Prompt profiles
Nearly every sentence Mework adds to a conversation on its own, from the environment block to tool descriptions, tool results and notices, is a key with built-in English text. A prompt profile is a JSON file that overrides the keys you name; every other key keeps the built-in wording.
What a profile changes
A profile can reword or remove:
- the environment block, and the skills, MCP servers and hooks sections of the system prompt;
- the descriptions of built-in tools and of MCP tools;
- what tools report back when they succeed, such as memory and handoff confirmations and background task status;
- the notices Mework delivers mid-conversation, such as plan-mode guidance and the handoff request;
- the texts around memory, project instructions, subagents, workflows and web search.
A profile changes only what the model reads. It does not change:
- the conversation's own system prompt card. Edit that on the timeline, or in a preset's conversation template;
- which tools exist, their parameters (apart from a few parameter descriptions that have keys), or what needs approval;
- tool error messages, which are fixed English;
- markers Mework reads back, such as
[Image #N]and<task-notification>, or the header line ofMEMORY.md; - the app's interface, including approval cards and dialogs, which stays in the app's language whichever profile you pick.
The built-in profile is Mework built-in. It is English, part of the app, updated with each version, and cannot be edited. Selecting no profile is the same as selecting it.
Where profile files live
Mework lists every .json file directly inside:
~/.mework/tool-descriptions/.mework/tool-descriptions/in every local workspace you have added, not only the conversation's
Sub-folders and symbolic links are ignored, and workspaces on SSH machines or in WSL are not scanned. Mework never creates, changes or deletes these files.
Choose a profile
- Open More options → Conversation settings → Advanced tools.
- Pick the profile in Tool descriptions. Mework built-in comes first, then your files.
The same row is in a preset's settings, and new conversations copy the preset's choice (see presets). The list refreshes when you open conversation settings, or when you press Rescan on its Skills, MCP or Hooks page.
| In the list | Meaning |
|---|---|
| {name} (unavailable) | The file is not valid JSON, or has no known key and no tool row with text. |
| {id} (no longer in the catalog) | The selected file was renamed, moved or deleted. The conversation runs with the built-in profile until you pick another. |
A selection is tied to where the file is. Changing name inside the file keeps it selected; renaming or moving the file, or its workspace folder, does not.
When changes apply
- The selected file is read again at the start of every run: edit it, save, and send your next message.
- New texts apply from the next run. Tool results and notices already in the conversation keep their old wording.
- Subagents and workflow steps use the profile the conversation had when they started.
- Switching profiles, or editing the selected file, mid-conversation changes the start of the request, so the next request cannot reuse the provider's prompt cache. After the conversation's first request, the Tool descriptions row is drawn orange like the other settings that cost the cache, and Mework asks once before switching.
File format
{
"name": "Terse",
"prompts": {
"task.wait_idle": "Nothing is running.",
"system.environment.date": "Date: {date}",
"project_memory.untrusted_banner": ""
},
"tools": [
{
"toolName": "grep",
"schemaNotes": "",
"usageGuidance": "Prefer grep to reading whole files."
}
]
}| Field | Type | What it does |
|---|---|---|
name |
string | The name shown in Tool descriptions, up to 120 characters. Default: the file name without .json. |
prompts |
object | Key to text. Each entry replaces that key's built-in text. Unknown keys and values that are not strings are ignored. |
tools |
array | Rows that override one tool each. |
tools[].toolName |
string, required | A built-in tool name such as grep, or an MCP tool's full name as the model sees it, starting with mcp__ (copy it from the tools row in More options → History). |
tools[].schemaNotes |
string | Replaces the tool's description. For a built-in tool this is the same text as its tool.<name>.description key, and it wins over a prompts entry for that key. For an MCP tool it replaces the server's description. Blank keeps the current text. |
tools[].usageGuidance |
string | Extra guidance the model reads beside the description. |
If one tool has several rows, the first row with any text wins.
- Fallback. For each key, Mework uses the selected file's text when the file has the key, and the built-in English text otherwise. A selected file that is missing or not valid JSON means the built-in profile.
- Empty strings.
""means "say nothing here". An emptysystem.environment_sectionremoves the whole environment block; an emptyproject_memory.untrusted_bannerdrops the banner from project instructions. - Keys that ship empty.
web.findings_notice,web.results_notice(anoticeon web search and fetch results) andweb.untrusted_marker(a prefix for retrieved lines that look like instructions) add nothing until you fill them in. - Placeholders. Words in braces, such as
{date}, are filled in when the text is used; the key reference lists each key's placeholders. You can leave one out. A placeholder the key does not declare stays in the text as written. - Lists. When Mework joins names into a list, it puts
format.list_separatorbetween them (,by default). - Size. The file must be UTF-8 JSON, at most 64 KiB.
Write your own
Start from the built-in profile, which has every key with its current text, and the key manifest, which lists each key's placeholders and where it appears:
prompt-profile.en-US.json— The built-in profileprompt-profile-keys.json— The key manifest
- Download
prompt-profile.en-US.jsonand save a copy as~/.mework/tool-descriptions/<name>.json, or in a workspace's.mework/tool-descriptions/. - Set
name, then delete every key you are not changing. Keys you leave out keep following Mework's updates; a key you keep stays at the text you wrote. - Edit the texts you kept, keeping the placeholders each one uses.
- Open More options → Conversation settings → Advanced tools and pick the file in Tool descriptions. If it is not listed, close conversation settings and open them again.
- Send a message, then open More options → History. The
systemrows show the system prompt Mework sent, and thetoolsrow shows the tool descriptions.
To have a model work in Chinese, or any other language, translate every key and keep the whole file: a key missing from the file falls back to English.
Key reference
Every key, grouped by its prefix, with the placeholders it accepts and where its text appears. Open a group to see its keys.
system.* 34
| Key | Placeholders | Where it appears |
|---|---|---|
system.environment_section | {facts} | Frame of the environment block at the head of the host system prompt: the heading and the sentence introducing the fact list. {facts} is the list, one - item per system.environment.* line. Emptying this key removes the whole block, facts included. |
system.environment.working_directory | {path} | Environment fact naming the directory this conversation's tools resolve relative paths against — its worktree when it has one, otherwise the workspace root. |
system.environment.worktree | — | Environment fact added when the conversation runs on an isolated worktree, telling the model to stay in it rather than reaching for the original checkout. |
system.environment.worktree_stash | — | Environment fact added alongside the worktree line: the stash stack is shared with every other checkout of the repository, so a bare git stash pop can take another session's work. |
system.environment.git_repository | {value} | Environment fact stating whether the working directory sits inside a Git checkout. {value} is true or false. |
system.environment.workspaces | — | Heading of the environment block's numbered workspace list. It appears only when the conversation has more than one workspace, because the number is how a tool call names which one it acts in; each workspace follows as its own nested item. |
system.environment.workspace_entry | {number} {path} {location} | One item of the numbered workspace list. {number} is the value a tool's workspace parameter takes, {path} is the root on that machine, and {location} is the rendered machine phrase from the system.environment.workspace_on_* keys. |
system.environment.workspace_on_host | — | Machine phrase for a workspace on the machine Mework itself runs on. It is what {location} becomes for a local workspace. |
system.environment.workspace_on_wsl | {name} | Machine phrase for a workspace inside a WSL distribution. {name} is the distribution name. |
system.environment.workspace_on_ssh | {name} | Machine phrase for a workspace on a registered SSH machine. {name} is the machine's name in the catalog. |
system.environment.platform | {platform} | Environment fact naming the host operating system, as Rust's std::env::consts::OS spells it (windows, macos, linux). |
system.environment.os_version | {version} | Environment fact naming the host operating-system version. The line is omitted when the version could not be read. |
system.environment.date | {date} | Environment fact naming today's date on the host, as YYYY-MM-DD. |
system.mcp_section | {servers} | Section appended to the system prompt listing the MCP servers selected for the conversation; {servers} is one system.capability_row per server. |
system.mcp_server_default_description | — | Description used for an MCP server whose configuration has no description. |
system.mcp_server_place | {machine} {workspaces} | Appended to an MCP server's row in system.mcp_section when the conversation's workspaces are not all one folder on this computer: the machine the server runs on and the workspaces there. {machine} is a system.environment.workspace_on_* phrase and {workspaces} the joined workspace numbers. |
system.mcp_server_place_none | {machine} | Appended to an MCP server's row like system.mcp_server_place when none of the conversation's workspaces is on the machine the server runs on. |
system.hooks_section | {hook_names} {hooks} | Section appended to the system prompt listing the lifecycle hooks selected for the conversation; {hook_names} is the joined name list and {hooks} one system.capability_row per hook. |
system.skill_folder | {directory} | Line after a skill's body in the system prompt (and in system.skill_added_body) when skills are delivered in the prompt, saying where the skill's files are. {directory} is the folder, or system.skill_workspace_directory / system.skill_local_directory when the conversation's workspaces are not all one folder on this computer. |
system.skill_workspace_directory | {path} {workspace} | The folder of a skill a workspace declared, as system.skill_folder and the skill tool's result give it when the conversation has more than one workspace or its one workspace is on another machine. {path} is the folder on that workspace's machine and {workspace} its number. |
system.skill_local_directory | {path} | The folder of a global skill (~/.mework/skills) in the same situation as system.skill_workspace_directory: it is on this computer, whichever machines the workspaces are on. {path} is the folder. |
system.skill_added_body | {name} {body} | <result> of the host notice delivering a skill selected after the conversation started, when skill bodies go into the prompt rather than behind the skill tool. |
system.skill_added_trigger | {name} {trigger} | <result> of the host notice announcing a skill selected after the conversation started, when skills are loaded on demand; the body stays behind the skill tool. |
system.capability_row | {name} {description} | One row of the MCP-server or hook list in the system prompt. |
system.hook_matcher_detail | {matcher} | Suffix added to a hook's description when the hook has a matcher. |
system.hook_event.session_start | — | Description of a SessionStart hook. |
system.hook_event.instructions_loaded | — | Description of an InstructionsLoaded hook. |
system.hook_event.user_prompt_submit | — | Description of a UserPromptSubmit hook. |
system.hook_event.pre_tool_use | — | Description of a PreToolUse hook. |
system.hook_event.permission_request | — | Description of a PermissionRequest hook. |
system.hook_event.post_tool_use | — | Description of a PostToolUse hook. |
system.hook_event.stop | — | Description of a Stop hook. |
system.plan_mode | — | System prompt appended at the point the user turns plan mode on, every time they do: what plan mode forbids, how the plan document works, and the workflow that ends in exit_plan_mode. It travels as a mid-conversation system message where the model and endpoint take one, and as the <result> of a box host notice (host_notice.plan_mode_summary) where they do not. Child agents never receive it. |
system.plan_mode_exit | — | System prompt appended at the point the user turns plan mode off before approving a plan, carried like system.plan_mode (in box under host_notice.plan_mode_exit_summary). An approved plan needs no such note: the exit_plan_mode result says so. |
tool.* 85
| Key | Placeholders | Where it appears |
|---|---|---|
tool.ls.description | — | Root description of the ls schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for ls overrides this key. |
tool.grep.description | — | Root description of the grep schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for grep overrides this key. |
tool.find.description | — | Root description of the find schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for find overrides this key. |
tool.read.description | — | Root description of the read schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for read overrides this key. |
tool.lsp.description | — | Root description of the lsp schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for lsp overrides this key. |
tool.write.description | — | Root description of the write schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for write overrides this key. |
tool.edit.description | — | Root description of the edit schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for edit overrides this key. |
tool.edit.read_first | — | Sentence appended to the edit description while the read-before-write guard is on: the file must have been read in this conversation first. |
tool.write.read_first | — | Sentence appended to the write description while the read-before-write guard is on: an existing file must have been read in this conversation first. |
tool.powershell.description | — | Root description of the powershell schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for powershell overrides this key. |
tool.bash.description | — | Root description of the bash schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for bash overrides this key. |
tool.zsh.description | — | Root description of the zsh schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for zsh overrides this key. |
tool.sh.description | — | Root description of the sh schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for sh overrides this key. |
tool.web_search.description | — | Root description of the web_search schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for web_search overrides this key. |
tool.web_fetch.description | — | Root description of the web_fetch schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for web_fetch overrides this key. |
tool.preview_start.description | — | Root description of the preview_start schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for preview_start overrides this key. |
tool.preview_stop.description | — | Root description of the preview_stop schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for preview_stop overrides this key. |
tool.preview_list.description | — | Root description of the preview_list schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for preview_list overrides this key. |
tool.preview_logs.description | — | Root description of the preview_logs schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for preview_logs overrides this key. |
tool.preview_console_logs.description | — | Root description of the preview_console_logs schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for preview_console_logs overrides this key. |
tool.preview_screenshot.description | — | Root description of the preview_screenshot schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for preview_screenshot overrides this key. |
tool.preview_snapshot.description | — | Root description of the preview_snapshot schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for preview_snapshot overrides this key. |
tool.preview_inspect.description | — | Root description of the preview_inspect schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for preview_inspect overrides this key. |
tool.preview_click.description | — | Root description of the preview_click schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for preview_click overrides this key. |
tool.preview_fill.description | — | Root description of the preview_fill schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for preview_fill overrides this key. |
tool.preview_eval.description | — | Root description of the preview_eval schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for preview_eval overrides this key. |
tool.preview_network.description | — | Root description of the preview_network schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for preview_network overrides this key. |
tool.preview_resize.description | — | Root description of the preview_resize schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for preview_resize overrides this key. |
tool.preview_upload_image.description | — | Root description of the preview_upload_image schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for preview_upload_image overrides this key. |
tool.preview_dialog.description | — | Root description of the preview_dialog schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for preview_dialog overrides this key. |
tool.agent_spawn.description | — | Root description of the agent_spawn schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for agent_spawn overrides this key. |
tool.task_wait.description | — | Root description of the task_wait schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for task_wait overrides this key. |
tool.task_list.description | — | Root description of the task_list schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for task_list overrides this key. |
tool.box.description | — | Root description of the box schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for box overrides this key. |
tool.read_global_memory.description | — | Root description of the read_global_memory schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for read_global_memory overrides this key. |
tool.read_project_memory.description | — | Root description of the read_project_memory schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for read_project_memory overrides this key. |
tool.create_global_memory.description | — | Root description of the create_global_memory schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for create_global_memory overrides this key. |
tool.create_project_memory.description | — | Root description of the create_project_memory schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for create_project_memory overrides this key. |
tool.edit_global_memory.description | — | Root description of the edit_global_memory schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for edit_global_memory overrides this key. |
tool.edit_project_memory.description | — | Root description of the edit_project_memory schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for edit_project_memory overrides this key. |
tool.ask_user.description | — | Root description of the ask_user schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for ask_user overrides this key. |
tool.fork.description | — | Root description of the fork schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for fork overrides this key. |
tool.workflow.description | — | Root description of the workflow schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for workflow overrides this key. |
tool.plan.description | — | Root description of the plan schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for plan overrides this key. |
tool.exit_plan_mode.description | — | Root description of the exit_plan_mode schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for exit_plan_mode overrides this key. |
tool.read_handoff_note.description | — | Root description of the read_handoff_note schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for read_handoff_note overrides this key. |
tool.create_handoff_note.description | — | Root description of the create_handoff_note schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for create_handoff_note overrides this key. |
tool.edit_handoff_note.description | — | Root description of the edit_handoff_note schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for edit_handoff_note overrides this key. |
tool.handoff.description | — | Root description of the handoff schema — what the model reads to decide what the tool is. A profile's tools[].schemaNotes for handoff overrides this key. |
tool.ls_limit | {limit} {depth} | Line of an ls result the character budget cut, naming the depth down to which the listing is complete. |
tool.ls_limit_partial | {limit} | Line of an ls result the character budget cut partway through the first level. |
tool.ls_ignored_note | — | Line of an ls result that listed ignored directories without expanding them. |
tool.ls_empty | — | ls result for an empty directory. |
tool.ignored_entry | {path} | An ignored entry in an ls or find result: a directory ls did not expand, a match find listed last. |
tool.grep_skipped | {error} | Line in a grep or ls result for an entry that could not be read. |
tool.grep_limit | {from} {to} {next} | Last line of a grep page when more matches follow, with the offset of the next page. |
tool.grep_no_match | — | grep result when nothing matched. |
tool.grep_no_match_at_offset | {offset} {count} | grep result when the requested offset is past the last match. |
tool.find_limit | {shown} {total} | Line of a find result that returned only some of its matches. |
tool.find_ignored_note | {count} | Line of a find result some of whose matches are in ignored paths, listed last. |
tool.find_scan_limit | {limit} | Line of a find result that stopped examining entries, so its total is a floor. |
tool.find_no_match | — | find result when nothing matched. |
tool.read_image | {path} {mime} {width} {height} {bytes} | read result for an image file (the image itself is attached). |
tool.read_range_out_of_bounds | — | read result when the requested line range is past the end of the file. |
tool.read_limit | {from} {to} {total} {next} | Last line of a read result that stopped before the end of the file or of the requested range. |
tool.read_line_too_long | {line} {size} | read error when a single line is longer than one read can return. |
tool.write_done | {bytes} {path} | write result. The default is a bare acknowledgement; the values stay available to a profile that wants to name the file. |
tool.edit_done | {path} | edit result. The default is a bare acknowledgement; the value stays available to a profile that wants to name the file. |
tool.file_state_current | — | Suffix on a write/edit result while the read-before-write or stale-write guard is on: the model need not read the file back. |
tool.edit_stale_recovered | — | Suffix on an edit result that applied to a file changed on disk since the model read it, because the find text still matched once. |
tool.file_changed_notice | {path} {snippet} | Round-start notice that a file the model read changed on disk, with the changed regions rendered with line numbers. |
tool.file_changed_omitted | {path} | The same notice when earlier files in the round already used up the snippet budget. |
tool.hook_file_resynced | {path} | Notice that a PostToolUse hook rewrote the file write/edit just wrote and the host re-read it. |
tool.shell_stale_read_hint | {count} {files} | Suffix on a shell result after a formatter-looking command changed files the model had read. |
tool.shell_stale_read_more | {count} | Tail of the file list in the shell stale-read hint once more than five files changed. |
tool.shell_cwd_outside_workspace | {directory} {workspace} {root} | Suffix on a successful shell result whose command ended outside its workspace, so the next command there starts at the workspace root. |
tool.shell_output_omitted | {size} | Line standing in for the middle of a command's output, past what is kept of its start and end. |
tool.shell_user_aborted | — | Shell result when the user aborted the command. |
tool.shell_exit_unknown | — | Stands in for the exit code when the process reported none. |
tool.shell_completed | {code} | Status line of a finished shell command that printed nothing. |
tool.shell_exit_code | {code} | Leading line of a failed shell result, before its stderr and stdout. |
tool.shell_timed_out | {seconds} | Shell result when the deadline expired and the running command could not be moved to the background (its run was going away), so it was stopped. |
tool.output_truncated | — | Suffix when a tool result was cut to the output limit. |
tool.output_spilled | {size} {path} {preview_size} {preview} | What a shell or grep result too long to return whole becomes: where the full output was saved, and its start. |
tool.diff_truncated | — | Suffix when a write/edit diff was cut to the limit. |
subagent.* 20
| Key | Placeholders | Where it appears |
|---|---|---|
subagent.addendum | — | Addendum appended (after a --- separator) to the system prompt of every spawned subagent and workflow step. |
subagent.update_tool_description | — | Schema description of the child-only subagent_update tool. |
subagent.update_message_description | — | Schema description of subagent_update.message. |
subagent.update_ack | — | Tool result a child receives after a successful subagent_update call. |
subagent.structured_output_root_seed | — | Root description of the child-only structured_output tool when the spawning schema has none. |
subagent.structured_output_lifecycle | — | Sentence appended to every structured_output schema description. |
subagent.structured_output_nudge | — | User context injected once when a schema-bound child ends a round without calling structured_output. |
subagent.structured_output_settled | — | Tool result of a valid structured_output call. |
subagent.structured_output_rejected | {error} {attempt} {max_attempts} | Tool result of a structured_output call that failed schema validation. |
subagent.structured_output_exhausted | {max_attempts} | Final assistant text of a child whose structured_output calls failed validation too many times. |
subagent.missing_structured_output | — | Notice prepended to a schema-bound child's final text when it never called structured_output. |
subagent.failed | {reason} | Result envelope body (or suffix) when a child's model request failed. |
subagent.failed_unknown_reason | — | Reason used in subagent.failed when the host has none. |
subagent.no_text_result | — | Result envelope body when a child finished without any text. |
subagent.result_truncated | — | Suffix appended when a child's final text was cut to the output limit. |
subagent.forced_stop | {name} | Result envelope body when the host force-stopped a child that ignored a stop request. |
subagent.worker_panic | — | Result envelope body when a task worker crashed. |
subagent.structured_result_block | {body} | Fenced block appended to a result envelope that carries a structured result. |
subagent.structured_unserializable | — | Body of subagent.structured_result_block when the value cannot be serialized. |
subagent.structured_truncated | — | Suffix inside subagent.structured_result_block when the value was cut to the inline limit. |
skill.* 5
| Key | Placeholders | Where it appears |
|---|---|---|
skill.tool_description | — | Schema description of the on-demand skill tool. |
skill.name_description | — | Schema description of skill.name. |
skill.listing_heading | — | Heading of the skill trigger list in the system prompt. |
skill.listing_row | {name} {trigger} | One row of the skill trigger list. |
skill.result | {directory} {body} | Tool result of a successful skill call. |
tool_search.* 8
| Key | Placeholders | Where it appears |
|---|---|---|
tool_search.tool_description | — | Schema description of the tool_search tool, exposed whenever a run is holding MCP tool schemas back. It has to teach the whole mechanism: that the announced names have no parameter schema until they are fetched, that the result is a <functions> block in the same encoding as the tool list at the top of the prompt, and the three query forms. |
tool_search.query_description | — | Schema description of tool_search.query. |
tool_search.max_results_description | — | Schema description of tool_search.max_results. |
tool_search.announcement | {tools} | Context injected at the head of every step of a run that withheld MCP tool schemas; {tools} is one tool_search.announcement_row per withheld tool. Announcing the names is what makes them findable — the model cannot search for a capability it has never heard of. |
tool_search.announcement_row | {server} {names} | One row of the withheld-tool announcement: every tool one server declared. Grouping by server is what makes a keyword query like +slack reach them. |
tool_search.result | {functions} | Tool result of a tool_search call that matched something; {functions} is the <functions> block carrying one <function> line per matched tool. |
tool_search.no_match | {query} {total} | Tool result of a tool_search call that matched nothing. |
tool_search.not_loaded | {name} | Rejection returned when the model calls an MCP tool whose schema this run has not handed out yet. Repairable on purpose: it names the call that fixes it. |
role.* 2
| Key | Placeholders | Where it appears |
|---|---|---|
role.listing_heading | — | Heading of the agent-role list appended to the agent_spawn / workflow tool description. |
role.listing_row | {name} {description} | One row of the agent-role list. |
task.* 58
| Key | Placeholders | Where it appears |
|---|---|---|
task.wait_timeout_all_pending | {seconds} {pending} {max_seconds} | Leading notice of a task_wait result that timed out before any named task settled. |
task.wait_timeout_partial | {seconds} {delivered} {pending} {max_seconds} | Leading notice of a task_wait result that timed out with some results delivered. |
task.wait_pending_fallback | — | Stands in for {pending} when the wait named no specific task. |
task.wait_idle | — | task_wait result when nothing is running and nothing is waiting to be collected. |
task.progress_update_label | — | Status word of a progress-update envelope: [agent · progress update]. |
task.no_text_result | — | Body of a result envelope whose task returned no text. |
task.cost_line | {tokens} {tool_uses} {duration_ms} | Footer line of a result envelope in a task_wait result. |
task.cost_unknown_tokens | — | Stands in for {tokens} when the provider reported no usage. |
task.wait_status_heading | — | Heading of the status roll-up that ends a task_wait result. The renderer recognizes the built-in English heading, and the Chinese one in transcripts older builds wrote. |
task.status.completed | — | Status word of a completed task. |
task.status.interrupted | — | Status word of an interrupted task. |
task.status.failed | — | Status word of a failed task. |
task.status.stopped | — | Status word of a task stopped by the user. |
task.status.round_limit | — | Status word of a task that hit its round limit. |
task.status.running | — | Status word of a running task. |
task.status.idle | — | Status word of a subagent that finished its turn and is waiting. |
task.list_empty | — | task_list result when the conversation has no tasks. |
task.list_total | {total} | First line of a non-empty task_list result. |
task.list_row_label | {label} | Suffix of a task_list row (and a task_wait observation) carrying the task's label. |
task.list_latest_update | {update} | Line under a task_list row showing the task's latest progress update. |
task.list_result_in_timeline | — | Suffix of a task_list status for a finished task whose result is in the timeline. |
task.group.subagents | — | task_list group title for subagents. |
task.group.workflows | — | task_list group title for workflow runs. |
task.group.terminals | — | task_list group title for terminals. |
task.group.shell_commands | — | task_list group title for background shell commands. |
task.group.preview_servers | — | task_list group title for dev servers. |
task.preview.starting | — | Status of a dev server that is still coming up. |
task.preview.running | — | Status of a dev server that is answering. |
task.preview.stopped | — | Status of a dev server that is no longer registered. |
task.terminal.running | — | Status of a terminal with a running command. |
task.terminal.idle | — | Status of an idle terminal. |
task.terminal.exited | — | Status of a terminal whose shell exited. |
task.terminal.closed | — | Status of a closed terminal. |
task.shell.completed | {code} | Status of a background command that exited successfully. |
task.shell.failed | {code} | Status of a background command that exited with an error. |
task.shell.aborted | — | Status of a background command that was aborted. |
task.shell.aborting | — | Status of a background command that is being aborted. |
task.shell.running | — | Status of a running background command. |
task.shell.finished | — | Status of a background command that finished without an exit code. |
task.shell_result | {shell_ref} {tool_name} {exit} {body} | Result envelope body of a finished background shell command. |
task.shell_exit_code | {code} | Stands in for {exit} when the exit code is known. |
task.shell_exit_unknown | — | Stands in for {exit} when the exit code is unknown. |
task.shell_no_output | — | Stands in for {body} when the command produced no output. |
task.shell_stopped_by_user | {shell_ref} {tool_name} {body} | Result envelope body of a background command the user stopped, carrying whatever it printed first. |
task.shell_failed_to_run | {shell_ref} {error} | Result envelope body of a background command that failed to execute. |
task.shell_timeout_backgrounded | {shell_ref} {seconds} | Receipt of a foreground command that ran out of time and was adopted by a task slot instead of being stopped. |
task.output_truncated | — | Suffix appended when a task result was cut to the output limit. |
task.stopped_by_user | — | Sentence appended to a task's result when the user closed that task from the sidebar. |
task.box_no_op | — | Tool result of a box call the model made itself; the tool is a host carrier and does nothing when called. |
task.notification.completed | {task} | <summary> of a completed-task notification. |
task.notification.failed | {task} | <summary> of a failed-task notification. |
task.notification.round_limit | {task} | <summary> of a round-limit notification. |
task.notification.interrupted | {task} | <summary> of an interrupted-task notification. |
task.notification.stopped | {task} | <summary> of a stopped-task notification. |
task.restart_summary | {task} | <summary> of the notification delivered when an application exit lost a subagent before its result reached the model. |
task.restart_notice | {task} {last_output} | Body of the notification delivered when an application exit lost a subagent before its result reached the model. {last_output} is task.restart_last_output or task.restart_no_output. |
task.restart_last_output | {text} | Stands in for {last_output} with the last text the lost subagent wrote. |
task.restart_no_output | — | Stands in for {last_output} when the lost subagent had written no text. |
fork.* 1
| Key | Placeholders | Where it appears |
|---|---|---|
fork.request_submitted | — | Tool result of fork when the request was raised for the user to decide. |
handoff.* 7
| Key | Placeholders | Where it appears |
|---|---|---|
handoff.armed_notice | — | The instruction to write handoff notes and call handoff, given at the round boundary where the context crosses the auto-compact threshold: a mid-conversation system message where the model and endpoint take one, otherwise the <result> of a box host notice with no <summary>. Either way it is all the model is told. |
handoff.index_context | {notes} | The handoff notes a continuation inherited. On a model that reads its tools ahead of its system prompt it is a system card, the system prompt's last section; on any other it is handed over once at the first round boundary, right behind the opening message — as a mid-conversation system message where the model and endpoint take one, otherwise as the <result> of a box host notice (handoff.index_summary). {notes} is one - name — description line per note. |
handoff.index_summary | — | <summary> of the box host notice that hands a continuation its notebook index where the model or endpoint takes no system message mid-conversation; its <result> is handoff.index_context. |
handoff.start_message | — | The host's first user message in a continuation: what its first run is asked to do. |
handoff.note_created | {name} | Tool result of a successful create_handoff_note call. |
handoff.note_updated | {name} | Tool result of a successful edit_handoff_note call. |
handoff.completed | {title} | Tool result of a successful handoff call. {title} is the continuation's title. |
host_notice.* 15
| Key | Placeholders | Where it appears |
|---|---|---|
host_notice.output_truncated_summary | — | <summary> of the host notice sent when a response was cut off at the output limit. |
host_notice.output_truncated | — | <result> of the same notice: the instruction to continue. |
host_notice.structured_output_summary | — | <summary> of the host notice a schema-bound run gets when a round ends without structured_output; its <result> is subagent.structured_output_nudge. |
host_notice.hook_context_summary | {name} {event} | <summary> of the host notice carrying a hook's additionalContext, which is its <result>. {name} is the hook's name and {event} its lifecycle event. |
host_notice.skill_added_summary | {name} | <summary> of the host notice delivering a skill selected after the conversation started; its <result> is system.skill_added_body or system.skill_added_trigger. |
host_notice.diagnostics_summary | — | <summary> of the host notice carrying the problems language servers published since the last round. |
host_notice.file_changes_summary | — | <summary> of the host notice listing files the model read that changed on disk since. |
host_notice.mcp_unavailable_summary | {servers} | <summary> of the host notice sent when selected MCP servers could not be used at the start of a turn. {servers} lists their names. |
host_notice.mcp_unavailable | {servers} | <result> of the same notice. {servers} is one system.capability_row per server, its description being why it could not be used. |
host_notice.instruction_skips_summary | — | <summary> of the host notice listing instruction files (MEWORK.md, rules, imports) a run left out. Its <result> has one line per file, - <file>: <reason>, the reason being one of the instruction_skip.* texts. |
host_notice.preview_start_failed_summary | {name} | <summary> of the host notice sent when a dev server the user started from the preview pane failed to start. {name} is the server's name in .mework/launch.json. |
host_notice.preview_start_failed | {name} {error} | <result> of the same notice. {name} is the server's name and {error} the error the start gave, which is what the pane showed the user. |
host_notice.plan_mode_summary | — | <summary> of the box host notice that carries system.plan_mode where the model or endpoint takes no system message mid-conversation. |
host_notice.plan_mode_exit_summary | — | <summary> of the box host notice that carries system.plan_mode_exit the same way. |
host_notice.system_prompt_summary | — | <summary> of the box exchange carrying a system prompt that applies from its place in the conversation — one the user wrote below the top of the timeline, or one appended under another model — to a model that takes no system message mid-conversation; its <result> is the prompt's text. |
instruction_skip.* 8
| Key | Placeholders | Where it appears |
|---|---|---|
instruction_skip.too_large | — | Reason in that list: the file is larger than one instruction file may be. |
instruction_skip.over_total_size | — | Reason: the file would take the run past the size all instruction files together may take. |
instruction_skip.over_file_count | — | A line of its own, naming no file: the run already reads as many instruction files as it may. |
instruction_skip.not_utf8 | — | Reason: the file is not valid UTF-8 text. |
instruction_skip.secret | — | Reason: the file looks like it contains a credential or other secret. |
instruction_skip.import_missing | — | Reason: an import of a file that does not exist or is not a file. |
instruction_skip.import_unsupported | — | Reason: an import Mework does not follow: a URL or ~ path, a cycle, or one nested too deep. |
instruction_skip.unreadable | — | Reason: the file could not be read. |
web.* 10
| Key | Placeholders | Where it appears |
|---|---|---|
web.executor_system_prompt | {budget_line} | System prompt of the isolated executor that runs a provider-native web_search. |
web.executor_budget_unlimited | — | {budget_line} when the conversation sets no search cap. |
web.executor_budget_limited | {max_searches} | {budget_line} when the conversation caps searches per call. |
web.executor_task | {query} | User message given to the isolated web-search executor. |
web.fetch_executor_system_prompt | — | System prompt of the isolated executor that runs a provider-native web_fetch. Its prose is discarded: the host reads the retrieved pages out of the tool results, so this only has to make the executor call the tool once per URL. |
web.fetch_executor_task | {urls} | User message given to the isolated web-fetch executor, carrying the URLs to retrieve one per line. |
web.search_warnings | {warnings} | Line appended to native findings when the provider reported search failures. |
web.findings_notice | — | notice field of the JSON result of a native web_search. Empty by default, and then the field is omitted entirely; fill it in to label the findings as untrusted. |
web.results_notice | — | notice field of the JSON result of a catalog-provider web_search or a web_fetch. Empty by default, and then the field is omitted entirely; fill it in to label the results as untrusted. |
web.untrusted_marker | — | Prefix put in front of a retrieved line that looks like an instruction. Empty by default, so such a line is passed through unmarked; the control characters a line could hide behind are stripped either way. |
memory.* 7
| Key | Placeholders | Where it appears |
|---|---|---|
memory.context_intro | — | First line inside the <mework-memory> block that carries each enabled tier's MEMORY.md. |
memory.tier.global | — | Name of the global memory tier. |
memory.tier.project | — | Name of the project memory tier. |
memory.tier.project_of_workspace | {workspace} {path} | Name of one workspace's project memory when the conversation has more than one workspace, each with its own; it heads that workspace's index in the memory block. {workspace} is the number and {path} the folder. |
memory.index_heading | {tier} | Heading above a tier's MEMORY.md inside the memory block. |
memory.created | {tier} {name} | Tool result of a successful create_*_memory call. |
memory.updated | {tier} {name} | Tool result of a successful edit_*_memory call. |
project_memory.* 1
| Key | Placeholders | Where it appears |
|---|---|---|
project_memory.untrusted_banner | — | Banner inside the project-instructions block (MEWORK.md / AGENTS.md style files found in the workspace). |
hook.* 8
| Key | Placeholders | Where it appears |
|---|---|---|
hook.session_start_blocked | {reason} | Assistant text written when a SessionStart hook blocked the turn. |
hook.user_prompt_blocked | {reason} | Assistant text written when a UserPromptSubmit hook blocked the turn. |
hook.blocked_by | {name} | Reason given to the model when a hook denied a tool call without a reason of its own. |
hook.continue_fallback | — | User context injected when a Stop hook asks to continue without giving a reason. |
hook.stop_limit_reached | {limit} | Assistant text written when a Stop hook asked to continue too many times in a row. |
hook.stop_skipped_definition_revoked | {error} | Assistant text written when the Stop hook was skipped because the named agent's definition was revoked. |
hook.post_tool_not_rolled_back | {reason} {tool} | Tool result substituted when a PostToolUse hook rejects a call whose effects cannot be rolled back. |
hook.interrupted_call_skipped | — | Tool result of a call that was not executed because a hook interrupted the turn. |
mcp.* 1
| Key | Placeholders | Where it appears |
|---|---|---|
mcp.mandatory_description_prefix | — | Prefix of the tool description of an MCP tool that requires user interaction on every call. |
run.* 1
| Key | Placeholders | Where it appears |
|---|---|---|
run.no_text_reply | — | Assistant text written when the model ended a turn without any text. |
workflow.* 17
| Key | Placeholders | Where it appears |
|---|---|---|
workflow.not_recoverable | — | Line appended to a workflow receipt when its run directory could not be created. |
workflow.aborted_cancelled | — | Result of a workflow run that was cancelled or whose turn ended. |
workflow.aborted_channel | {detail} | Result of a workflow run aborted by a host event-channel failure. |
workflow.resume_hint | {run_id} | Line appended to a failed workflow result explaining how to resume it. |
workflow.resume_degraded | {run_id} | Resume hint used when journal writes failed, so a resume replays nothing. |
workflow.resume_repeated_warning | {count} | Line appended to a resume hint when steps kept starting without ever finishing. |
workflow.timeout | {seconds} {unfinished} | Result of a workflow run that exceeded the run deadline. |
workflow.losers_cancelled | {count} {steps} | Progress note written when the script returned while steps were still running. |
workflow.step_no_structured | — | Error of a workflow step that finished without returning its required structured result. |
workflow.step_ended_with | {status} | Error of a workflow step that ended in a non-completed status. |
workflow.step_preview_truncated | — | Suffix of a step output preview in the workflow timeline context. |
workflow.step_no_result | — | Error of a workflow step that produced no result. |
workflow.step_not_started | — | Error of a workflow step that had not started when the run was aborted. |
workflow.restart_summary | {task} | <summary> of the notification delivered when a workflow run was interrupted by an application restart. |
workflow.restart_notice | {task} {script} {reusable_steps} {run_id} {reason} | Body of the notification delivered when a workflow run was interrupted by an application restart and the host could not resume it. |
workflow.restart_resumed_summary | {task} | <summary> of the notification delivered when the host resumed a workflow run an application restart interrupted. |
workflow.restart_resumed | {task} {script} {reusable_steps} | Body of the notification delivered when the host resumed a workflow run an application restart interrupted. |
format.* 1
| Key | Placeholders | Where it appears |
|---|---|---|
format.list_separator | — | Separator used when the host joins names into a list (hook names, task addresses, status roll-ups). |