I-D Action: draft-das-agentic-tool-binding-00.txt
| Newsgroups | gmane.ietf.announce |
|---|---|
| Message-ID | <178780090294.834836.6820963936421603255@dt-datatracker-786f84c586-vck88> |
Internet-Draft draft-das-agentic-tool-binding-00.txt is now available. Title: tool_use Is Not invoke(): Binding Execution-Finality to Claude, ChatGPT, and MCP Author: Sangam Das Name: draft-das-agentic-tool-binding-00.txt Pages: 22 Dates: 2026-08-26 Abstract: Frontier runtimes already standardized the dangerous moment. Claude emits a tool_use block. ChatGPT emits tool_calls. MCP emits tools/ call. The host then invokes whatever name and arguments the model printed. Alignment, allowlists, and OAuth sit around that moment. They do not sit on it. If the block is treated as a capability, prompt-injected mail, a poisoned retrieval, or a stolen enterprise seat becomes an external act with a 200 from the tool. This document does not invent another assistant API. It binds the Agent Candidate Act profile [I-D.das-agentic] onto the three interfaces those labs and their customers already ship: Anthropic tool_use / computer_use, OpenAI function calling and Responses tools, and Model Context Protocol tools/call. The model may emit the block. The block remains non-effective. A local enforcer builds the act, binds the argument digest, and refuses invoke() until scoped authority is verified and consumed at the dispatch sink. The implementation target is a middleware function that a host loop can call without changing the model vendor. tool_use is not invoke(). The IETF datatracker status page for this Internet-Draft is: https://datatracker.ietf.org/doc/draft-das-agentic-tool-binding/ There is also an HTML version available at: https://www.ietf.org/archive/id/draft-das-agentic-tool-binding-00.html Internet-Drafts are also available by rsync at: rsync.ietf.org::internet-drafts _______________________________________________ I-D-Announce mailing list -- [email protected] To unsubscribe send an email to [email protected]