A tool is a function call with manners
The model does not run anything. It emits a name and arguments, you decide whether to honour them, and that boundary is your security model.
Tool use is a structured output with a convention attached. You describe available functions with a schema; the model returns a request to call one with arguments; your code validates and executes it if it chooses to; the result goes back in as another message and the model continues. At no point does the model execute anything or hold any privilege.
That means every authorisation decision is yours and belongs in ordinary code: the same checks you would apply to a request from an untrusted client, because that is exactly what a tool call is. Arguments are attacker-influenceable input. Validate types, bound ranges, check the current user actually owns the record, and never construct a query by interpolating what came back.
The failure everyone makes once is putting the rule in the prompt: telling the model it may only refund up to fifty pounds. That is a suggestion to a text generator, not a control. The control is the fifty-pound check in the function.
You should now be able to
- Describe the full round trip of a tool call
- Identify who is responsible for authorisation
Loading…