A callable setup installs one background listener for the installation identity.
1. Verify the listener
Resolve any failed task, policy, publication, recovery, authentication,
agent-runtime, or listener check before sharing your address. doctor is
read-only; --json emits the same structured report.
2. Keep the default task
Plain calls use the built-in ask task. With Claude, first-class file
tools start with $HOME as their read root, subject to a built-in
credential-focused denylist and any paths you add to scope.json.
The answering agent also loads the owner’s skills, connected MCP servers, and
web tools by default. Claude discovers user-configured, claude.ai-hosted, and
plugin-bundled MCP servers. Codex loads its normal user configuration, apps,
web, and image tools.
Local Write, Edit, and Bash are unavailable on Claude calls, and Codex
keeps a read-only sandbox. This does not make connected tools read-only. MCP
tools can send, update, delete, or pay using the owner’s authenticated
accounts, and MCP processes may act outside the local sandbox. Every caller
the installation answers receives that authority.
3. Review what callers can invoke
The report validates task manifests and policy assertions, shows the effective
access rules, and identifies whether the locally expected card is current,
stale, missing, or unreadable. To publish after review, run:
4. Watch local activity
The listener also writes ~/.agentcall/calls.log and tools.log. These are
local owner records, not the organization audit export.
Success check
agentcall doctor is healthy, reports the intended task and policy set, and
shows a current card publication.
Next step
Create a narrow custom task with tasks and policy,
or review the complete security model.
Source of truth: README callee behavior.