When an Agent Can Reach Out
An agent gets truly powerful the moment it can use tools — run code, read the web, query a database — instead of only writing text. This lesson is about the tools you can hand it, and how to think about them.
The Tool Families
Most of what an agent can reach falls into a handful of families.
- The CLI / shell — run commands on your machine
- Code execution / sandboxes — run and test code safely
- MCP — a standard way to connect tools and data sources
- File editing — read and write files directly
The Sandbox
A sandbox lets the agent run code in an isolated environment — so it can test its own work without any risk to your real system or files.
MCP in One Idea
Instead of writing custom glue for every single tool, MCP is a common plug — so an agent can reach many tools and data sources the same way.
- Without it — a bespoke integration per tool, each one different
- With it — one shared standard the agent already speaks
- The payoff — add a new data source without teaching the agent a new dialect
Power Cuts Both Ways
More tools means more capability — and more to secure. Every tool the agent can reach is also something that can go wrong. Give an agent only the tools a task actually needs.
Build It
How to implement: identify one external thing your tool needs the agent to reach — run tests, read a file, call an API — and note whether a built-in tool or an MCP connection provides it.
- Weekly AI Tasks tracker — the agent may use the shell to run the server and tests; at runtime your app calls the LLM and messaging APIs (tools for the app, not the agent).
- Personal brand site — the agent mostly needs file editing and a local preview; keep its toolset small.
What you learned
Tools turn a text generator into an agent that acts: the shell, sandboxes, MCP, and file editing. MCP is the common plug for the rest — and every tool you add is one more thing to secure, so keep the set small.