Agent
An agent puts an LLM in a loop with tool access, letting it decide autonomously which tools to call and in what order to accomplish a multi-step goal.
An agent puts an LLMLLM (Large Language Model)An LLM is a large transformer trained to predict the next token on massive text corpora, then fine-tuned to follow instructions — the architecture behind GPT, Claude, Gemini, and Llama. in a loop with access to tools, letting it decide — autonomously, from one step to the next — which tools to call and in what order to accomplish a goal, rather than answering in a single request/response turn. Each step's tool result feeds back into the model's context to inform the next decision, until the model determines the goal is achieved. Practical agent systems add guardrails (step limits, confirmation before high-stakes actions) since errors can compound across a chain of steps.
How it works
The loop is mechanically simple. The application sends the model a
system prompt, the conversation so far, and a list of tool schemas —
name, description, and a JSON Schema for the arguments. The model
replies either with ordinary text or with a structured tool call. The
application executes that call itself, appends the result to the
message list as a tool role message, and calls the model again. The
model never runs anything; it only emits requests. Everything the agent
"knows" at step n is whatever is in that growing message list, so
the loop is really an exercise in context management: what to append
verbatim, what to summarise, and what to drop. Stopping is a policy
decision — a final text answer, a done tool, or a hard step cap.
When it breaks
- Error compounding. Each step conditions on the last, so one bad tool result or misread output steers every later decision. A 95% per-step success rate is about 60% over ten steps.
- Context exhaustion. Raw tool output — file dumps, HTML, long logs — fills the window fast, and truncating it silently drops the evidence the model needs, which invites hallucinationHallucinationA hallucination is a confidently stated, fluent LLM output that is factually wrong, a direct consequence of models being trained to produce plausible text rather than verified facts..
- Loops and thrash. Agents retry a failing call with cosmetic variations instead of changing approach. Step caps and repeated-call detection are load-bearing, not optional.
- Cost and latency scale with steps. Every step is a full inferenceInferenceInference is using a trained model to generate output, as opposed to training — for LLMs, an inherently sequential, token-by-token process with its own performance engineering. pass over a longer prompt, so cost grows worse than linearly.
See also: RAGRAG (Retrieval-Augmented Generation)RAG grounds an LLM's answers in retrieved documents at request time, letting it answer questions about private or current data without retraining., MCPMCP (Model Context Protocol)MCP is an open standard, introduced by Anthropic, for how applications expose tools and data to LLMs, so a tool built once can be reused across different LLM apps., LLMLLM (Large Language Model)An LLM is a large transformer trained to predict the next token on massive text corpora, then fine-tuned to follow instructions — the architecture behind GPT, Claude, Gemini, and Llama.
Learn more: Agents & Tool Use
Mentioned in
Lessons where this comes up in context.
- Agents & Tool UseGiving an LLM the ability to take actions and chain multiple steps together — tool use, MCP, and the agent loop
- AI Safety & AlignmentWhether a model's own objectives match what we actually want, independent of any attacker — specification gaming, outer vs. inner alignment, why RLHF isn't a complete answer, and scalable oversight
- AI SecurityAdversarial misuse of a deployed AI system — prompt injection, jailbreaks, data exfiltration via tool use, adversarial examples, and the red-teaming practice that hunts for all of them
- Applied & Agentic SystemsHow prompting, RAG, and agents combine to turn a single trained LLM into a real, capable application
- Prompt EngineeringShaping an LLM's output by changing the input alone — few-shot examples, chain-of-thought, and system prompts — with no training involved
- RAG & Vector DatabasesRetrieval-augmented generation grounds an LLM's answers in retrieved text at request time — and the vector databases and similarity search that make it work
- Reinforcement LearningMDPs, reward, policy and value functions, Q-learning — the third major ML paradigm, and the actual mechanism behind RLHF
Prompt Engineering
Prompt engineering shapes an LLM's output by changing the input phrasing alone — via few-shot examples, chain-of-thought, or system prompts — with no training involved.
MCP (Model Context Protocol)
MCP is an open standard, introduced by Anthropic, for how applications expose tools and data to LLMs, so a tool built once can be reused across different LLM apps.