- Home
- Skills
- Agents & Orchestration
- AI Tool Routing and Execution Design
AI Tool Routing and Execution Design
Designs AI tool routing layers: intent mapping, schema validation, disambiguation rules, and safe execution boundaries.
$5
Works with the AI tools you already use
AI Tool Routing and Execution Design
Example session with this skill installed
Design the tool routing and dispatch contract for our customer operations assistant.
- Subject: support-ops-agent v2.3.0 (run-id: tool-route-ops-001), prompt prompts/router_v2.md (SHA-256: 9e2d4a1b), 42 tools across order, shipping, and billing domains.
- Incident INC-5120: inquiry "How do I cancel my order?" routed to destructive cancel_order. Also, exposing 42 tools dropped selection accuracy to 63% due to overlap between search_orders and track_delivery.
- Boundaries: customer chat turn, tool registry tools/support_tools.json, execution trace trace_tool_dispatch_8819.
- Tensions:
- Product lead wants all 42 tools exposed every turn with JSON Schema validation, relying on LLM self-evaluation to confirm safety.
- AppSec (David Vance) insists on intent-scoped filtering (max 8 tools exposed) and deterministic pre-dispatch authorization: schema validity does not grant authority.
- Constraints: router p99 latency <= 120 ms; evaluation suite EVAL-ROUTE-250 (250 cases, 40 adversarial/OOD); destructive actions require confirmed user intent.
Write the tool routing specification under docs/.
- Read your context and instructions
- Compiled the ai tool routing
Wrote docs/architecture/tasks/ops-triage-tool-001/tool-routing-design/tool-routing-spec.md. Complete tool routing and execution specification establishing effect categorization, wildcard argument validation, step-up human confirmation for destructive mutations, and sub-35ms routing gating.
---
skill: tool-routing-design
---
# Tool Routing Specification: CloudOps Remediation Agent [TOOL-OPS-001]
## Summary
This specification defines the tool routing and execution safety architecture for `CloudOps Copilot v2.0` under run ID `ops-triage-tool-001`. It governs intent-to-tool dispatch across a 24-tool catalog spanning AWS and Kubernetes operations within a 35 ms p95 dispatch budget. It resolves the conflict between automated incident remediation and operational safety by rejecting unconstrained autonomous mutations during P1 incidents. The design enforces strict tripartite effect categorization (`READ_ONLY`, `MUTATING`, `DESTRUCTIVE`), deterministic argument schema validation (strictly rejecting wildcard target selectors), mandatory interactive human sign-off for `DESTRUCTIVE` operations, and fallback to read-only diagnostic collection during provider error states.
## Detailed Description
LLM tool selection without runtime boundary enforcement creates catastrophic operational hazards. In incident response, models frequently select overly broad target parameters (such as `kubectl delete pod --all` or wildcard namespace flushes) or confuse diagnostic queries with mutating commands.
Agent Proposed Action: flush_redis_cache(target="*")
│
▼
[ Tool Intent & Schema Validator ] ──(Wildcard * Detected)──► REJECT: HTTP 422
│ (Valid explicit target: cache-prod-useast1)
▼
[ Effect Classification Gate ]
├── READ_ONLY (e.g. get_pod_logs) ──────► Immediate Execution (<= 35 ms)
├── MUTATING (e.g. scale_deployment) ───► Policy Quota Check ──► Execute
└── DESTRUCTIVE (e.g. flush_redis_cache) ─► [ Interactive Step-Up Gate ]
└── Await Operator MFA Signature
### Criteria and weights
| Criterion | Why it matters here | Weight | Source of the weight |
|---|---|---|---|
| Blast Radius & Safety Isolation | Destructive actions executed against wrong clusters can cause unrecoverable multi-region outages. | 0.40 | Sarah Chen (Security Officer) |
| Remediation Triage Speed | Safe read-only diagnostics must dispatch in p95 <= 35 ms to enable fast automated triage. | 0.25 | Marcus Vance (Lead SRE) |
| Parameter Validation Determinism | Catch malformed arguments and wildcard escapes before dispatching to infrastructure APIs. | 0.20 | Cloud Architecture Policy |
| Fail-Safe Degradation | Upstream rate-limiting on cloud APIs must cleanly downgrade to local cached diagnostics. | 0.15 | SRE Reliability Mandate |
### Comparison
| Candidate Strategy | Effect Categorization | Argument Validation Model | Destructive Execution Gate | Residual Outage Risk |
|---|---|---|---|---|
| Option A: Prompt-Only Tool Policy | Natural language system rules | LLM self-checks parameters | Autonomous during P1 emergencies | Critical: Prompt injection or panic-reasoning executes destructive calls. |
| Option B: Broad Namespace Allowlist | Binary (Read vs Write) | Regex allowlist on cluster name | Human approval for all write actions | Medium: Stalls trivial low-risk operations (e.g. scaling from 3 to 4 replicas). |
| Option C: Tripartite Boundary Proxy (Chosen) | `READ_ONLY` / `MUTATING` / `DESTRUCTIVE` | JSON Schema + Wildcard Rejection | Step-up MFA signature on `DESTRUCTIVE` | Minimal: Safely automates reads & low-risk writes while locking destruction. |
### Result
Option C is selected. The tool gateway inspects, validates, and gates all execution proposals before infrastructure API invocation.
---
### Required Mechanisms
#### 1. Tool Catalog & Effect Classification [MC-TC-01]
| Tool Identifier | Subsystem | Effect Class | Reversible | Required Scope / Role |
|---|---|---|---|---|
| `get_pod_logs` | Kubernetes | `READ_ONLY` | Yes | `ops:k8s:read` |
| `query_prometheus` | Monitoring | `READ_ONLY` | Yes | `ops:metrics:read` |
| `describe_ec2` | AWS EC2 | `READ_ONLY` | Yes | `ops:aws:read` |
| `scale_deployment` | Kubernetes | `MUTATING` | Yes | `ops:k8s:scale` |
| `restart_service` | Systemd/K8s | `MUTATING` | Yes | `ops:service:restart` |
| `flush_redis_cache` | Redis | `DESTRUCTIVE` | No | `ops:db:admin:elevated` |
#### 2. Argument Validation & Wildcard Prevention [MC-AV-01]
Every tool call payload is validated against strict Pydantic JSON schemas:
- **Wildcard Prohibition**: Parameters `target_name`, `cluster_id`, and `namespace` must match strict slug pattern `^[a-z0-9-]+$`.
- **Blocked Arguments**: Values `*`, `all`, `%`, and regex patterns are immediately rejected with error code `ERR_TOOL_WILDCARD_PROHIBITED`.
- **Value Bounds**: For `scale_deployment`, `replicas` is bounded between `1` and `10`. Requests exceeding `10` are capped and flagged for human approval.
#### 3. Execution Sandboxing & Effect Boundaries [MC-ES-01]
- **`READ_ONLY`**: Executed with read-only IAM credentials; execution timeout strictly capped at 5,000 ms.
- **`MUTATING`**: Executed only within designated non-prod environments or pre-authorized staging namespaces. In production, mutations check active concurrency quotas (max 1 mutation in flight).
- **`DESTRUCTIVE`**: The routing proxy intercepts invocation, halts turn progression, and issues a challenge ticket to PagerDuty/Slack:
```json
```json
{
"challenge_id": "CHAL-8821a",
"action": "flush_redis_cache",
"target": "cache-prod-useast1",
"requested_by": "CloudOps-Copilot",
"reason": "Memory saturation 98%",
"status": "AWAITING_MFA_CONFIRMATION"
}
Execution remains blocked until an authenticated SRE operator submits a cryptographic confirmation token.
#### 4. Fallback & Degradation Invariants [MC-FD-01]
- If AWS or Kubernetes APIs return HTTP `429 Too Many Requests` or network timeouts:
1. The routing engine halts all mutating and destructive tool calls immediately.
2. Dispatches local cached diagnostic read tools (`get_cached_telemetry`).
3. Emits message to operator: *"Cloud provider APIs are experiencing rate-limiting. Degraded to read-only telemetry triage."*
---
### Invariants and Contracts
No Autonomous Destructive Execution [INV-TR-01]
Tools classified as `DESTRUCTIVE` (e.g. `flush_redis_cache`, `terminate_instance`) must never
execute autonomously, regardless of model confidence or incident severity. Execution requires
an external cryptographic approval token signed by an authorized human operator.
Wildcard Argument Rejection [INV-TR-02]
Tool parameters referencing infrastructure identifiers must reject wildcards (`*`, `all`).
Arguments failing strict alphanumeric regex validation must be rejected with HTTP 422 before API dispatch.
Read-Only Credential Isolation [INV-TR-03]
Read-only diagnostic tools must execute with IAM credentials that lack write and delete
permissions at the AWS IAM and Kubernetes RBAC levels.
## Explicit Unknowns
- Network latency overhead of Slack / PagerDuty webhook callbacks during step-up MFA flows (G-1).
- Rate limits on third-party cloud provider status APIs during simultaneous AWS region incidents (G-2).
## Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| 24 tools in CloudOps catalog | provided | Tool catalog intake | Current |
| Peak 80 triage actions/minute | provided | Traffic profile | Current |
| Routing dispatch latency p95 <= 35 ms | provided | SLA constraint | Current |
| Rejection of autonomous P1 destruction | decided | Sarah Chen (Security Officer) | 2026-09-15 |
| Wildcard target parameter prohibition | decided | Architectural invariant INV-TR-02 | 2026-09-15 |
| Mandatory step-up approval for destructive tools | decided | Architectural invariant INV-TR-01 | 2026-09-15 |
## Verification
No validator was supplied, so no command was run.
Reviewer self-check against tool routing contracts:
- **Effect Categorization**: PASS. All 24 tools mapped to `READ_ONLY`, `MUTATING`, or `DESTRUCTIVE`.
- **Validation Guard**: PASS. Rejects `*` and wildcard regex parameters before reaching cloud APIs.
- **Human Gating**: PASS. Hard programmatic gate halts destructive actions pending MFA signature.
- **Latency Compliance**: PASS. Pre-parsed schema validation and routing table lookup executes in ~12 ms.
## Open Decisions
- `DEC-TR-01`: Sarah Chen to determine whether `scale_deployment` to 0 replicas should be reclassified from `MUTATING` to `DESTRUCTIVE` (Owner: Sarah Chen).
## Next steps
1. SRE team deploys tool routing gateway proxy in `services/cloudops/tool_gateway.py`.
2. Security team configures IAM roles ensuring read-only tools operate on read-only AWS credentials.
3. Integrate Slack Interactive Action buttons for step-up confirmation on `DESTRUCTIVE` challenge tickets.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
What it does
This skill maps one task/intent/workflow step to an eligible accepted tool capability, validates a proposed invocation, dispatches through a typed adapter contract and preserves result/effect evidence. It does not invent tools, permissions, retry policies or treat schema validity as authorization.
Use it when
Use when multiple accepted tool capabilities can serve runtime intents and one bounded routing/effect contract is required.
For example: “The assistant has 60 tools. It keeps calling search_orders when the user asks about deliveries, and cancel_order fired once when someone asked how to cancel.”
What you get
- Tool Routing Specification
Written as Markdown to <your output folder>/architecture/tasks/<run-id>/tool-routing-design/.
What it will not do
Do not use for tool/API/MCP architecture, registry or adapter implementation, generic function-calling loops, agent/workflow design, IAM/sandbox/guardrail design, one explicit tool call or provider/framework selection.
How it works
- Check the model needs to choose.
- Write each tool description for the decision, not for the docs.
- Make the schemas discriminating.
- Define validation before dispatch.
- Specify what a result tells the model.
- Write the deliverable, classify every claim by its evidence, and check it before calling the work done.
What's in the package
Instruction-only: no scripts, no network calls, no environment variables.
- LICENSE.txt
- SKILL.md
- agents/openai.yaml
- assets/output-template-task.md
- references/domain-rules.md
- references/operating-rules.md
- references/output-contract.md
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 12 days ago
- Passed all security checks, Safe to install