The model never runs anything itself. It emits a structured request — this function, these arguments — and your code decides whether to honour it, executes it, and hands the result back. That gap is the single most important control surface in any agent, because it is the one place where a human-written rule sits between the model's intention and a real effect.
Treating it as a formality is the common failure. The arguments are model output and therefore untrusted: validate them the way you would validate a form submission from the internet, because that is effectively what they are. Scope each tool's credentials to what that tool needs, not to what the application has.
Related terms
AI agent
A language model given tools it can call and a goal to pursue, so it decides the steps rather than following a fixed script.
MCP (Model Context Protocol)
An open protocol for exposing tools and data to a model, so one integration works with any client that speaks it.
Prompt injection
An attack where text the model reads as data is treated by it as instructions instead.
The bench this belongs to
AI automationThe repetitive half of your week, handed to software that does not get bored. Inbox triage, follow-ups, reporting, data entry between tools that were never meant to talk.
