What a tool can read
A tool reads five views of what unicorn holds: items, upcoming deadlines, changes, courses and buckets. It cannot read credentials or settings, and it cannot write. Your agent can list the views and their columns with the admin tooldescribe_schema.
Rules
You cannot reuse the name of a built-in tool. Statements that insert, update, delete, drop or change database settings are rejected, and the message quotes the part that failed so your agent can fix it and try again.
Mount the admin connection
Defining tools uses unicorn’s admin connection. It is a separate address from the one your agent normally uses, and it takes the admin token only. A browser approval cannot reach it, which means you cannot add it to claude.ai or ChatGPT. Use a terminal client such as Claude Code.Define a tool
With the admin connection mounted, describe the question to your agent. It writes the query and saves it.list_tools shows what you have.
Install a shared tool
A shared library holds tools other people wrote. It lives in theTuuHub/unicorn-tools repository on GitHub.
Share a tool
Ask your agent to publish one of yours. It prepares the file, the library entry and thegh commands to open a pull request. unicorn never writes to GitHub: your agent runs the commands from your machine, with your GitHub login, and you review the pull request.