Skip to content

add WebSearchTool with Metaso API integration - #133

Closed
mrluanma wants to merge 1 commit into
HKUDS:mainfrom
meta-sota:feat/websearch-metaso
Closed

add WebSearchTool with Metaso API integration#133
mrluanma wants to merge 1 commit into
HKUDS:mainfrom
meta-sota:feat/websearch-metaso

Conversation

@mrluanma

Copy link
Copy Markdown

Description

Adds WebSearchTool — a web search tool backed by the Metaso API — and registers it in the default agent toolset. Includes a built-in default API key with ~100 free searches/day.

Related Issues

None.

Changes Made

  • nanobot/agent/tools/web.py — Added _get_metaso_api_key() helper (falls back to built-in default key), and WebSearchTool class with web_search name, supporting query and optional topK params.
  • nanobot/agent/loop.py — Imported and registered WebSearchTool alongside WebFetchTool.
  • nanobot/workspace/TOOLS.md — Documented the new web_search tool.
  • tests/web_search_test.py — 387 lines of tests covering API key resolution, search responses, error handling, and edge cases.

Implement web_search tool using the Metaso search API. The tool supports
query-based web search with configurable result count, API key resolution
from METASO_API_KEY env var, and comprehensive error handling for rate
limits, auth failures, and daily quotas.

Metaso provides 100-free-searches/day quota.  You can set your own
`METASO_API_KEY` environment variable to raise that limit.
@Zongwei9888

Copy link
Copy Markdown
Collaborator

Closing this branch — it targets nanobot/nanobot/agent/tools/web.py, and the nanobot/ tree was removed in the v2.0 refactor. The equivalent surface today is core/harness/tools/web.py.

The WebSearchTool idea is worth having. Two things would need to change in a version against core/:

  1. No bundled key. _get_metaso_api_key() falls back to a literal key when METASO_API_KEY is unset. That would trip the repo's gitleaks check, and a shared key in a public repo gets exhausted or abused quickly. Reading the environment variable only, and failing with a clear message when it is absent, matches how every other credential is handled here.
  2. Register through core/harness/tools/ rather than the old agent loop.

Separately, and worth acting on regardless of this PR: that key has been visible in this diff since May. It should be rotated.

@Zongwei9888 Zongwei9888 closed this Aug 6, 2026
pull Bot pushed a commit to ari1988/DeepCode that referenced this pull request Aug 6, 2026
The Secret history scan has failed on main since dd8f0a8. Cause: merging HKUDS#131
with -s ours recorded the branch in history without applying its tree, and
gitleaks scans history, not the working tree.

The finding is a fixture, not a credential — the literal "sk-secret123456"
inside a RuntimeError message, asserting that error text is redacted before it
reaches the UI. Its file, tests/ui_session_resume_test.py, does not exist on
main, so the finding cannot be fixed by editing it; a fingerprint entry is the
only route.

Verified: gitleaks over origin/main now reports no leaks across 240 commits.

Note for future -s ours merges: they bring the branch's full history under the
secret scan. Two branches deliberately left unmerged (HKUDS#133, HKUDS#143) carry
findings of their own, and HKUDS#133's is a real key — merging them for attribution
alone would have put it in main's history permanently.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants