diff --git a/CHANGELOG.md b/CHANGELOG.md
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -1,6 +1,10 @@
 # Changelog
 
-## Unreleased
+## 0.4.1.0 — 2026-09-30
+
+- Give `ReAct`'s `ProtocolAuto` its own tool-calling check instead of reusing `Shikumi.Adapter.capabilityFor`. Behavior is unchanged: only `openai` over Chat Completions or Responses and `anthropic` over Messages use provider-native tool calling. CLI models, which `shikumi` 0.4.1.0 now treats as schema-native, still use the prompt tool protocol, because Baikai's CLI providers drop tools. Raise the internal `shikumi` bound to `^>=0.4.1.0` so this check never pairs with an older `shikumi`.
+
+- Move the dependency on `mori://shinzui/baikai/packages/baikai` to `>=0.7.1.0 && <0.8` and widen the `effectful` bound to `>=2.6 && <2.8`, so both effectful 2.6 and 2.7 are supported (effectful 2.7 needs `baikai-effectful` 0.4.0.2, effectful 2.6 needs 0.4.0.1). Bounds only; no source changed.
 
 ## 0.4.0.0 — 2026-09-08
 
diff --git a/shikumi-tools.cabal b/shikumi-tools.cabal
--- a/shikumi-tools.cabal
+++ b/shikumi-tools.cabal
@@ -1,10 +1,10 @@
-cabal-version:   3.4
-name:            shikumi-tools
-version:         0.4.0.0
+cabal-version: 3.4
+name: shikumi-tools
+version: 0.4.1.0
 synopsis:
   Typed tools and ReAct agents for shikumi LM programs (EP-11)
 
-category:        AI
+category: AI
 description:
   Typed tools and multi-step ReAct agents for shikumi. A @Tool i o@ is an ordinary
   function over record types whose JSON-Schema argument shape is Generic-derived
@@ -19,20 +19,26 @@
   inspectable shikumi program. Every test runs against a deterministic mock LM with
   no network.
 
-license:         BSD-3-Clause
-author:          Nadeem Bitar
-maintainer:      nadeem@gmail.com
-build-type:      Simple
+license: BSD-3-Clause
+author: Nadeem Bitar
+maintainer: nadeem@gmail.com
+build-type: Simple
 extra-doc-files: CHANGELOG.md
 
 common common-options
   ghc-options:
-    -Wall -Wcompat -Widentities -Wincomplete-uni-patterns
-    -Wincomplete-record-updates -Wredundant-constraints
-    -fhide-source-paths -Wmissing-export-lists -Wpartial-fields
+    -Wall
+    -Wcompat
+    -Widentities
+    -Wincomplete-uni-patterns
+    -Wincomplete-record-updates
+    -Wredundant-constraints
+    -fhide-source-paths
+    -Wmissing-export-lists
+    -Wpartial-fields
     -Wmissing-deriving-strategies
 
-  default-language:   GHC2024
+  default-language: GHC2024
   default-extensions:
     DeriveAnyClass
     DuplicateRecordFields
@@ -40,8 +46,8 @@
     OverloadedStrings
 
 library
-  import:          common-options
-  hs-source-dirs:  src
+  import: common-options
+  hs-source-dirs: src
   exposed-modules:
     Shikumi.Agent.History
     Shikumi.Agent.ReAct
@@ -61,31 +67,34 @@
     Shikumi.Tool.Web
 
   build-depends:
-    , aeson            >=2.2      && <2.3
-    , baikai           >=0.7.0.0  && <0.8
-    , base             >=4.20     && <5
-    , bytestring       >=0.11     && <0.13
-    , containers       >=0.6      && <0.9
-    , directory        >=1.3      && <1.4
-    , effectful        >=2.5      && <2.7
-    , filepath         >=1.4      && <1.6
-    , generic-lens     >=2.2      && <2.4
-    , http-client      >=0.7      && <0.8
-    , http-client-tls  >=0.3      && <0.5
-    , http-types       >=0.12     && <0.13
-    , lens             ^>=5.3
-    , process          >=1.6      && <1.7
-    , regex-tdfa       >=1.3      && <1.4
-    , shikumi          ^>=0.4.0.0
-    , text             ^>=2.1
-    , vector           >=0.13     && <0.14
+    aeson >=2.2 && <2.3,
+    baikai >=0.7.1.0 && <0.8,
+    base >=4.20 && <5,
+    bytestring >=0.11 && <0.13,
+    containers >=0.6 && <0.9,
+    directory >=1.3 && <1.4,
+    effectful >=2.6 && <2.8,
+    filepath >=1.4 && <1.6,
+    generic-lens >=2.2 && <2.4,
+    http-client >=0.7 && <0.8,
+    http-client-tls >=0.3 && <0.5,
+    http-types >=0.12 && <0.13,
+    lens ^>=5.3,
+    process >=1.6 && <1.7,
+    regex-tdfa >=1.3 && <1.4,
+    shikumi ^>=0.4.1.0,
+    text ^>=2.1,
+    vector >=0.13 && <0.14,
 
 test-suite shikumi-tools-test
-  import:         common-options
-  type:           exitcode-stdio-1.0
+  import: common-options
+  type: exitcode-stdio-1.0
   hs-source-dirs: test
-  main-is:        Main.hs
-  ghc-options:    -threaded -with-rtsopts=-N
+  main-is: Main.hs
+  ghc-options:
+    -threaded
+    -with-rtsopts=-N
+
   other-modules:
     AcceptanceSpec
     AgentHistorySpec
@@ -97,13 +106,13 @@
     FsSpec
     ProgramOfThoughtSpec
     ProtocolSpec
+    RLMExample
+    RLMSpec
     ReActSessionExample
     ReActSpec
     ResponsesIntegrationSpec
     ResponsesSchemaSpec
     RestrictedSpec
-    RLMExample
-    RLMSpec
     SchemaSpec
     SessionSpec
     ShellSpec
@@ -112,21 +121,21 @@
     WebSpec
 
   build-depends:
-    , aeson
-    , baikai           >=0.7.0.0  && <0.8
-    , base
-    , bytestring
-    , containers
-    , directory
-    , effectful
-    , filepath
-    , generic-lens
-    , lens
-    , shikumi          ^>=0.4.0.0
-    , shikumi-cache    ^>=0.2.0.0
-    , shikumi-testing  ^>=0.1.0.0
-    , shikumi-tools    ^>=0.4.0.0
-    , tasty
-    , tasty-hunit
-    , text
-    , vector
+    aeson,
+    baikai >=0.7.1.0 && <0.8,
+    base,
+    bytestring,
+    containers,
+    directory,
+    effectful,
+    filepath,
+    generic-lens,
+    lens,
+    shikumi ^>=0.4.1.0,
+    shikumi-cache ^>=0.2.0.0,
+    shikumi-testing ^>=0.1.0.0,
+    shikumi-tools ^>=0.4.0.0,
+    tasty,
+    tasty-hunit,
+    text,
+    vector,
diff --git a/src/Shikumi/Agent/ReAct.hs b/src/Shikumi/Agent/ReAct.hs
--- a/src/Shikumi/Agent/ReAct.hs
+++ b/src/Shikumi/Agent/ReAct.hs
@@ -16,8 +16,9 @@
 -- inspectable, and composes with every other shikumi program and combinator.
 --
 -- Two tool /protocols/ are supported behind one internal interface ('ProtocolImpl'),
--- selected by a 'ToolProtocol' value ('ProtocolAuto' resolves per model via
--- "Shikumi.Adapter"'s 'capabilityFor'): a provider-native function-calling path
+-- selected by a 'ToolProtocol' value ('ProtocolAuto' resolves per model from a
+-- tool-calling table of first-party HTTP hosts, kept separate from
+-- "Shikumi.Adapter"'s schema-only 'Shikumi.Adapter.capabilityFor'): a provider-native function-calling path
 -- (baikai @Context.tools@ + @Options.toolChoice@, parsing @AssistantToolCall@ blocks)
 -- and a prompt-based fallback that renders an explicit action grammar and parses the
 -- model's text. The loop body is protocol-agnostic.
@@ -93,7 +94,7 @@
 import Effectful (Eff, (:>))
 import Effectful.Error.Static (Error, catchError, throwError)
 import GHC.Generics (Generic)
-import Shikumi.Adapter (ModelCapability (..), ToPrompt (toPrompt), attachSchema, capabilityFor)
+import Shikumi.Adapter (ToPrompt (toPrompt), attachSchema)
 import Shikumi.Agent.History (ReActSession)
 import Shikumi.Agent.History qualified as H
 import Shikumi.Compaction (CompactionConfig (..), compactTail, defaultCompactionConfig, usageExceedsWindow)
@@ -361,9 +362,23 @@
 resolveProtocolKind :: ToolProtocol -> Model -> ToolProtocol
 resolveProtocolKind ProtocolNative _ = ProtocolNative
 resolveProtocolKind ProtocolPrompt _ = ProtocolPrompt
-resolveProtocolKind ProtocolAuto m = case capabilityFor m of
-  NativeSchema -> ProtocolNative
-  PromptFallback -> ProtocolPrompt
+resolveProtocolKind ProtocolAuto m
+  | nativeToolCalling m = ProtocolNative
+  | otherwise = ProtocolPrompt
+
+-- | Whether a model's transport executes provider-native function calling.
+-- Deliberately not "Shikumi.Adapter"'s 'Shikumi.Adapter.capabilityFor': that
+-- answers /schema/ enforcement, which baikai's CLI providers (@claude@, @codex@)
+-- support, while those same providers silently drop @Context.tools@. Only the
+-- first-party HTTP hosts are native here; CLI, third-party and @Custom@ hosts
+-- use the prompt protocol.
+nativeToolCalling :: Model -> Bool
+nativeToolCalling m =
+  (m ^. #provider, m ^. #api)
+    `elem` [ ("openai", B.OpenAIChatCompletions),
+             ("openai", B.OpenAIResponses),
+             ("anthropic", B.AnthropicMessages)
+           ]
 
 -- | Build the concrete 'ProtocolImpl' for a model, choosing the native or prompt
 -- renderers from 'resolveProtocolKind'.
diff --git a/test/ProtocolSpec.hs b/test/ProtocolSpec.hs
--- a/test/ProtocolSpec.hs
+++ b/test/ProtocolSpec.hs
@@ -61,6 +61,12 @@
           _ -> assertFailure "both protocols should succeed",
       testCase "ProtocolAuto picks prompt for a CLI model" $
         resolveProtocolKind ProtocolAuto (emptyModel & #api .~ AnthropicMessagesCli) @?= ProtocolPrompt,
+      testCase "ProtocolAuto picks prompt for a codex CLI model" $
+        resolveProtocolKind ProtocolAuto (emptyModel & #provider .~ "codex-cli" & #api .~ OpenAICompletionsCli) @?= ProtocolPrompt,
+      testCase "ProtocolAuto picks prompt for a claude CLI model (schema-native, not tool-native)" $
+        resolveProtocolKind ProtocolAuto (emptyModel & #provider .~ "claude-cli" & #api .~ AnthropicMessagesCli) @?= ProtocolPrompt,
+      testCase "ProtocolAuto picks prompt for a third-party Chat Completions host" $
+        resolveProtocolKind ProtocolAuto (emptyModel & #provider .~ "deepseek" & #api .~ OpenAIChatCompletions) @?= ProtocolPrompt,
       testCase "ProtocolAuto picks native for a native-capable model" $
         resolveProtocolKind ProtocolAuto (emptyModel & #provider .~ "openai" & #api .~ OpenAIChatCompletions) @?= ProtocolNative,
       testCase "native turn with two tool calls executes both in order" $ do
