Skip to content

Expose configured Huabu capabilities to external agents #110

Description

@mydmdm

Summary

Expose Huabu capabilities to external agents through a secure, capability-scoped interface. External agents should be able to use the same user-configured Huabu capabilities that are available to the native experience, without receiving raw credentials or bypassing Huabu authorization and policy controls.

Motivating examples

  • Web search: allow an external agent to invoke web search using the user's configured Tavily token and Huabu's existing search behavior.
  • Image generation: allow an external agent to request image generation using the user's configured model/provider and Huabu's existing image-generation flow.
  • Future capabilities: make it possible to add more Huabu tools—such as document/file operations, media processing, or other model providers—without creating a separate integration for every external agent runtime.

Requirements

  • Define a stable external-agent capability contract and tool discovery mechanism.
  • Expose capabilities by explicit allowlist and scope, not by granting unrestricted access to Huabu internals.
  • Keep provider credentials, tokens, model configuration, and other secrets server-side; external agents receive operation results, not raw secrets.
  • Reuse the user's existing Huabu configuration, authorization, quotas, policy checks, and audit/error semantics.
  • Support capability-specific input validation, cancellation/timeouts, bounded resource use, and clear errors when a capability is unavailable or not configured.
  • Preserve Space, Canvas, tenant, and user authorization boundaries for every invocation.
  • Make the interface usable by external agent runtimes over the supported agent/RFS integration surface, with documentation and examples.
  • Define compatibility/versioning expectations so capabilities can evolve without silently changing behavior for existing agents.

Security considerations

  • Never inject Tavily tokens, model-provider credentials, or other secrets into agent prompts, tool descriptions, generated HTML, or client-visible state.
  • Prevent an external agent from selecting arbitrary credentials, providers, models, or scopes outside the user's authorized configuration.
  • Apply rate limits, cost controls, origin/thread attribution, and audit logging consistently with native Huabu operations.
  • Return only the minimum result data required by the requested capability.

Acceptance criteria

  • An external agent can discover whether web search and image generation are available.
  • An authorized external agent can invoke web search using the user's configured Tavily integration without seeing the token.
  • An authorized external agent can invoke image generation using the user's configured model/provider without seeing provider credentials.
  • Unauthorized, unconfigured, invalid, timed-out, and over-limit requests fail explicitly and safely.
  • Existing native Huabu capability behavior remains compatible.
  • The capability contract, authorization model, credential boundary, lifecycle, and at least one integration test per initial capability are documented.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions