article research

Programmatic tool calling: pattern and Prime Agent

Programmatic tool calling lets an agent compose, invoke, and process tools through code rather than a fixed JSON schema. Prime Agent's model-facing tool is a persistent IPython kernel: file edits, shell commands, skills, and subagent calls are ordinary Python calls. This differs from provider-native function calling and inherits the kernel's trust boundary.

v v0.7.1reviewed 2026-08-09evidence officialsources S001, S008, S033cutoff 2026-08-09
Home

First-party announcement, documentation, release, or installer.

Generic pattern

Programmatic tool calling lets an agent compose, invoke, and process tools through code rather than a fixed JSON schema. Prime Agent's model-facing tool is a persistent IPython kernel: file edits, shell commands, skills, and subagent calls are ordinary Python calls. This differs from provider-native function calling and inherits the kernel's trust boundary.

  • S001 supports the route's current claim set.
  • S008 supports the route's current claim set.
  • S033 supports the route's current claim set.

Persistent Python

Programmatic tool calling lets an agent compose, invoke, and process tools through code rather than a fixed JSON schema. Prime Agent's model-facing tool is a persistent IPython kernel: file edits, shell commands, skills, and subagent calls are ordinary Python calls. This differs from provider-native function calling and inherits the kernel's trust boundary.

  • S001 supports the route's current claim set.
  • S008 supports the route's current claim set.
  • S033 supports the route's current claim set.

Host requests

Programmatic tool calling lets an agent compose, invoke, and process tools through code rather than a fixed JSON schema. Prime Agent's model-facing tool is a persistent IPython kernel: file edits, shell commands, skills, and subagent calls are ordinary Python calls. This differs from provider-native function calling and inherits the kernel's trust boundary.

  • S001 supports the route's current claim set.
  • S008 supports the route's current claim set.
  • S033 supports the route's current claim set.

Security and cost trade-offs

Programmatic tool calling lets an agent compose, invoke, and process tools through code rather than a fixed JSON schema. Prime Agent's model-facing tool is a persistent IPython kernel: file edits, shell commands, skills, and subagent calls are ordinary Python calls. This differs from provider-native function calling and inherits the kernel's trust boundary.

  • S001 supports the route's current claim set.
  • S008 supports the route's current claim set.
  • S033 supports the route's current claim set.