Added
- describe_image tool (VisionConfig, make_vision_tool) with a pluggable VisionProvider and two reference providers, GeminiVisionProvider and AnthropicVisionProvider. Bring-your-own-key: api_key and model both required, no env-var fallback, no default provider or model. Reads images only from the existing file-ops sandbox (same path-escape and symlink protection). URLs deliberately not accepted (SSRF risk). Image type detected from the file's bytes; size capped at 5,000,000 bytes and prompt at 2,000 characters by default. Standard library only, so there are still zero required dependencies.
Verified
- 133 tests passing locally (was 100); ragleap-tools-tests green in CI on PRs #567 and #568. Provider tests mock urllib.request.urlopen and assert on each provider's real URL, headers and body.
- Live-checked on 2026-10-03 against the real Gemini API (model gemini-3.6-flash): one describe_image call on a generated 64x64 PNG returned the expected answer.
Not verified
- AnthropicVisionProvider has not been called against a live account.
- Gemini JPEG/WebP input, large images and error responses were not live-checked.
- Tavily/Serper (v0.2.0) and authenticated GitHub requests remain unverified.
Correction
- The GitHubSearchConfig docstring in the published 0.3.0 wheel says unauthenticated search is limited to 60 requests/hour. A live check showed the search resource at 10 (core at 60). Fixed in this release; code behavior was never affected.
The descriptions are untrusted text derived from images (prompt-injection surface, not screened).