The current built-in ecosystem#
Endpoint inventory, software deployment and script execution through Action1.
16 static tools · Enabled by default
Permissions: action1.organizations.read, action1.endpoints.read, action1.software.read, action1.software.deploy, action1.software.uninstall, action1.scripts.read, action1.scripts.run, action1.powershell.run
Read-only Active Directory users, computers, groups and organizational units.
10 static tools · Enabled by default
Permissions: ad.health.read, ad.users.read, ad.computers.read, ad.groups.read, ad.ous.read
Per-user Codex App Server integration, opt-in, models and YAADMIN tool bridging.
1 static registration · Disabled by default
Permissions: codex.use, codex.manage
Owner-scoped file creation, reading and stored-table queries.
3 static tools · Enabled by default
Permissions: files.create, files.upload, files.read, files.delete
Discover and invoke tools from configured external MCP servers.
Dynamic MCP tools · Enabled by default
Permissions: mcp.use (fallback); per-tool permissions are discovered dynamically.
Read-only 1C HTTP service queries, nomenclature, stock and movements.
11 static tools · Enabled by default
Permissions: onec.schema.read, onec.query.read, onec.health.read, onec.warehouses.read, onec.nomenclature.read, onec.images.read, onec.document_text.read, onec.search.read, onec.stock.read, onec.movements.read
Resolve named infrastructure targets using connected providers.
1 static registration · Enabled by default
Permissions: targets.resolve
A small contract, a useful capability#
Modules supply metadata and register tools with descriptions, schemas, risk/approval and permissions. Loading/discovery connects those definitions to the generic runtime; external packages can extend the supported contracts without editing Core.
- Package
- Discovery
- Registry
- Permission / approval
- Execution
What the counts mean#
42 static registrations include the disabled/internal Codex bootstrap. MCP tools are dynamic and cannot be listed as permanent built-ins without a real server inventory. Enabling a module does not certify provider configuration or health.
Native versus possible integrations#
RAS, Terminal Server, Dahua/Video, U-Prox and n8n do not have verified native modules in this snapshot. Custom modules or compatible external MCP tools could expose other systems, but each capability needs its own implementation.