# smolagents - Doramagic AI Context Pack

> Purpose: pre-work context for the user's host AI. This pack does not prove that the project has been installed, run, or validated.

## Project

- canonical_name: `huggingface/smolagents`
- capability: 🤗 smolagents: a barebones library for agents that think in code.
- expected_user_outcome: 🤗 smolagents: a barebones library for agents that think in code.

## Operating Boundaries

- Do not claim that the project has been installed, run, called through an API, or used on local files unless separate evidence proves it.
- Project facts must come from repo evidence, Claim Graph, or explicit source references.
- When a capability is not verified, mark it as unverified instead of completing it as fact.
- publish_status: `publishable`
- blocking_gaps: none

---

## Doramagic Context Augmentation

The following sections strengthen the repository context for a host AI. Human Manual data is a reading route, and pitfall notes become operating constraints.

## Human Manual Outline

Usage rule: this is only a reading route and salience signal, not factual authority. Concrete claims must still return to repo evidence or Claim Graph.

Host AI hard rules:
- Do not treat page titles, section order, summaries, or importance values as factual project evidence.
- When explaining the Human Manual outline, state that it is only a reading route or salience signal.
- Capability, installation, compatibility, runtime state, and risk claims must cite repo evidence, source paths, or Claim Graph.

- **Core Agent System and ReAct Loop**: importance `high`
  - source_paths: src/smolagents/agents.py, src/smolagents/__init__.py, src/smolagents/prompts/code_agent.yaml, src/smolagents/prompts/structured_code_agent.yaml, src/smolagents/prompts/toolcalling_agent.yaml
- **Memory and State Management**: importance `high`
  - source_paths: src/smolagents/memory.py, src/smolagents/agents.py, docs/source/en/tutorials/memory.md, examples/plan_customization/plan_customization.py
- **Tools, Models, and Execution Backends**: importance `high`
  - source_paths: src/smolagents/models.py, src/smolagents/tools.py, src/smolagents/default_tools.py, src/smolagents/mcp_client.py, src/smolagents/local_python_executor.py
- **Deployment, CLI, UI, Security, and Extensibility**: importance `high`
  - source_paths: src/smolagents/cli.py, src/smolagents/gradio_ui.py, src/smolagents/vision_web_browser.py, src/smolagents/serialization.py, src/smolagents/monitoring.py

## Repo Inspection Evidence

- repo_clone_verified: true
- repo_inspection_verified: true
- repo_commit: `e8b988d0a33ae2f0ca6e53a111fd21bc1aed42f3`
- inspected_files: `pyproject.toml`, `README.md`, `docs/README.md`, `docs/source/zh/_toctree.yml`, `docs/source/zh/index.md`, `docs/source/zh/guided_tour.md`, `docs/source/zh/_config.py`, `docs/source/hi/_toctree.yml`, `docs/source/hi/index.md`, `docs/source/hi/guided_tour.md`, `docs/source/hi/_config.py`, `docs/source/ko/_toctree.yml`, `docs/source/ko/index.md`, `docs/source/ko/guided_tour.md`, `docs/source/ko/_config.py`, `docs/source/ko/installation.md`, `docs/source/es/_toctree.yml`, `docs/source/es/index.md`, `docs/source/es/_config.py`, `docs/source/es/installation.md`

Host AI hard rules:
- Without repo_clone_verified=true, do not claim that the source code has been read.
- Without repo_inspection_verified=true, do not write README, docs, or package-file conclusions as facts.
- Without quick_start_verified=true, do not claim that the Quick Start path has run successfully.

## Doramagic Pitfall Constraints

These rules come from Doramagic discovery, validation, or compilation findings. The host AI must treat them as operating constraints, not background notes.

### Constraint 1: Maintenance risk requires verification

- Trigger: Project evidence flags a maintenance risk. Review the linked source before relying on this workflow.
- Host AI rule: Reproduce the official install and quickstart path in an isolated environment.
- Why it matters: May increase setup, validation, or first-run risk for the user.
- Evidence: community_evidence:github | https://github.com/huggingface/smolagents/issues/1579
- Hard boundary: Do not present this pitfall as solved, verified, or ignorable unless later evidence explicitly closes it.

### Constraint 2: Maintenance risk requires verification

- Trigger: Project evidence flags a maintenance risk. Review the linked source before relying on this workflow.
- Host AI rule: Reproduce the official install and quickstart path in an isolated environment.
- Why it matters: May increase setup, validation, or first-run risk for the user.
- Evidence: community_evidence:github | https://github.com/huggingface/smolagents/issues/694
- Hard boundary: Do not present this pitfall as solved, verified, or ignorable unless later evidence explicitly closes it.

### Constraint 3: Security or permission risk requires verification

- Trigger: Developers should check this security_permissions risk before relying on the project: [Feature Request] Memory Poisoning Protection for smolagents via OWASP Agent Memory Guard
- Host AI rule: Before packaging this project, run the relevant install/config/quickstart check for: [Feature Request] Memory Poisoning Protection for smolagents via OWASP Agent Memory Guard. Context: Observed when using python
- Why it matters: Developers may expose sensitive permissions or credentials: [Feature Request] Memory Poisoning Protection for smolagents via OWASP Agent Memory Guard
- Evidence: failure_mode_cluster:github_issue | https://github.com/huggingface/smolagents/issues/2332
- Hard boundary: Do not present this pitfall as solved, verified, or ignorable unless later evidence explicitly closes it.

### Constraint 4: Security or permission risk requires verification

- Trigger: Project evidence flags a security or permission risk. Review the linked source before relying on this workflow.
- Host AI rule: Reproduce the official install and quickstart path in an isolated environment.
- Why it matters: May increase setup, validation, or first-run risk for the user.
- Evidence: community_evidence:github | https://github.com/huggingface/smolagents/issues/2129
- Hard boundary: Do not present this pitfall as solved, verified, or ignorable unless later evidence explicitly closes it.

### Constraint 5: Security or permission risk requires verification

- Trigger: Project evidence flags a security or permission risk. Review the linked source before relying on this workflow.
- Host AI rule: Reproduce the official install and quickstart path in an isolated environment.
- Why it matters: May increase setup, validation, or first-run risk for the user.
- Evidence: community_evidence:github | https://github.com/huggingface/smolagents/issues/2332
- Hard boundary: Do not present this pitfall as solved, verified, or ignorable unless later evidence explicitly closes it.

### Constraint 6: Security or permission risk requires verification

- Trigger: Project evidence flags a security or permission risk. Review the linked source before relying on this workflow.
- Host AI rule: Reproduce the official install and quickstart path in an isolated environment.
- Why it matters: May increase setup, validation, or first-run risk for the user.
- Evidence: community_evidence:github | https://github.com/huggingface/smolagents/issues/901
- Hard boundary: Do not present this pitfall as solved, verified, or ignorable unless later evidence explicitly closes it.

### Constraint 7: Installation risk requires verification

- Trigger: Developers should check this installation risk before relying on the project: Save/Load agent memory
- Host AI rule: Before packaging this project, run the relevant install/config/quickstart check for: Save/Load agent memory. Context: Observed when using python
- Why it matters: Developers may fail before the first successful local run: Save/Load agent memory
- Evidence: failure_mode_cluster:github_issue | https://github.com/huggingface/smolagents/issues/1216
- Hard boundary: Do not present this pitfall as solved, verified, or ignorable unless later evidence explicitly closes it.

### Constraint 8: Installation risk requires verification

- Trigger: Developers should check this installation risk before relying on the project: v1.21.0
- Host AI rule: Before packaging this project, run the relevant install/config/quickstart check for: v1.21.0. Context: Observed when using python
- Why it matters: Upgrade or migration may change expected behavior: v1.21.0
- Evidence: failure_mode_cluster:github_release | https://github.com/huggingface/smolagents/releases/tag/v1.21.0
- Hard boundary: Do not present this pitfall as solved, verified, or ignorable unless later evidence explicitly closes it.

### Constraint 9: Installation risk requires verification

- Trigger: Developers should check this installation risk before relying on the project: v1.22.0
- Host AI rule: Before packaging this project, run the relevant install/config/quickstart check for: v1.22.0. Context: Observed when using python, docker
- Why it matters: Upgrade or migration may change expected behavior: v1.22.0
- Evidence: failure_mode_cluster:github_release | https://github.com/huggingface/smolagents/releases/tag/v1.22.0
- Hard boundary: Do not present this pitfall as solved, verified, or ignorable unless later evidence explicitly closes it.

### Constraint 10: Configuration risk requires verification

- Trigger: Developers should check this configuration risk before relying on the project: DOC: `evaluate_python_code` docstring is missing two parameters
- Host AI rule: Before packaging this project, run the relevant install/config/quickstart check for: DOC: `evaluate_python_code` docstring is missing two parameters. Context: Observed when using python
- Why it matters: Developers may misconfigure credentials, environment, or host setup: DOC: `evaluate_python_code` docstring is missing two parameters
- Evidence: failure_mode_cluster:github_issue | https://github.com/huggingface/smolagents/issues/2372
- Hard boundary: Do not present this pitfall as solved, verified, or ignorable unless later evidence explicitly closes it.
