Skip to content

Tool Use and Function Calling

Stories from people dealing with Tool Use and Function Calling — what changed, who decided it, and what the ordinary days look like now.

14 stories

Laptop showing an invoice download held in quarantine before email and cloud upload approval.

Agentic AI & Orchestration

Block Browser Agents From Reuploading Unchecked Files

A browser agent can carry a hostile download from a public site into email or cloud storage. Put an inspection gate between the download tool and every upload tool.

Mara Quintero · August 9, 2026 · 7 min

Support workstation showing a replacement-laptop case with its warehouse shipment status marked unknown.

Agentic AI & Orchestration

An AI Agent Timed Out. The Shipment May Still Be Moving

A timed-out tool call can leave an agent between failure and success. Safe retries depend on a persistent request identity, a way to check status, and a queue for unresolved actions.

Mara Quintero · 7 min read

Laptop showing a refund analysis query beside a database access policy limited to approved views.

Agentic AI & Orchestration

Let the Database Agent See Views, Not Your Production Tables

A natural-language database agent can handle recurring analysis without arbitrary SQL access. The workable setup combines narrow views, enforced query budgets and a separate path for changes.

Mara Quintero · 8 min read

Browser-agent tool log showing an invoice task diverted toward a blocked external URL containing a test canary.

Agentic AI & Orchestration

A Webpage Can Quietly Rewrite an AI Agent’s Task

A browser agent followed instructions embedded in a vendor support page instead of retrieving an invoice. Isolation reduced the confusion; narrow tool permissions stopped the attempted data leak.

Mara Quintero · 8 min read

Laptop showing a supplier refund page beside an agent approval panel listing an invoice and email destination.

Agentic AI & Orchestration

A Hidden Webpage Prompt Can Redirect a Browser Agent

Indirect prompt injection turns ordinary page content into instructions for an agent. The practical defense is to limit what the agent can see, call, and approve on its own.

Mara Quintero · 8 min read

Laptop showing a blocked browser-agent navigation beside a case note containing a vendor return window.

Agentic AI & Orchestration

Stop Hidden Webpage Commands From Hijacking a Browser Agent

A browser agent followed an off-screen instruction into a dummy internal file. A URL allowlist and action-level confirmation gate stopped the same run without relying on the model to police itself.

Mara Quintero · 8 min read

Laptop showing two model-response logs beside a support workflow configuration screen.

AI Industry & Models

Test the Replacement Before Your Model API Disappears

A retirement date tells you when an endpoint closes, not whether its replacement behaves the same. Shadow traffic exposes changes in refusals, tool calls, latency, and length before cutover.

Tobias Lund · 8 min read

Laptop showing an invoice portal beside a vendor page, with an agent tool-call log open on a second screen.

Agentic AI & Orchestration

A Web Page Can Turn Your Browser Agent Against Its Tools

Indirect prompt injection turns page content into commands for an AI agent. Authenticated sessions raise the stakes because the agent may already have access to files, email, purchases, or account settings.

Mara Quintero · 8 min read

A laptop showing a failed JSON validation log beside an order refund screen.

AI Industry & Models

Schema-Constrained AI Still Sends Bad Data to Production

Valid JSON is only the first gate. Production systems must also catch truncated responses, schema drift, unsupported fields, and values that look valid but trigger the wrong action.

Tobias Lund · 8 min read

Other impacts

One story a day

The story of the day, in your inbox

One real story about AI each morning — no hype, no alarm, just company for the road.