ToolInterceptor 链:before→decision→execute→after

ToolInterceptor 链:before→decision→execute→after 由 Archify 生成的时序图。 ① beforeToolCall(call, context) ② Decision:ALLOW 放行 / MODIFY 换 call / BLOCK 短路 / ROUTE_TO 改道 ③ BEFORE_TOOL_CALL 事件 ④ executeToolInvocation(同步或 Async start/await) AgentToolResult → normalizeToolResult ⑤ afterToolCall(call, output):BLOCK 可否决结果 ⑥ AFTER_TOOL_CALL(finally 必发) ReActRuntime · 工具调用编排 · 时序参与者 ReActRuntime 工具调用编排 Interceptor · before/after 决策 · 时序参与者 Interceptor before/after 决策 Lifecycle · 生命周期事件 · 时序参与者 Lifecycle 生命周期事件 ToolExecutor · 真实工具执行 · 时序参与者 ToolExecutor 真实工具执行 图例 默认消息

四种前置决策

  • • ALLOW 原样放行;MODIFY 用 decision.modifiedCall 替换后再执行(改写 name/args)
  • • BLOCK 不触达工具:合成 FAILED result 喂回模型;ROUTE_TO 带 SandboxSpec+SandboxCommand 改道沙箱执行

后置否决

  • • afterToolCall 拿到执行结果后仍可 BLOCK(如输出泄密)→ 结果替换为 blocked output 并标 FAILED
  • • 决策返回值 null 视为 ALLOW;interceptor 抛异常按工具失败处理

异常边界

  • • 工具执行异常 → FAILED result 继续喂模型,循环不中断
  • • HandoffPolicy / HostInput 等控制流异常直接上抛中断;AFTER_TOOL_CALL 在 finally 中必发