{
  "id": 11431915,
  "title": "Lean Agents: Decide What Your Agent Can Reach Before It Runs",
  "url": "https://urgent.news/2026/10/02/lean-agents-decide-what-your-agent-can-reach-before-it-runs",
  "topic": "ai",
  "section": "AI",
  "published": "2026-10-02T12:05:04.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/_firelinks/lean-agents-decide-what-your-agent-can-reach-before-it-runs-16h5"
  },
  "original_language": "en",
  "account": "The cost and permission aspects of an agent are determined by the tools it connects to. Each tool provides a name, description, JSON Schema for input, and the client typically shares these definitions with the model. A study by Anthropic shows that using tools from five servers such as GitHub, Slack, Sentry, Grafana, and Splunk took about 55,000 tokens before the conversation even began (Anthropic engineering).\n\nThe permission side is straightforward: if a tool is listed, the model can choose to use it. To manage access, an agent should have its own sandbox environment with only the access granted, employing a zero-trust approach within the system. Two other controls include creating a per-task tool allowlist, choosing specific server and tool permissions, and setting a run budget with limits on tool calls, total tokens, and wall clock timeout.\n\nMonitor each tool call during the agent's operation, recording arguments and results to detect any potential missteps. The established MCP spec suggests logging tool usage for auditing, implementing timeouts, and rate-limiting tool invocations (MCP tools specification). By following these steps, you can identify issues and make necessary adjustments.",
  "summary": "Every tool you connect to an agent is two things at once: tokens the model reads on every run, and an action the model can take. So the same inventory answers your cost question and your permission question. I start every agent with that inventory, and with nothing connected that the task doesn't need. I talked through this with Tom Smith on CoderLegion's Developer Stories ( video , from 9:46).…",
  "key_points": [
    "Agents' capabilities determined by connected tools",
    "Tool usage incurs token cost, monitored during operation",
    "Zero-trust sandbox, tool allowlist, and run budget controls"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}