Memory hook: Validate every tool; bound every loop.
Must remember
- Function calling proposes structured arguments; application code authorizes, validates and executes the operation. Check both input and tool-result schemas and reject unsafe or malformed requests.
- MCP servers/clients expose supported tools and resources; A2A connects agent systems. Authentication, user consent, tenant isolation and network policy remain application responsibilities.
- Functions, Logic Apps and API Management can expose controlled capabilities. Use allowlisted operations, scoped identities, timeouts, idempotency keys and explicit error contracts.
- Agent Framework, LangGraph/LangChain and other frameworks express orchestration differently; select by required state, branching, integration and operational support. Hugging Face Transformers supplies model capabilities rather than automatically solving workflow governance.
- Implement approval, override and escalation as explicit states. Cap spawned agents, concurrency, token use, retries and elapsed time; cancel downstream work when the parent workflow stops.
- Prompt caching, response caching and semantic caching cache different things. Include model/prompt version, tenant/access context and relevant freshness in cache design; do not reuse a private answer across users.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| A tool retries after a network timeout | Use a stable idempotency key and inspect whether the action already succeeded. |
| A semantically similar query comes from another tenant | Re-evaluate authorization; do not return a shared cached private response. |
Traps
- MCP discovery does not authorize unrestricted execution.
- Parallelism can exceed model/API quotas and make the whole workflow slower.
Active recall
1. What should a tool error contract distinguish?
Retryable failures, permanent errors, partial completion and authorization denial.
2. Why use middleware?
To apply consistent logging, authorization and exception handling across agent/tool calls.
3. What is semantic caching?
Reusing results based on meaning similarity, subject to correctness, freshness and access constraints.
4. How avoid endless agent handoffs?
Clear ownership, termination criteria and bounded depth/time budgets.
5. Why validate tool results?
They may be malformed, stale, malicious or inconsistent with the expected operation.