Tools, and the eight you did not register
You register some tools. A deep agent already had eight. Knowing what those eight are for is most of understanding why the library is shaped the way it is.
The default set
ls read_file write_file edit_file glob grep # filesystem
execute # execution
task # delegationPlus delete, added to the filesystem group in v0.7.
Read that as three groups rather than eight names. A filesystem, an execution facility, and a delegation facility. Those three are the whole thesis of the product, and the parameters from lesson 1 line up against them exactly: backend configures the first two, subagents configures the third.
Two of them are conditional in ways worth knowing:
executedepends on the backend. In Deep Agents, sandboxes are backends, and the backend is what grants execution. The tool is registered regardless. Whether it does anything is module 2’s story.taskis the subagent handoff tool, and it is only interesting once you have supplied subagents for it to hand off to. Module 4.
The filesystem is not a convenience
Your tools are a permanent tax
Every registered tool contributes its description to context on every single request, before the agent has done anything at all.
That is why v0.7’s headline saving is tool descriptions trimmed by roughly 43 percent, and why base input tokens fell by roughly 65 percent as a result. The library’s own fixed cost was its tool descriptions, and the fix was to write shorter ones.
Same arithmetic applies to yours. Twenty tools with generous descriptions is a real bill, paid on every turn of a loop that may run for hours. And it is the same cost model as a skill description or an AGENTS.md file, which is the point module 3 will make properly: anything always-present is priced per run, forever.
Shaping the tool surface
Three levers, and they solve different failures. Do not reach for the wrong one.
LLMToolSelectorMiddlewarenarrows what the model is offered. This is the answer to it keeps picking the wrong tool.ToolCallLimitMiddlewarecounts and stops. This is the answer to it is looping and burning money.wrap_tool_callsurrounds an individual invocation, which is the only shape that can log a call, substitute a result, or short-circuit a tool that is currently rate limited.
The third one is worth remembering as a shape rather than a name. A before or after hook can watch a tool call. Only a wrap hook holds the call itself, which is why retries, caching and substitution all live there and cannot be built out of observation.
Try it yourself
Not in the default set
A deep agent ships with tools already registered. One of these is not among them.
ls read_file write_file edit_file glob grep execute task
plus delete, added to the filesystem tools in v0.7Show answer
Correct answer: C — search_web
There is no default web search tool. Anything that reaches the outside world is yours to register, and that boundary is deliberate: the defaults are all about the agent's own working environment. delete is the tempting one because it is the newest and easiest to miss, but v0.7 added it to the default filesystem set, so it is in.
Why a filesystem, really
There is an obvious answer and a better one. The better one is the reason these tools are defaults rather than an optional extra.
Why does a deep agent ship with ls, read_file, glob and grep by default, rather than treating file access as something you opt into?
Reveal answer
Because they are the retrieval half of the offloading system. When a tool result exceeds the offload threshold it is written to a file and replaced in context by a path plus a head-and-tail preview, the first 5 lines and the last 5 with a truncation marker between them, so the agent needs a way to go and read the part it actually wants. Without file tools, offloading would be a mechanism for losing data rather than relocating it. The filesystem is an extension of the context window, and these tools are how the agent reaches into it.
Why the descriptions got trimmed
v0.7 trimmed tool descriptions by roughly 43 percent and cut base input tokens by roughly 65 percent. What is the relationship between those two numbers?
Show answer
Correct answer: A — Descriptions load into context on every request, so trimming cuts a per-call cost
Every registered tool's description sits in context on every request, so the description set is a fixed tax paid before the agent has done anything. Trimming it is the single cheapest saving available. The third option is tempting because shorter descriptions plausibly do help selection, but that would be a behavioural improvement rather than a token one, and the release quantifies tokens.
Twenty tools, wrong choices
An agent has twenty registered tools and keeps picking the wrong one. You want to narrow what it considers, not cap how often it acts. Which built-in?
Show answer
Correct answer: A — LLMToolSelectorMiddleware
LLMToolSelectorMiddleware shapes which tools the model is offered, which is what a selection problem needs. ToolCallLimitMiddleware is the genuinely tempting neighbour and it is the right answer to a different question: it bounds how many tool calls happen, which stops a runaway loop but does nothing about a wrong choice made once. Match the middleware family to the failure, not to the noun in the sentence.
Count your own tool tax
A five-minute audit of something you already have. No new code.
- Open any agent you have built and list every tool it registers.
- Next to each, write the first sentence of its description.
- Add the eight deep agent defaults to the bottom of the list as if you had adopted the harness.