#!/usr/bin/env python3 """ s06: 子 Agent — 用全新的 messages[] 启动子 Agent,实现上下文隔离。 父 Agent 子 Agent +------------------+ +------------------+ | messages=[...] | | messages=[task] | <-- 全新上下文 | | 分发 | | | tool: task | ---------------> | 自己的 while 循环 | | prompt="..." | | bash/read/... | | | 只返回摘要 | (最多 30 轮) | | result = "..." | <--------------- | 返回最后文本 | +------------------+ +------------------+ ^ | | 中间结果会被丢弃 | +--------------------------------------+ 子 Agent 工具:bash、read、write、edit、glob(没有 task,避免递归) 相对 s05 的变化: + task 工具 + 使用全新 messages[] 的 spawn_subagent() + 安全上限:每个子 Agent 最多 30 轮 + extract_text() 辅助函数 子 Agent 不能再启动子子 Agent(sub_tools 里没有 task 工具)。 主循环不变:task 通过 TOOL_HANDLERS 自动分发。 运行: python s06_subagent/code.py 需要: pip install anthropic python-dotenv + .env 中配置 ANTHROPIC_API_KEY """ import ast, json, os, subprocess from pathlib import Path try: import readline readline.parse_and_bind('set bind-tty-special-chars off') except ImportError: pass from anthropic import Anthropic from dotenv import load_dotenv load_dotenv(override=True) if os.getenv("ANTHROPIC_BASE_URL"): os.environ.pop("ANTHROPIC_AUTH_TOKEN", None) WORKDIR = Path.cwd() client = Anthropic(base_url=os.getenv("ANTHROPIC_BASE_URL")) MODEL = os.environ["MODEL_ID"] CURRENT_TODOS: list[dict] = [] SYSTEM = ( f"你是位于 {WORKDIR}. " "遇到复杂子问题时,使用 task 工具启动一个子 Agent。" ) # s06: 子 Agent 使用自己的系统提示词 — 没有 task,不递归 SUB_SYSTEM = ( f"你是位于 {WORKDIR}. " "完成交给你的任务,然后返回简洁摘要。" "不要继续委派。" ) # ═══════════════════════════════════════════════════════════ # 来自 s02-s05 (未改动): 工具实现 # ═══════════════════════════════════════════════════════════ def safe_path(p: str) -> Path: path = (WORKDIR / p).resolve() if not path.is_relative_to(WORKDIR): raise ValueError(f"路径逃逸出工作区:{p}") return path def run_bash(command: str) -> str: try: r = subprocess.run(command, shell=True, cwd=WORKDIR, capture_output=True, text=True, timeout=120) out = (r.stdout + r.stderr).strip() return out[:50000] if out else "(无输出)" except subprocess.TimeoutExpired: return "错误:执行超时(120 秒)" def run_read(path: str, limit: int | None = None) -> str: try: lines = safe_path(path).read_text().splitlines() if limit and limit < len(lines): lines = lines[:limit] + [f"... ({len(lines) - limit} 行更多内容)"] return "\n".join(lines) except Exception as e: return f"错误:{e}" def run_write(path: str, content: str) -> str: try: file_path = safe_path(path) file_path.parent.mkdir(parents=True, exist_ok=True) file_path.write_text(content) return f"已写入 {len(content)} 字节到 {path}" except Exception as e: return f"错误:{e}" def run_edit(path: str, old_text: str, new_text: str) -> str: try: file_path = safe_path(path) text = file_path.read_text() if old_text not in text: return f"错误:在文件中未找到目标文本:{path}" file_path.write_text(text.replace(old_text, new_text, 1)) return f"已编辑 {path}" except Exception as e: return f"错误:{e}" def run_glob(pattern: str) -> str: import glob as g try: results = [] for match in g.glob(pattern, root_dir=WORKDIR): if (WORKDIR / match).resolve().is_relative_to(WORKDIR): results.append(match) return "\n".join(results) if results else "(无匹配)" except Exception as e: return f"错误:{e}" def _normalize_todos(todos): if isinstance(todos, str): try: 个待办 = json.loads(todos) except json.JSONDecodeError: try: 个待办 = ast.literal_eval(todos) except (SyntaxError, ValueError): return None, "错误:todos 必须是列表或 JSON 数组字符串" if not isinstance(todos, list): return None, "错误:todos 必须是列表" for i, t in enumerate(todos): if not isinstance(t, dict): return None, f"错误:todos[{i}] 必须是对象" if "content" not in t or "status" not in t: return None, f"错误:todos[{i}] 缺少 'content' 或 'status'" if t["status"] not in ("pending", "in_progress", "completed"): return None, f"错误:todos[{i}] 包含无效状态 '{t['status']}'" return 个待办, None def run_todo_write(todos: list) -> str: global CURRENT_TODOS 个待办, error = _normalize_todos(todos) if error: return error CURRENT_TODOS = 个待办 lines = ["\n\033[33m## 当前任务\033[0m"] for t in CURRENT_TODOS: icon = {"pending": " ", "in_progress": "\033[36m▸\033[0m", "completed": "\033[32m✓\033[0m"}[t["status"]] lines.append(f" [{icon}] {t['content']}") print("\n".join(lines)) return f"已更新 {len(CURRENT_TODOS)} 个任务" TOOLS = [ {"name": "bash", "description": "运行一条 shell 命令。", "input_schema": {"type": "object", "properties": {"command": {"type": "string"}}, "required": ["command"]}}, {"name": "read_file", "description": "读取文件内容。", "input_schema": {"type": "object", "properties": {"path": {"type": "string"}, "limit": {"type": "integer"}}, "required": ["path"]}}, {"name": "write_file", "description": "向文件写入内容。", "input_schema": {"type": "object", "properties": {"path": {"type": "string"}, "content": {"type": "string"}}, "required": ["path", "content"]}}, {"name": "edit_file", "description": "在文件中替换一次完全匹配的文本。", "input_schema": {"type": "object", "properties": {"path": {"type": "string"}, "old_text": {"type": "string"}, "new_text": {"type": "string"}}, "required": ["path", "old_text", "new_text"]}}, {"name": "glob", "description": "查找匹配 glob 模式的文件。", "input_schema": {"type": "object", "properties": {"pattern": {"type": "string"}}, "required": ["pattern"]}}, {"name": "todo_write", "description": "为当前编码会话创建并维护任务清单。", "input_schema": {"type": "object", "properties": {"todos": {"type": "array", "items": {"type": "object", "properties": {"content": {"type": "string"}, "status": {"type": "string", "enum": ["pending", "in_progress", "completed"]}}, "required": ["content", "status"]}}}, "required": ["todos"]}}, ] TOOL_HANDLERS = { "bash": run_bash, "read_file": run_read, "write_file": run_write, "edit_file": run_edit, "glob": run_glob, "todo_write": run_todo_write, } # ═══════════════════════════════════════════════════════════ # 新增于 s06: 子 Agent — 全新 messages[],只返回摘要 # ═══════════════════════════════════════════════════════════ SUB_TOOLS = [ {"name": "bash", "description": "运行一条 shell 命令。", "input_schema": {"type": "object", "properties": {"command": {"type": "string"}}, "required": ["command"]}}, {"name": "read_file", "description": "读取文件内容。", "input_schema": {"type": "object", "properties": {"path": {"type": "string"}}, "required": ["path"]}}, {"name": "write_file", "description": "向文件写入内容。", "input_schema": {"type": "object", "properties": {"path": {"type": "string"}, "content": {"type": "string"}}, "required": ["path", "content"]}}, {"name": "edit_file", "description": "在文件中替换一次完全匹配的文本。", "input_schema": {"type": "object", "properties": {"path": {"type": "string"}, "old_text": {"type": "string"}, "new_text": {"type": "string"}}, "required": ["path", "old_text", "new_text"]}}, {"name": "glob", "description": "查找匹配 glob 模式的文件。", "input_schema": {"type": "object", "properties": {"pattern": {"type": "string"}}, "required": ["pattern"]}}, ] # 没有 "task" 工具 — 防止递归启动 SUB_HANDLERS = { "bash": run_bash, "read_file": run_read, "write_file": run_write, "edit_file": run_edit, "glob": run_glob, } def extract_text(content) -> str: """Extract text from message content blocks.""" if not isinstance(content, list): return str(content) return "\n".join(getattr(b, "text", "") for b in content if getattr(b, "type", None) == "text") def spawn_subagent(description: str) -> str: """Spawn a subagent with fresh messages[], return summary only.""" print(f"\n\033[35m[子 Agent 已启动]\033[0m") messages = [{"role": "user", "content": description}] # 全新上下文 for _ in range(30): # 安全上限 response = client.messages.create( model=MODEL, system=SUB_SYSTEM, messages=messages, tools=SUB_TOOLS, max_tokens=8000, ) messages.append({"role": "assistant", "content": response.content}) if response.stop_reason != "tool_use": break results = [] for block in response.content: if block.type == "tool_use": # 问题 1:子 Agent 也运行 Hooks(权限同样生效) blocked = trigger_hooks("PreToolUse", block) if blocked: results.append({"type": "tool_result", "tool_use_id": block.id, "content": str(blocked)}) continue handler = SUB_HANDLERS.get(block.name) output = handler(**block.input) if handler else f"未知工具:{block.name}" trigger_hooks("PostToolUse", block, output) print(f" \033[90m[sub] {block.name}: {str(output)[:100]}\033[0m") results.append({"type": "tool_result", "tool_use_id": block.id, "content": output}) messages.append({"role": "user", "content": results}) # 问题 5:如果在 tool_use 期间触发安全上限,则使用兜底逻辑 result = extract_text(messages[-1]["content"]) if not result: # 最后一条消息是 tool_result,向前查找 assistant 文本 for msg in reversed(messages): if msg["role"] == "assistant": result = extract_text(msg["content"]) if result: break if not result: result = "子 Agent stopped 等待 30 turns without final answer." print(f"\033[35m[子 Agent 已完成]\033[0m") return result # 只保留摘要,完整消息历史会被丢弃 # 把 task 工具加入父 Agent 的工具列表 TOOLS.append({ "name": "task", "description": "启动一个子 Agent 处理复杂子任务。只返回最终结论。", "input_schema": {"type": "object", "properties": {"description": {"type": "string"}}, "required": ["description"]}, }) TOOL_HANDLERS["task"] = spawn_subagent # ═══════════════════════════════════════════════════════════ # 来自 s04 (未改动): Hook 系统 # ═══════════════════════════════════════════════════════════ HOOKS = {"UserPromptSubmit": [], "PreToolUse": [], "PostToolUse": [], "Stop": []} def register_hook(event: str, callback): HOOKS[event].append(callback) def trigger_hooks(event: str, *args): for callback in HOOKS[event]: result = callback(*args) if result is not None: return result return None DENY_LIST = ["rm -rf /", "sudo", "shutdown", "reboot", "mkfs", "dd if="] def permission_hook(block): """PreToolUse: deny list check.""" if block.name == "bash": for p in DENY_LIST: if p in block.input.get("command", ""): print(f"\n\033[31m⛔ 已拦截:'{p}'\033[0m") return "权限被拒绝" return None def log_hook(block): """PreToolUse:记录工具调用。""" print(f"\033[90m[HOOK] {block.name}\033[0m") return None def context_inject_hook(query: str): """UserPromptSubmit: log working directory.""" print(f"\033[90m[HOOK] UserPromptSubmit: 工作目录:{WORKDIR}\033[0m") return None def summary_hook(messages: list): """Stop:打印工具调用次数。""" tool_count = sum(1 for m in messages for b in (m.get("content") if isinstance(m.get("content"), list) else []) if isinstance(b, dict) and b.get("type") == "tool_result") print(f"\033[90m[HOOK] Stop:会话使用了 {tool_count} 次工具调用\033[0m") return None register_hook("UserPromptSubmit", context_inject_hook) register_hook("PreToolUse", permission_hook) register_hook("PreToolUse", log_hook) register_hook("Stop", summary_hook) # ═══════════════════════════════════════════════════════════ # agent_loop — 与以下相同: s05 + 催办提醒, task 会自动分发 # ═══════════════════════════════════════════════════════════ def agent_loop(messages: list): rounds_since_todo = 0 while True: # s05: 催办提醒 if rounds_since_todo >= 3 and messages: messages.append({"role": "user", "content": "请更新你的待办事项。"}) rounds_since_todo = 0 response = client.messages.create( model=MODEL, system=SYSTEM, messages=messages, tools=TOOLS, max_tokens=8000, ) messages.append({"role": "assistant", "content": response.content}) if response.stop_reason != "tool_use": force = trigger_hooks("Stop", messages) if force: messages.append({"role": "user", "content": force}) continue return rounds_since_todo += 1 results = [] for block in response.content: if block.type != "tool_use": continue blocked = trigger_hooks("PreToolUse", block) if blocked: results.append({"type": "tool_result", "tool_use_id": block.id, "content": str(blocked)}) continue handler = TOOL_HANDLERS.get(block.name) output = handler(**block.input) if handler else f"未知工具:{block.name}" trigger_hooks("PostToolUse", block, output) if block.name == "todo_write": rounds_since_todo = 0 results.append({"type": "tool_result", "tool_use_id": block.id, "content": output}) messages.append({"role": "user", "content": results}) if __name__ == "__main__": print("s06: 子 Agent — spawn sub-agents with 全新上下文, summary only") print("输入问题后按回车。输入 q 退出。\n") history = [] while True: try: query = input("\033[36ms06 >> \033[0m") except (EOFError, KeyboardInterrupt): break if query.strip().lower() in ("q", "exit", ""): break trigger_hooks("UserPromptSubmit", query) history.append({"role": "user", "content": query}) agent_loop(history) for block in history[-1]["content"]: if getattr(block, "type", None) == "text": print(block.text) print()