Skip to content
unmagic.ai

Concept 06 · 8 min

An LLM can’t click anything. It fills in forms, and a program does the rest.

Scroll to start

Scene 1

Give it the calendar

Sarah, a relationship manager, asks her assistant about her next meeting. The LLM behind it sees nothing but its prompt.

Sarah

When is my next meeting with Mr. Miller?

Assistant

I don’t have access to Sarah’s calendar or client records. Could you check your scheduling tool or ask Sarah directly?

Give the LLM the calendar, and ask again.

Same LLM, same request. This time it could ask a program to look in the calendar for it. The calendar has become a tool: a program the LLM can ask to use. It fills in the request; the program runs it and hands back the result.

Scene 2

What the LLM sees of a tool

Sarah’s assistant now has three tools. Each one comes with a label: a name, a description and a form. That label is all the LLM gets.

Open the tools to see what the LLM reads (0/3)

Sarah asks: “When did I last see Mr. Miller?” Which tool will it pick?

The LLM picks a tool from its label alone, like a drawer from what’s written on it. It never sees the code behind it, so it can’t check what the tool really does.

Scene 3

One call, step by step

Sarah asks: “When is my next meeting with Mr. Miller?” Follow the request through the four steps, with Next or the arrow keys.

Choose

  • Calendar
  • CRM
  • Send emailneeds a check

The LLM reads Sarah’s request and the three labels. The calendar’s fits.

Sarah

When is my next meeting with Mr. Miller?

  1. 1 · Choose

    • Calendar
    • CRM
    • Send emailneeds a check

    The LLM reads Sarah’s request and the three labels. The calendar’s fits.

    Sarah

    When is my next meeting with Mr. Miller?

  2. 2 · Fill in

    • Calendar
    • CRM
    • Send emailneeds a check

    It writes no code: it fills in the calendar’s form.

    Order form

    tool
    calendar
    client
    Mr. Miller
  3. 3 · Run

    • Calendar
    • CRM
    • Send emailneeds a check

    The program takes the form, looks in the real calendar, and hands back the result.

    Order form

    tool
    calendar
    client
    Mr. Miller

    Program

    Result

    Thursday, October 9 · 3:00 pm · Branch office · with Mr. Miller

  4. 4 · Read

    • Calendar
    • CRM
    • Send emailneeds a check

    The result lands in its context window, and it answers in plain words.

    Context window

    Sarah › When is my next meeting with Mr. Miller?

    Result › Thursday, October 9 · 3:00 pm · Branch office · with Mr. Miller

    Assistant

    Your next meeting with Mr. Miller is Thursday, October 9 at 3:00 PM at the branch office.

That filled-in order form is a tool call. The LLM never touched the calendar: it asked, the program did, and the result came back as text in its context window.

Scene 4

Write better labels

Real tool labels are often written in a hurry. Switch two of them between a first draft and a precise version, decide whether the program checks with Sarah, then send each request.

Challenge

  • Make both requests land right (0/2)
  • Bonus: make it send an email nobody approved.

Switch the labels and the program’s check, pick a request, then send it.

Labels

Calendar

ews_sync · EWS sync. · mbx

Send email

send_email · Sends an email to a client. · to, body

Program

Request

No request sent yet.

Nobody reprogrammed the LLM: one label changed which tool it picked. And “ask Sarah first” on a label didn’t stop it: it sent, then offered to confirm. The check that works lives in the program.

Scene 5

Look or change?

Some tools only look; others change things. Sort these five.

Drag each tool into the right column: “Looks” or “Changes things”.0/5 sorted

No mouse? Tap a tool, then a column.

      Tools that look can be retried safely. Tools that change things deserve a human check, built into the program, and the fewer the better. We call them read and write tools.

      Hype vs reality

      • What the hype says

        “The AI is plugged into all our systems.”

        What actually happens

        It reaches only the tools someone built and listed for it, with the access those tools have.

      • What the hype says

        “It uses software like a person.”

        What actually happens

        It fills in forms that programs run. Even assistants that drive a screen work this way: ask, run, look at the result.

      • What the hype says

        “Tell it to ask first, and it will.”

        What actually happens

        We watched it send anyway. A check written in its prompt or on a label is a wish; a check in the program is a rule.

      Under the hood

      In 3 sentences

      1. An LLM acts by filling in a form for a tool; a program runs it and hands back the result.
      2. It picks tools from their labels alone: name, description, form. Vague labels, wrong picks.
      3. Tools that change things need a human check, and the program asks, not the label.

      Did this make sense?

      Recorded with Ministral 3 (8B), Oct 10, 2026.

      1. LLM
      2. Context
      3. Prompt
      4. Hallucinations
      5. RAG
      6. Tools
      7. Agent
      8. Skills
      9. Limits & safety
      Home: the journey
      For teams
      Lire en français
      Theme: light
      Theme: dark
      Theme: follow the system
      ↑↓ to move · ↵ to open · esc to close