AI 中文总结
该研究针对大语言模型智能体的工具调用问题,提出以智能体为核心的工具设计AFT机制,并构建受控接口干预框架AFT-Bench,探究工具接口暴露与智能体安全操作的关系。
AI 中文摘要
工具调用可能完全有效,但仍会导致自主智能体无法确定下一步行动。例如,若外部效果已提交但其响应丢失,即使需要不同的后续操作,智能体也可能无法区分已提交和未提交的状态。我们研究可调用性与可操作性之间的差距:工具接口是否暴露了智能体在操作不确定性下安全继续所需的与动作相关的状态和语义。我们通过Agent-First Tooling(AFT,以智能体为核心的工具设计)将工具可操作性落地,这是一套涵盖选择性能力发现、执行生命周期与恢复、显式外部效果语义、机器可读结果及后置条件验证的接口机制。我们引入AFT-Bench,这是一个受控接口干预框架,在保持任务、后端、初始状态、注入故障、智能体及语言模型固定的同时,改变暴露给智能体的接口。
英文摘要
A tool call can be perfectly valid yet still leave an autonomous agent unable to determine what to do next. For example, if an external effect commits but its response is lost, committed and uncommitted states may become indistinguishable to the agent even though they require different continuation actions. We study this gap between callability and operability: whether a tool interface exposes the action-relevant state and semantics needed for an agent to continue safely under operational uncertainty. We operationalize tool operability through Agent-First Tooling (AFT), a set of interface mechanisms spanning selective capability discovery, execution lifecycle and recovery, explicit external-effect semantics, machine-readable results, and postcondition verification. We introduce AFT-Bench, a controlled interface-intervention framework that holds the task, backend, initial state, injected failure, agent, and language model fixed while varying the interface exposed to the agent.