RagLeap
ragleap-tools · release notes

ragleap-tools v0.4.0

Added

  • describe_image tool (VisionConfig, make_vision_tool) with a pluggable VisionProvider and two reference providers, GeminiVisionProvider and AnthropicVisionProvider. Bring-your-own-key: api_key and model both required, no env-var fallback, no default provider or model. Reads images only from the existing file-ops sandbox (same path-escape and symlink protection). URLs deliberately not accepted (SSRF risk). Image type detected from the file's bytes; size capped at 5,000,000 bytes and prompt at 2,000 characters by default. Standard library only, so there are still zero required dependencies.

Verified

  • 133 tests passing locally (was 100); ragleap-tools-tests green in CI on PRs #567 and #568. Provider tests mock urllib.request.urlopen and assert on each provider's real URL, headers and body.
  • Live-checked on 2026-10-03 against the real Gemini API (model gemini-3.6-flash): one describe_image call on a generated 64x64 PNG returned the expected answer.

Not verified

  • AnthropicVisionProvider has not been called against a live account.
  • Gemini JPEG/WebP input, large images and error responses were not live-checked.
  • Tavily/Serper (v0.2.0) and authenticated GitHub requests remain unverified.

Correction

  • The GitHubSearchConfig docstring in the published 0.3.0 wheel says unauthenticated search is limited to 60 requests/hour. A live check showed the search resource at 10 (core at 60). Fixed in this release; code behavior was never affected.

The descriptions are untrusted text derived from images (prompt-injection surface, not screened).

View on GitHub Package page All releases
← v0.3.0

Release notes mirrored from GitHub Releases.