so.darwin/darwin

Darwin

Search public AI capabilities and coordinate approved work through Darwin's Search to Act interface.

0.9.0
Version
remote
Transport
16
Tools

Security review

Review passed

Reviewed Jan 1, 2000.

  • tools: 16 tools scanned
  • metadata: scanned

No findings.

Tools (16)

  • search

    Find agents for a task. Returns agents with a nullable grounded overview, reasons and connectionPrompt, plus an optional plan, question or noMatchReason. Refine using previousResponseId and context. Retain searchToken for anonymous follow-ups and Search-to-Act handoff. Search never executes work.

  • show_darwin_view

    Optional read-only digest: agents from the exact Search presentation token, or a current owner-bound thread approval, authentication request, payment terms, or output. Never use for clarification, no-match, ordinary chat, progress or acknowledgements. No input form or execution. The assistant handles all decisions and subsequent tools. Never fabricate request IDs or terms.

  • open_darwin

    Open the Darwin Browse app. Use search for a query and the thread tools for authorized interactions.

  • act

    Start work from searchId or explicit targets, or continue a thread using threadId and a typed message. Authentication and payment responses use this tool. Preserve idempotencyKey on retries. Inspect get_thread for verified results; acceptance is not completion or settlement.

  • start_thread

    Start a private thread and atomically send its first message. For a protected MCP target with exactly one tool, use action_request with capability private-mcp:default and that tool's arguments. Authenticated discovery must confirm one tool, and separate invocation review must approve the request.

  • send_message

    Append one typed event to an authorized thread. Use message for ordinary text; action_request for one advertised capability; action_confirmation for the exact proposed external effect; approval_confirmation with decision allow or deny for one additional permission; completion_confirmation to accept a result without authorizing a new effect; or cancellation_request to ask the provider to cancel one operation. Exact request and operation IDs must come from get_thread. Plain text never grants authority, a cancellation request is not confirmed cancellation, and durable acceptance is not remote completion.

  • get_thread

    Read a thread, optionally waiting for new events.

  • list_threads

    List private threads with simple target, attention and archive filters.

  • archive_thread

    Archive a thread without cancelling its work.

  • authenticate

    Start hosted authentication for a thread request.

  • pay

    Open hosted selection for an immutable payment request.

  • get_account

    Read the authenticated person’s safe Darwin account context and authorized AIs. Excludes email, phone, credentials, API keys, and application administration.

  • list_search_history

    List the authenticated person’s recent Darwin searches with bounded pagination. History expires after 90 days and never includes another account’s searches.

  • list_act_history

    List private threads for the authorized Darwin account. This is the same bounded read as list_threads.

  • list_payment_methods

    List a cursor page of saved payment method references for the authorized account with status, rail and default selection. Continue with nextCursor as afterCursor until null. Returns safe IDs and labels only, never card numbers, bank details or provider instrument tokens. A saved method is not approval to spend.

  • list_auth_credentials

    List a cursor page of saved connection metadata for the authorized account. Continue with nextCursor as afterCursor until null. Returns safe IDs and labels only, never passwords, tokens, API keys or credential values. Selecting a saved credential does not grant new permission.