Skip to content

Subagents ​

For the concept and everyday use, read Subagents.

Fields ​

FieldDescriptionDefault
SubagentMaxConcurrencyMaximum concurrent subagents3
SubAgent.MaxDepthMaximum spawn depth for session-backed subagents. The first child is depth 11
SubAgent.MaxConcurrentSubAgentsMaximum resident session-backed subagents inside one root thread's subtree. Exceeding it auto-closes the oldest idle subagent, and the spawn fails instead when every resident subagent is still running16
SubAgent.ProviderPreferencesComplete native subagent preferences keyed by the parent thread provider. A missing entry inherits that thread's complete MainAgent preference{}
SubAgent.MinWaitTimeoutMsMinimum accepted WaitAgent.timeoutMs value in milliseconds15000
SubAgent.DefaultWaitTimeoutMsWaitAgent.timeoutMs used when the tool call omits a timeout60000
SubAgent.MaxWaitTimeoutMsMaximum accepted WaitAgent.timeoutMs value in milliseconds3600000
SubAgent.EnableExternalCliSessionResumeAllows external CLI profiles that support resume to reuse saved external sessionsfalse
SubAgent.DisabledProfilesSubagent profile names hidden and disabled for this workspace[]
SubAgent.RolesWorkspace-defined subagent roles. Entries with built-in names override built-in roles[]

Roles ​

Role example:

json
{
  "SubAgent": {
    "MaxDepth": 2,
    "Roles": [
      {
        "Name": "docs-explorer",
        "Description": "Read-only documentation and code explorer.",
        "ToolAllowList": ["ReadFile", "GrepFiles", "FindFiles", "WebSearch", "WebFetch", "SkillView", "Exec"],
        "ShellAccess": "ReadOnly",
        "AgentControlToolAccess": "Disabled",
        "Instructions": "Inspect files, web sources, and non-mutating shell output such as `git diff`. Do not edit files, manage skills, or spawn agents."
      }
    ]
  }
}

Fields inside each SubAgent.Roles entry:

FieldDescription
NameRole name, also the value used by SpawnAgent.agentRole
DescriptionShort role description exposed to the main Agent
ToolAllowListExact tool allow-list; empty means no additional restriction on eligible tools
ToolDenyListExact tool deny-list removed after the tool set is assembled
ShellAccessHow far a reachable shell tool may go: None / ReadOnly / Full. Applied in addition to the allow/deny lists, not instead of them. Defaults to Full
AgentControlToolAccessAgentTools policy: Disabled / Full / AllowList
AllowedAgentControlToolsAgentTools names allowed when AgentControlToolAccess is AllowList
InstructionsRole instructions delivered as the subagent thread's role context message
ModeOptional mode override
ModelOptional model override
OverrideBasePromptReplaces the base prompt with Instructions; by default instructions are appended

External CLI profiles ​

Custom external CLI profiles live under SubAgentProfiles. Workspace config overrides same-named global profiles.

json
{
  "SubAgent": {
    "EnableExternalCliSessionResume": true
  },
  "SubAgentProfiles": {
    "my-cli": {
      "runtime": "cli-oneshot",
      "bin": "my-cli",
      "workingDirectoryMode": "workspace",
      "inputMode": "arg",
      "outputFormat": "text",
      "supportsResume": true,
      "resumeArgTemplate": "--resume {sessionId}",
      "resumeSessionIdJsonPath": "session_id"
    }
  }
}

Fields inside each SubAgentProfiles entry:

FieldDescription
runtimeRuntime type; external short-process CLIs use cli-oneshot
binCLI executable name or absolute path
argsFixed argument list
workingDirectoryModeworkspace / specified
inputModestdin / arg / arg-template / env
inputArgTemplateTemplate for arg-template mode
inputEnvKeyEnv-var name receiving task text in env mode
envFixed env vars injected into the subprocess
envPassthroughNames of env vars to copy from parent
outputFormattext or json
outputJsonPathJSON path to extract the final result in json mode
readOutputFilePrefer reading the output file as the final result
outputFileArgTemplateOutput-file argument template, supports {path}
supportsResumeAllow DotCraft to store and reuse the external session id
resumeArgTemplateResume argument template, supports {sessionId}
resumeSessionIdJsonPathJSON path to extract session id from stdout
resumeSessionIdRegexRegex fallback when stdout is not a single JSON object
timeoutPer-run timeout in seconds
maxOutputBytesMaximum captured output bytes
trustLeveltrusted / prompt / restricted
permissionModeMappingMap DotCraft approval modes to CLI arguments

Vendor headless notes:

ProfileBehavior
cursor-cliDotCraft injects -p --output-format json and appends --resume {sessionId} when resuming
codex-cliDotCraft injects exec plus output-file arguments; resume becomes exec resume {sessionId}