Tool schemas, validation, and tool errors
By the end of today you can treat tool arguments as untrusted input, decide which tools need approval before running, and return errors the model can actually recover from.
YesterdayOn Day 37 you learned to validate at trust boundaries. On Day 38 you learned to check ownership, not just identity. Both apply here, doubly.
TomorrowTomorrow the loop arrives, and every weakness here gets executed repeatedly.
Why this matters
A tool call is a request from a probabilistic system to run code in yours. Everything you learned about trust boundaries applies, with the added twist that the caller can be manipulated by whatever text it just read.
- Tool schemas
- Validating tool arguments
- Tool permissions
- Tool errors
Learn it
70 minCopy this into Claude or ChatGPT. It quizzes you before it explains anything, which is deliberate. The resources under it are how you check what it told you.
Today's Master Prompt
Free · sign inA prompt written for this day alone: your level, the exact scope, what to leave out, and an instruction to quiz you before it explains anything. Paste it into Claude or ChatGPT and it teaches you today's material.
Check it against something that is not a model
An assistant can be fluent and wrong, and on a topic you met today you will not catch it. These cover the same ground and were made by people who do this for a living, so they are what you hold the explanation up against. They are other people's work and we only link to them, so judge them for yourself.
3 hand-picked resources
Free · sign inVideos, official docs and articles covering the same ground, each opened and annotated by hand. They are what you check the assistant against on a day you cannot yet catch it being wrong.
Build it
50 minTake yesterday's tools and harden them. Constrain the schemas so damaging arguments cannot be expressed. Add authorization inside each tool that acts as a specific user. Return a structured error rather than raising, and confirm the model adapts. Then try to make the model call a tool with arguments it should not be able to produce.
Recall it
25 minAnswer out loud, reveal, then mark honestly whether you had it. That score is the only thing on this page you do not get to choose.
5 recall questions
Free · sign inQuestions you answer from memory, then grade yourself against the real answer. The score is carried into the mastery rating below it, so an honest miss cannot quietly become a tick.
Rate it
Completion and mastery are tracked separately. Be honest, because an inflated rating only means the concept resurfaces sooner.
Mastery tracking
Free · sign inRate yourself against five named criteria per concept. Completion and mastery are tracked separately, and anything you rate shakily comes back automatically on a spaced schedule.
Recap
- 01A tool call is untrusted input from a system that can be influenced by text
- 02Authorization belongs in the tool; a prompt instruction is not a control
- 03Return errors to the model so it can adapt, without leaking internals
- 04Classify tools by reversibility and gate the irreversible ones
Your progress
Free · sign inMark days complete, pick up where you left off across devices, and watch completion and mastery diverge. Free, and the account exists only so ninety days of work cannot vanish with a cleared browser.