Before you dive in
What you’ll find in the original
- Build the decision from the available Composio tool set and the user's request rather than asking a model to emit an arbitrary tool call.
- Handle an explicit abstain result before touching any external system.
- Keep execution behind an application-owned risk check; the demo refuses tools whose risk class is not read-only.
Worth knowing
Requires Composio credentials and TypeSafe access. The demo is an integration pattern, not evidence that every Composio tool is safe or correctly classified; applications must define and enforce their own execution policy.