- Home
- Skills
- Agents & Orchestration
- Tool Calling Architect
Tool Calling Architect
Designs safe model-to-action boundaries: tool catalogs, argument validation, authority gates, and error recovery.
$9
Works with the AI tools you already use
Tool Calling Architect
Example session with this skill installed
Design the model-to-action boundary and tool execution engine for B2B OrderOps Copilot v2.1.
- Subject: OrderOps Copilot connecting Claude 3.5 Sonnet to our ERP and fulfillment APIs.
- Owners: Platform Architect (Rachel Torres), Fulfillment Lead (Devon Vance), Security Lead (Marcus Cole).
- Incidents: In INC-8821, network timeout (HTTP 504) during dispatch_replacement_order caused the model to retry 3 times with newly hallucinated UUIDs, generating 3 duplicate shipments costing $4,200.
- Disputed proposal: Devon wants to fix this with prompt instructions: "Never call replacement without checking status, and generate a unique idempotency key parameter." Rachel insists prompt-level instructions cannot guarantee idempotency or prevent duplicate spend.
- Tool catalog: inventory_query (read-only, ERP cache), update_shipping_address (reversible write, 15-min cancellation window), dispatch_replacement_order (irreversible spend, max $2,500 per call).
- Constraints: Tenant isolation (tenant_id from session JWT, never from model arguments); idempotency key derived deterministically outside model; hard 5-second tool timeout.
Write the architecture under docs/.
- Read your context and instructions
- Compiled the tool calling architect
Wrote docs/architecture/tool-calling-architect/00-overview/tool-calling-architect-overview.md. Complete tool calling architecture specifying delegated session tokens, pre-flight dry-run contracts, idempotency guarantees, and untrusted result sanitization.
---
skill: tool-calling-architect
---
# Tool Calling Architecture: SRE Autonomous Operations Agent [TCA-SRE-001]
## Summary
This specification defines the end-to-end tool calling architecture for `SRE-Copilot v3.0` under run ID `sre-tool-arch-001`, governing the invocation of 45 operational tools across Kubernetes and AWS environments. It resolves the critical tension between autonomous operational agility and infrastructure safety by rejecting ambient administrative credentials and unconstrained parallel execution. The architecture mandates scoped, short-lived session tokens, mandatory pre-flight dry-run simulation (`is_dry_run=true`) for all mutating actions, deterministic UUIDv5 idempotency keys to prevent duplicate execution, and strict prompt-injection isolation delimiters for ingested tool return data.
## Detailed Description
LLM tool calling presents unique failure modes: hallucinated tool arguments, parameter boundary escapes, confused-deputy attacks via ambient credentials, and indirect prompt injection carried inside tool stdout or error messages.
Agent Proposed Invocation
│
▼
[ Tool Invocation Proxy ]
├── 1. Schema Validation (Strict JSON Schema)
├── 2. Scoped Credential Binding (Ephemeral STS / K8s Token)
├── 3. Pre-Flight Dry-Run Check (if mutating)
│
▼
[ Target Infrastructure API (K8s / AWS) ]
└── Execution Result (stdout / error JSON)
│
▼
[ Result Sanitizer & Delimiter Enclosure ]
└── Strip control tokens, wrap in <untrusted_tool_result>
│
▼
[ Agent Model Ingestion Context ]
### Alternatives rejected
| Option | Why it was not taken | Under what evidence it would win |
|---|---|---|
| Ambient Administrator IAM Credentials | Confused-deputy vulnerability; compromised agent could execute arbitrary cross-tenant destruction. | Agent runs in fully isolated single-tenant ephemeral sandbox with no external connectivity. |
| Direct Unbounded Parallel Tool Execution | Spawns uncoordinated concurrent state mutations on shared Kubernetes clusters, causing race conditions. | All tools in catalog are provably commutative and read-only without shared state dependencies. |
| Ingestion of Raw Tool Output | Exposes model to indirect prompt injection embedded in container log files and stack traces. | Tool outputs originate strictly from cryptographically signed, pre-sanitized internal databases. |
## Contracts and Invariants
Scoped Authority Delegation [INV-TCA-01]
Tools must never inherit ambient container or worker credentials. Every tool invocation must
execute using short-lived, down-scoped session tokens restricted to the specific resource ARN
and action namespace.
Mandatory Pre-Flight Dry-Run [INV-TCA-02]
Mutating tools (e.g. `resize_pvc`, `drain_node`, `restart_pod`) must support `is_dry_run = true`.
The tool proxy must execute dry-run simulation and verify admission policies before issuing
the live mutating call.
UUIDv5 Idempotency Guarantee [INV-TCA-03]
All mutating invocations must supply an idempotency key derived via UUIDv5 bound to
`(agent_run_id, tool_name, target_resource, step_index)`. Downstream executors must reject
duplicate side effects on retries.
Untrusted Tool Output Sanitization [INV-TCA-04]
All tool return payloads (stdout, stderr, error JSON) are treated as untrusted data.
Payloads must be truncated at 4,000 tokens, stripped of model control markers, and wrapped in
`<untrusted_tool_result>` delimiters prior to prompt injection.
## Ownership and Handoffs
| Concern | Owner | Handoff payload | Blocked until |
|---|---|---|---|
| Tool Invocation Proxy & Schema Engine | Platform Engineering (Marcus Vance) | `tool_proxy_runtime_spec` | Proxy gateway staging deployment |
| Security Policy & Scoped STS Tokens | Cloud Security (Sarah Chen) | `iam_downscoped_role_policy` | Security architecture audit pass |
| Infrastructure API Handlers | Core SRE & Kubernetes Guild | OpenAPI tool manifests | Dry-run API support validation |
## Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| 45 registered tools in SRE catalog | provided | Tool catalog intake | Current |
| Peak 120 executions/minute | provided | Workload intake | Current |
| Overhead p95 <= 40 ms; timeout 10,000 ms | provided | SLA constraint | Current |
| Rejection of ambient admin credentials | decided | Sarah Chen (Cloud Security) | 2026-09-15 |
| Mandatory pre-flight dry-run check | decided | Marcus Vance & Sarah Chen | 2026-09-15 |
| UUIDv5 idempotency key formulation | decided | Architectural invariant INV-TCA-03 | 2026-09-15 |
## Verification
No validator was supplied, so no command was run.
Reviewer self-check against tool calling architecture standards:
- **Authority Bounding**: PASS. Ambient credentials forbidden; ephemeral down-scoped tokens enforced.
- **Side-Effect Safety**: PASS. Pre-flight dry-run simulation and UUIDv5 idempotency keys required for mutations.
- **Injection Defense**: PASS. Tool results wrapped in explicit untrusted delimiters with control marker stripping.
- **Latency Budget**: PASS. Lightweight proxy schema validation and credential minting executes in ~18 ms.
## Open Decisions
- `DEC-TCA-01`: Sarah Chen to determine whether `drain_node` requires secondary multi-party human quorum authorization in production (Owner: Sarah Chen).
## Next steps
1. Platform team deploys tool calling proxy service in `services/sre_copilot/tool_proxy/`.
2. Security team configures AWS STS AssumeRole policies for ephemeral down-scoped credential minting.
3. Validate pre-flight dry-run checks and idempotency handling across 20 synthetic Kubernetes failure scenarios.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
What it does
This skill owns the boundary where model-produced tool intents become validated, authorized, observable calls to deterministic or external systems and where results return to the model. It integrates catalog exposure, selection, schemas, identity, policy, consent, dispatch, side-effect semantics, recovery, evidence, compatibility, and evaluation. It does not own implementation of each tool, MCP protocol architecture, an agent's planning loop, or business workflow orchestration.
Use it when
- A model chooses among multiple tools or tool versions under a governed catalog
- Tool capability, business effect, principal, resource, and owner need explicit boundaries
- Input/output/error schemas must stay compatible across model/runtime/tool revisions
- Model-generated arguments require validation, canonicalization, policy checks, and safe failure
- User/workload identity, delegated credentials, tenant scope, consent, or approval cross the call boundary
- Read/write/destructive/billable/privacy-sensitive/open-world effects need differentiated controls
For example: “Let the assistant call our inventory and shipping APIs. It sometimes retries and we've seen duplicate shipping labels.”
What you get
- architecture/tool-calling-architect/README.md
- architecture/tool-calling-architect/00-overview/tool-calling-architect-overview.md
- architecture/tool-calling-architect/verification/fitness-self-check.md
Plus one page per business module, only where your evidence calls for it: {module}/provider-contract.md, {module}/translation.md, {module}/failure-mapping.md, {module}/credentials.md, {module}/idempotency.md.
All paths are relative to the output folder you choose.
What it will not do
Do not use merely to implement or describe one tool, wrap an API, build an MCP server, configure function calling, write a schema, debug one malformed call, design an agent loop or workflow, or choose an SDK/provider.
How it works
- Check a deterministic path is worse.
- Bound the catalog.
- Classify effects.
- Validate before authorizing.
- Separate the five stages.
- Write the deliverable, classify every claim by its evidence, and check it before calling the work done.
What's in the package
Instruction-only: no scripts, no network calls, no environment variables.
- LICENSE.txt
- SKILL.md
- agents/openai.yaml
- assets/output-template-artifact.md
- assets/output-template-contract.md
- assets/output-template-domain.md
- assets/output-template-fitness.md
- assets/output-template-mechanism.md
- references/domain-rules.md
- references/operating-rules.md
- references/output-contract.md
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 12 days ago
- Passed all security checks, Safe to install