AI Agents
Tool Use
Function calling, schemas, and validating what the model asks you to run.
Grasp
Tool use is how a language model stops being a text generator and starts being able to act. You describe a set of functions with a schema, the model decides which one to call and with what arguments, your code executes it, and the result goes back into the conversation.
The model never runs anything itself. It emits a structured request, and every consequence of that request is yours to permit or refuse. That boundary is the single most important thing to hold onto, because it is where all of the security and all of the reliability live.
What separates working tool use from a demo is unglamorous. Tool descriptions are prompts - vague ones produce wrong calls, and the fix is almost always a better description rather than a better model. Arguments must be validated before execution, never trusted because they parsed. Errors returned to the model should explain what to do differently, since a good error message lets it recover on the next turn. And anything irreversible - sending, deleting, paying - needs a human in the loop or a hard constraint in code, not a polite instruction in the prompt.