Overview

Loop’s agent comes with four built-in tools that let it interact with your filesystem and execute commands. Each tool has safety guardrails, configurable permissions, and detailed output.

read

Read file contents from the filesystem. Behavior:
  • Returns file contents with line numbers
  • Automatically truncates large files
  • Detects and labels binary files
  • Resolves relative paths against the working directory

write

Create or overwrite files. Behavior:
  • Creates parent directories if they don’t exist
  • Overwrites existing files
  • Subject to tool approval policy (default: ask)

edit

Perform exact string replacements in files. Produces unified diff output. Behavior:
  • Requires exact match of old_string in the file
  • Shows a unified diff of the change
  • Supports diff review in external editor (VS Code / Cursor)
  • Subject to tool approval and file edit review policies

bash

Execute shell commands with a configurable timeout. Behavior:
  • Default 120-second timeout
  • Subject to command safety blocklist
  • Returns stdout, stderr, and exit code
  • Can run in container sandbox when configured

Command Safety

Before any command executes, it passes through check_command_policy, which blocks dangerous patterns:
The following patterns are blocked by default:
  • rm -rf / and variants
  • Fork bombs (e.g., :(){ :|:& };:)
  • Disk wipe patterns (dd if=/dev/zero)
  • Other destructive operations
You can extend the blocklist through the safety policy system.

Tool Execution Modes

Tools can execute in parallel or sequentially, configurable per-tool: The agent determines execution order based on dependencies between tool calls.

Hooks

Loop supports declarative hooks that fire at various points in the agent lifecycle: Configure hooks as JSON files in ~/.loop/agent/hooks/:

Tool Permissions

Configure approval policies for each tool.