Smart Shikka Safe Tool Execution Plan Preview

dry_run preview_only execution_off adapter_off send_off write_off payment_off

What is Safe Tool Execution Plan?

This is the planning layer that runs before any future tool execution. Every tool action—send, write, payment, external API, research, screenshot, PDF—must first produce a dry-run execution plan. The plan defines what tool, what risk, what approval is needed, which adapter would run, what rollback is needed, what audit is needed, and why execution is currently blocked in preview mode.

Execution Plan Types

External Service Validation Planpreview_only
Email Confirmation Planpreview_only
Phone Confirmation Planpreview_only
Notification Send Planpreview_only
Messaging Send Planpreview_only
File Upload Planpreview_only
Screenshot Capture Planpreview_only
Pdf Generation Planpreview_only
Research Live Run Planpreview_only
Anshika Agent Tool Planpreview_only
Payment Or Customer Mutation Planpreview_only

Plan Lifecycle Timeline

1request received
2input redacted
3capability checked
4risk assessed
5approval required
6adapter selected preview
7preflight checked
8execution blocked in preview
9rollback plan prepared
10audit plan prepared
11dry run result returned

Risk Levels

Risk LevelApproval RequiredBlocked in Preview
safe_previewNoNo
low_read_onlyYesYes
medium_external_lookupYesYes
high_send_or_writeYesYes
critical_payment_or_customer_mutationYesYes

Preflight Check

Before any execution plan proceeds, preflight checks verify: required controls in place, approval receipts present, rate limits configured, audit trail ready, server-side keys available (for external API). All checks are preview-only.

Approval Gate

Medium, high, and critical actions require owner approval before execution. In preview mode, approval receipt is always missing and execution remains locked. No approval persistence in this version.

Adapter Selection Preview

Each tool action maps to a candidate adapter category (email adapter, phone adapter, messaging adapter, etc.). In preview mode, no adapter is selected for production and no adapter is executed.

Rollback Plan Preview

Write, payment, and customer mutation actions require a rollback strategy. In preview mode, rollback plans are prepared but never executed.

Audit Plan Preview

All non-read-only actions require audit trail entries. In preview mode, audit plans are prepared but no audit data is written.

Blocked Execution Preview

Actions that require external API, send, write, payment, Python execution, or customer mutation are blocked in preview mode. Future controls required: approval receipt, adapter allowlist, rate limit, audit store, rollback strategy.

Safety Guarantees

Future Unlock Plan

  1. Persistent approval receipt
  2. Role permission check
  3. Adapter allowlist
  4. Rate limit enforcement
  5. Audit store integration
  6. Rollback strategy activation
  7. Live execution bridge after approval

Approved actions go through the Tool Approval Workflow first. Execution plans choose future adapters through the Tool Adapter Registry. Live provider calls are routed through External Service Toolkit. Policy Decision API decides when execution plans are required.