AI Foundationspredict · compress · act
act IX

The Agent Infrastructure

A model with tools can search, calculate, and change the world. A tool schema is a contract written in JSON.

34

Hands and Function Calls

before this →From Answer to Action

A language model alone can only emit text. Give it tools and it can look things up, run code, send messages, and write files. The mechanism is function calling: the model does not run anything — it emits a structured request, and your code decides whether to honour it.

modelproposes{“name”: “search”,“args”: {…}}your codechecks, then runsresult fed back into context — the model never executes anything itself
the model proposes a call; your program executes it and returns the result

The tool schema

You describe each tool with a schema: a name, a description, and typed parameters. That description is a prompt. Vague tools get called wrongly; precise tools get called well. The model reads the schema, decides a call is needed, and emits arguments matching it.

Tools fall into a few broad kinds. Retrieval tools search a knowledge base. Code execution tools run code in a sandbox. API tools talk to the outside world. Write tools change state — and those are the ones that need permission checks and confirmation.

The security boundary

this is where agents get dangerous

A model that can only produce text can only offend. A model that can call tools can delete files, spend money, and email your customers. Every tool is an attack surface, and every untrusted input is a potential prompt injection: text that hijacks the agent into calling tools it should not.

the ruleTreat the model as an untrusted user, not a trusted administrator. Validate arguments, gate risky tools, and never let model output become a shell command unchecked.
SCHEMAdescribe the tool precisely
PROPOSEthe model emits a structured call
VALIDATEyour code decides and checks
introduces →function callingtool schemacode executionAPI
← previousFrom Answer to Actionnext →Memory Outside the Weights