate or fully rewrite a file
edit, apply_patch, or str_replaceEdit files with the selected format
grepSearch file contents with a regex (in-process)
globList paths that match a glob (in-process)

Rho exposes exactly one edit tool at a time. Select it with behavior.edit_tool or /config > Tools > Edit tool. The default is auto, which picks the format the active provider's models were trained to use in their first-party harness (apply_patch for Codex, str_replace for Anthropic and xAI, hashline otherwise). See Edit tool for the full catalog and pin options.

Additional tools:

ToolRole
bash / powershellNative shell for the current platform (RTK rewrite when available)
processStart, poll, or stop a managed background shell process
web_searchHosted provider search when available, otherwise the configured backup
fetch_contentFetch pages, GitHub URLs, local files, PDFs, and video targets
get_search_contentRetrieve stored content from a prior web tool call
workflowValidate, freeze, run, inspect, cancel, or resume a durable workflow
skillLoad a skill into the session
rhoRead-only harness diagnostics
advisorSecond-model review when advisor mode is on

Prefer grep and glob over shell search for workspace inspection. Both honor .gitignore, skip hidden files by default, never follow symlinks, and request read access only, so they work in every permission mode including plan. Agent shell commands can use RTK for token-efficient output when the binary is installed.

Built-in skills that ship with the binary include rho-diagnostics, rho-config, rho-agent-creator, and rho-workflow-authoring. Custom skills live under ~/.rho/skills/<name>/SKILL.md, ~/.agents/skills/<name>/SKILL.md, or <project-root>/.agents/skills/<name>/SKILL.md. Set disable-model-invocation: true in a skill's frontmatter to keep it available only through /skill:<name>.

Security and workspace boundaries

Tools run with the current user's permissions. File tools can read or modify any path that the user can access, including paths outside the workspace, and shell commands can do the same.

The default auto permission mode allows this behavior. plan denies file writes and process execution, while supervised asks for interactive confirmation before those operations. Supervised non-interactive runs fail closed because no approval UI is available.

Permission modes are policy checks at Rho's tool-capability boundary, not an operating-system sandbox. They do not reduce the permissions of the Rho process itself, and they depend on tools correctly declaring and authorizing capabilities. The SDK still scopes file access by default; embedded hosts must opt into broader access when they build a Workspace. Run Rho only in workspaces where you are comfortable with the selected mode and these limits.

For session storage separate from the workspace, see sessions. For output-size settings, see configuration.

File edits and writes

Rho supports three edit formats and registers only the selected tool:

  • edit (config/selector hashline) applies snapshot-tagged, line-anchored PUT and CUT operations to existing files.
  • apply_patch applies Codex-style add, delete, update, and move sections across one or more files. Patch paths must be workspace-relative, must not contain .., and Add File targets must not exist.
  • str_replace replaces an exact string in one existing file, with an optional replace_all flag.

Use write for a complete create-or-replace operation. Successful file mutations return model-facing snapshots for chaining, while unified diffs stay in tool metadata for UI cards. In the interactive TUI, added lines are highlighted in green, removed lines in red, and diff headers use the accent color.

Details for the default format: Hash-line edit format.

Search tools

grep and glob run in-process, honor ignore rules, and stay read-only so they work in every permission mode including plan.

Details: Search tools.

Documents and images

read_file and fetch_content extract text-layer PDFs and Office docs under strict size limits, and can show bounded image thumbnails in supporting terminals.

Details: Documents and images.

Web tools store large bodies by responseId, refuse private destinations by default, and add provider amenities such as xAI x_search when relevant.

Details: Web access and related tools.

Background processes

The process tool starts, polls, and stops managed background shell commands owned by the current Rho instance only.

Details: Background processes.