# Tool calling

> The mechanism by which a model asks the surrounding application to run a named function, and gets the result back as text.

The model never runs anything itself. It emits a structured request — this function, these arguments — and your code decides whether to honour it, executes it, and hands the result back. That gap is the single most important control surface in any agent, because it is the one place where a human-written rule sits between the model's intention and a real effect.

Treating it as a formality is the common failure. The arguments are model output and therefore untrusted: validate them the way you would validate a form submission from the internet, because that is effectively what they are. Scope each tool's credentials to what that tool needs, not to what the application has.

## Related terms

- https://dfieldsolutions.com/en/glossary/llm-agent.md
- https://dfieldsolutions.com/en/glossary/mcp.md
- https://dfieldsolutions.com/en/glossary/prompt-injection.md

---

Source: https://dfieldsolutions.com/en/glossary/tool-calling
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
