Llamada de herramientas
Tool calling lets a model request an operation through a defined interface.
Descripción general
The application or provider executes the operation and returns a result. A model proposing a tool call is different from that call succeeding, and both are different from the user’s overall task being completed.
Conclusiones clave
- Validate authority as well as argument shape.
- Design safe retries for side effects.
- Verify the resulting state.
Buceo profundo
Define each tool’s purpose, input schema, output shape, and side effects. A narrowly scoped operation is easier to validate than a general command interface. The tool description should explain when the operation is appropriate without granting the model authority beyond the user’s request. Validate inputs and permissions in application code. A well-formed argument can still identify the wrong account, destination, or amount. Keep secrets out of tool descriptions and return only information the requesting user is allowed to access. Handle errors and uncertain outcomes explicitly. A network timeout may occur before or after an external action completes. Use operation identifiers or a read-back check where possible so a retry does not duplicate a completed action. After execution, supply an accurate result and verify the intended state. Treat text returned by a website or document as untrusted content; it cannot authorize new actions merely because it arrived through a tool. Test cancellation, malformed responses, revoked access, and partial completion as part of the full tool-use loop.
Información técnica
Input-schema validation establishes shape and some constraints. It does not prove that an action is authorized or that the selected record is the correct one.
Retry without duplicating work
- Imagine a task-creation tool accepts request identifier demo-17. The response times out after the task is created.
- Look up demo-17 before creating another task. If the service supports idempotency, reuse the same identifier for the retry.
- Report completion only after confirming the resulting task and its contents.
This constructed example separates uncertain transport from the external action’s actual outcome.
Impacto Estratégico
Speed and scale
Los flujos de trabajo lingüísticos pueden avanzar más rápido sin sacrificar la coherencia.
Access and reach
Amplía el acceso a través de idiomas y estilos de comunicación.
Decisiones más claras
Los equipos pueden dedicar más tiempo a juzgar mientras la automatización se encarga de la repetición.
Implementación en el mundo real
Fetch a current record before proposing an update.
Return an operation identifier and verified result after a file save.
Riesgos y barandillas
Los hechos alucinados pueden aparecer silenciosamente en informes, flujos de apoyo o resultados de investigaciones.
La sensibilidad rápida puede crear resultados inconsistentes en solicitudes similares.
Los datos de texto confidenciales pueden quedar expuestos si los controles de acceso son débiles.
Hoja de ruta de implementación
Defina el formato de salida, el tono y los estándares de calidad antes del lanzamiento.
Respuestas terrestres con fuentes confiables siempre que la precisión sea importante.
Mantenga un punto de control de revisión humana para los resultados de alto riesgo.
Realice un seguimiento de los patrones de error y vuelva a capacitar las indicaciones o los flujos de trabajo con regularidad.
Fuentes y lecturas adicionales
- AnthropicHow tool use works
Sigue explorando
Free newsletter
Get the daily AI briefing
Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.
One email each weekday. Unsubscribe in one click. We never sell or share your address.
Test yourself
Take the Tool Calling quiz
Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.
Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation
Siguiente guía
Orquestación de herramientas agentes
Preguntas frecuentes
Does a model execute a function merely by naming it?
No. The application or tool provider executes the operation. A structured request must be handled, authorized, and checked.