DreamAgent
Build and deploy websites, Telegram and Discord bots from chat via the DreamAgent platform.
- 1.0.0
- Version
- remote
- Transport
- 20
- Tools
Security review
Review passedReviewed Jan 1, 2000.
- tools: 20 tools scanned
- metadata: scanned
No findings.
Tools (20)
dreamagent_list_projects
List the user's DreamAgent projects. Returns each project's name, ID, type, status, and live domain (when available). Use when the user asks to see, find, select, or check their projects — and ALWAYS before modifying a project when its ID is not already known (resolve names to IDs here first).
dreamagent_list_global_integrations
List the user's saved credentials (Global Integrations). ALWAYS call this before creating any bot project or asking the user for a token/API key. Saved credentials are referenced BY ID when creating projects: bot_token_integration_id for bot tokens, global_integration_ids for other keys. Secret values are never returned — only IDs and metadata (type, key name, verified, title). If nothing suitable is saved: direct the user to dreamagent.cloud → Settings → Global Integrations to add it (one-time, verified, reusable). Never ask the user to paste tokens in chat.
dreamagent_list_project_env
List a project's environment variables with their details. Shows each key's name, title, description, docs URL, and category — values are masked (secrets are never returned). Use to see which integrations a project already has before adding more, or to answer "what keys does my project have?". These are PROJECT-SPECIFIC variables — distinct from the user's Global Integrations — API-key credentials and connected OAuth services (dreamagent_list_global_integrations).
dreamagent_list_superpowers
List DreamAgent Superpowers — the account's ready-made AI tools (song/video/image generation, voiceover, lip sync, voice clone, transcription, media processing, PDF tools) with their enabled state and beta pricing. Read-only; no credits consumed. Use when the user asks what AI tools/superpowers are available, whether a specific tool is enabled, or what they can add to a project. Tools shown as enabled can be used from ANY of the user's projects through dreamagent_chat (just ask in the message).
dreamagent_list_files
List the file tree of a DreamAgent project (source files only — hidden files like .env are excluded). Use before reading or editing a file to find the correct path.
dreamagent_read_file
Read a source file from a DreamAgent project. file_path is the project-relative path (from dreamagent_list_files), e.g. "src/pages/Home.tsx" or "telegram/main.py". Hidden files (.env) and binaries are not readable.
dreamagent_write_file
WRITE ACTION — overwrite or create one source file in a DreamAgent project with the exact content given. Changes go live after the project is rebuilt (dreamagent_build_publish). CONFIRM BEFORE CALLING — in ONE message show the user: the target path and a summary of the change, then call only after they agree. Never write on the first mention. GUARDS (enforced server-side, the same as the in-app code editor): path stays inside the project, hidden/credential files (.env, .git, keys) are rejected, content is scanned for malware/shell signatures and blocked, 2MB size cap. Failed scans return the reason. The user can undo damage by editing in the DreamAgent editor, so a wrong write is recoverable — still, prefer precise minimal diffs.
dreamagent_get_file_diff
Git diff of one project file against the last commit — shows the pending (not yet live) changes. Free, read-only. Use after edits to review exactly what changed before rebuilding.
dreamagent_delete_file
WRITE ACTION — delete one source file from a DreamAgent project. Hidden/credential files (.env, .git, keys) are rejected. Recoverable via the project's git history. CONFIRM BEFORE CALLING — tell the user which file will be deleted and call only with confirm=true after they agree.
dreamagent_build_publish
WRITE ACTION — build & publish a DreamAgent project: rebuilds the app from the current source files and pushes the new version live. Use after finishing file edits (dreamagent_write_file) so the user's changes go live. Pro/paid accounts only. CONFIRM BEFORE CALLING — tell the user the project will be rebuilt and redeployed, and call only with confirm=true after they agree. ASYNCHRONOUS: kick-off returns immediately; check dreamagent_get_project_status until the project reports 'ready'.
dreamagent_design_mode
WRITE ACTION — redesign a website project's UI to match a design image. Website projects only. The user provides an image (screenshot, mockup, AI-generated design) and instructions. You generate the image (e.g. DALL-E), encode it as base64, and send it here. DreamAgent's AI will read the image and redesign the project's frontend to match. CONFIRM BEFORE CALLING — show the user: 1. The project being redesigned 2. The design instructions Then call only with confirm=true after they agree.
dreamagent_create_project
WRITE ACTION — creates a new DreamAgent project (website, Telegram bot, Discord bot, or AI agent). Use ONLY when the user clearly asks to create/build a new project; not for questions about what to build. CONFIRM BEFORE CALLING — never create on the first mention. In ONE message, present and get the user's explicit go-ahead for: 1. The credential: run dreamagent_list_global_integrations first. If several telegram/discord credentials are saved, list them (id + title) and ask which to use. If exactly one is saved, state which one you will use. Never pick silently. 2. The plan: name, type, and the final description exactly as you will submit it (this is the Prompt Assistant's recommendation summary). Call this tool only after the user confirms. CREATION IS ASYNCHRONOUS: after calling, check dreamagent_get_project_status repeatedly until the project is 'ready' or 'failed' (bots ~2-5 min, websites longer). CREDENTIALS: raw bot tokens are never accepted in chat or as inputs
dreamagent_get_project_status
Check a project's creation/deployment state. Terminal states are 'ready' (built and live) and 'failed'; while a project is being created it reports progressive phases such as 'creating', 'building', 'deploying', or 'ai_provisioning' — treat any non-terminal status as still building. Use after dreamagent_create_project (poll until ready or failed) and whenever the user asks whether a project is ready or live. NOTE: this reports the PROJECT's build/deploy state — NOT AI edit progress. For edits use dreamagent_get_edit_progress.
dreamagent_chat
WRITE ACTION — builds, modifies, or fixes an EXISTING project with a natural-language instruction. Use ONLY when the user clearly asks for a change ("add X", "fix Y", "change the theme"). If the user is only asking for advice, analysis, review, or suggestions ("what could be improved?", "review my bot"), do NOT call this — answer from the project's info instead; a review request is not an edit. Describe ONLY the desired change — DreamAgent's AI automatically handles code, tests, rebuild, and redeployment. Completed changes are saved and committed automatically. ASYNCHRONOUS: returns immediately with the session_key; monitor with dreamagent_get_edit_progress (or dreamagent_get_chat_status with the returned session key) until a terminal state. Report success only after run_status reaches 'completed'. Edits consume the user's AI credits. ERRORS (actual returns): failures come back as text starting with 'ERROR:'. If the edit was rejected before starting, the text says 'the edit was NOT
dreamagent_list_sessions
List a project's development sessions (conversation threads). Returns each session's identifier (session key) and context so you can select, continue, or monitor a specific development session — pass the session key to dreamagent_chat to continue that thread or to dreamagent_get_chat_status to monitor it. The session key is a reference used to address a session; it is not an authentication credential or a secret.
dreamagent_create_session
Create a new development session for a project — a separate conversation with its own context. Use when the user wants to start a distinct development topic. A new session does NOT replace or affect the existing project — earlier sessions remain available.
dreamagent_release_project_lock
RECOVERY-ONLY — releases a project's editing lock when a stale or abandoned session blocks new modifications. NOT a normal editing step, and NEVER a way to bypass an actively running edit. The lock state is not machine-readable from here: to judge staleness, check dreamagent_get_edit_progress — if no edit is active but dreamagent_chat still fails with a lock error, the lock is stale. Confirm with the user before releasing if they may have the project open elsewhere.
dreamagent_get_chat_status
Check the progress and final status of a specific AI development session using its session key. Use this to monitor an asynchronous edit until it completes, fails, or is cancelled — keep checking until a terminal state. The session key comes from dreamagent_chat or dreamagent_list_sessions and is an identifier, not a secret. Returns (actual fields): 'active=', 'run_status=', 'next_after=' (cursor for the next check), optional 'new_output:' (text produced since the last check), then either "Still working — poll again" or a terminal 'done=true' line: finished (with the final output tail), 'the edit was NOT started: <reason>' (rejected early, e.g. HTTP 402 insufficient credits), or 'stream error' (the connection to the run broke — the server-side run may still have finished; verify with dreamagent_get_edit_progress). run_status values: queued | running | cancel_requested | completed | failed | cancelled | interrupted | unknown.
dreamagent_get_edit_progress
Check the latest AI edit progress for a project using its project identifier — no session key needed: the project id retrieves the session holding the latest edit. Use when the user asks whether their edit is finished, when the session key isn't available (e.g. a new conversation), and BEFORE starting any new edit. Returns (actual fields): 'session_key=' (the identifier of the session this progress comes from), 'edit_active=', 'run_status=', 'chunks=' (output size so far), optional 'recent_output (tail):', and a terminal 'result:' line: finished (with the final output tail), 'the edit was NOT started: <reason>' (rejected early, e.g. HTTP 402 insufficient credits), 'stream error', or 'no run is currently active'. run_status values: queued | running | cancel_requested | completed | failed | cancelled | interrupted | unknown. Distinct from dreamagent_get_project_status: project status = creation/deployment state (creating/ready/failed); edit progress = current AI modification state; cha
dreamagent_cancel_chat
DESTRUCTIVE — stops an AI edit that is currently running. Use ONLY when the user explicitly asks to stop/cancel the active edit. After cancellation, do NOT claim the requested change was completed — report that it was stopped. Returns 'Cancellation requested: <backend message>' — e.g. 'Query cancelled', 'Cancellation requested' (durable run), or 'No active query found'. Afterwards poll dreamagent_get_chat_status / dreamagent_get_edit_progress until run_status reports 'cancelled'.