Which specific operation to execute
Executed by actual programs
Then verify if the operation meets the criteria
Tool: A specific capability that a system can invoke, such as searching, reading files, computing, or generating files.
From "Saying You'll Do It" to Actually Executing
When a model says "I'll calculate that," it's a response; calling a computing capability to get results involves actual execution. Reading files, generating presentations, and rendering pages are each specific operations.
Tools may be built into the application, or connected through other interfaces or MCP services. Not every tool needs to use MCP.
Understanding Capabilities Through a PPT Task
| Tool Capability | Observable Result |
|---|---|
| Read material | Returns original text, data, or a read error |
| Create file | Generates an openable PPTX, or reports generation failure |
| Render page | Produces an actual image or preview |
Writing a filename does not equal file generation; successful rendering does not equal accurate content. Each layer should be checked against its corresponding result.
Verify Before and After Use
Before the operation: check whether the tool is connected, whether parameters are correct, and whether the necessary permissions exist. After the operation: check whether the return is success, partial results, or an error, then decide on the next step.
For example, a course query requires a valid course ID. If the response is "Course not found," verify against the directory—don't treat an error as successfully read material. The Agent needs to adjust its actions based on such responses.
Tools Also Have Boundaries
A tool's name and description indicate its purpose, but cannot guarantee continuous availability. Runtime environment, account scope, input format, or service status may all affect execution.
"Read-only" should be enforced through implementation and environmental restrictions; writing "read-only" in a description does not provide operating-system-level isolation. Reading, modifying, and sending are different actions—judge the scope based on the actual task.
Going a Step Deeper
Common invocations include the tool name, parameters, and return value. The model may propose an invocation intent, while the application or environment handles execution. The return value then enters the context, influencing subsequent decisions.
Next Steps
Read Permissions, or see a real tool invocation in MCP Usage Example.
Reflect
The "Can generate PPT" tool invocation returns an error, but the model provides a filename. Was file generation completed?
Reference judgment: No; there must be a successful execution result and an openable file—the filename is just text.
Sources and Scope of Application
Referenced OpenAI · Using tools, MCP · Tools. Technical accuracy verified on 2026-09-09; examples and instructional organization are authored by this site. Specific product support scope and operation methods should be verified separately; this article makes no cross-product feature commitments.