Hands and Function Calls
A language model alone can only emit text. Give it tools and it can look things up, run code, send messages, and write files. The mechanism is function calling: the model does not run anything — it emits a structured request, and your code decides whether to honour it.
The tool schema
You describe each tool with a schema: a name, a description, and typed parameters. That description is a prompt. Vague tools get called wrongly; precise tools get called well. The model reads the schema, decides a call is needed, and emits arguments matching it.
Tools fall into a few broad kinds. Retrieval tools search a knowledge base. Code execution tools run code in a sandbox. API tools talk to the outside world. Write tools change state — and those are the ones that need permission checks and confirmation.
The security boundary
A model that can only produce text can only offend. A model that can call tools can delete files, spend money, and email your customers. Every tool is an attack surface, and every untrusted input is a potential prompt injection: text that hijacks the agent into calling tools it should not.