错误处理与安全的工具执行
通过优雅地处理失败、验证输入并限制自主执行期间工具可以执行的操作,让代理工具更加健壮和安全。
错误处理与安全的工具执行 是 CoddyKit 上的免费 AI Agents with LangChain & Autonomous Workflows 课时。 这是第 4 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 AI Agents with LangChain & Autonomous Workflows 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 AI Agents with LangChain & Autonomous Workflows 课程共包含 4 节课。
本课时的部分内容尚未翻译,以英文显示。
Tools Will Fail
Agents call external tools: APIs, databases, shells. These time out, return errors, or behave unexpectedly. An agent that crashes on the first failure is useless in production.
This lesson covers making tool execution safe and resilient.
Returning Errors as Observations
Instead of throwing, a tool should return the error as a message the agent can read. This lets the agent reason about the failure and try another approach.
def search(q):
try:
return api.search(q)
except Exception as e:
return 'ERROR: search failed: ' + str(e)Validating Tool Inputs
LLMs sometimes pass nonsense arguments. Validate inputs before acting, so a malformed query never reaches a real system.
def get_user(user_id):
if not str(user_id).isdigit():
return 'ERROR: user_id must be numeric'
return db.fetch(user_id)Timeouts and Retries
Wrap slow tools with a timeout and retry transient failures a bounded number of times. Without limits, an agent can hang or loop forever.
for attempt in range(3):
try:
return call(timeout=5)
except Timeout:
continue
return 'ERROR: timed out after 3 attempts'The Danger of Powerful Tools
A tool that runs shell commands or executes SQL can do real damage if the agent is tricked or confused. Power must be paired with constraints.
Least Privilege
Give each tool only the access it needs. A read tool should not be able to write. A query tool should use a read-only database role.
# read-only DB connection for the query tool
conn = connect(user='reader', readonly=True)Allowlists over Blocklists
Trying to block every dangerous action is a losing game. Instead, permit only an explicit set of safe operations and reject everything else by default.
ALLOWED = {'read_file', 'list_dir', 'search'}
if action not in ALLOWED:
return 'ERROR: action not permitted'Human-in-the-Loop Approval
For high-impact actions like sending money or deleting data, pause and require human confirmation before executing. The agent proposes; a person approves.
if action.is_destructive:
return await request_human_approval(action)Preventing Infinite Loops
Agents can get stuck retrying the same failing tool. Cap the number of steps and detect repeated identical actions, stopping with a clear message instead of burning tokens forever.
agent = initialize_agent(tools, llm, max_iterations=8)Logging for Auditing
Record every tool call with its inputs, outputs, and outcome. This audit trail is essential for debugging agent behavior and for catching unsafe actions after the fact.
A Safe Tool Workflow
Putting it together:
- Return errors as observations, not crashes
- Validate inputs and bound timeouts/retries
- Apply least privilege and allowlists
- Require approval for destructive actions
- Cap iterations and log every call
Quick Check
Test your understanding of safe tool execution.
Recap
You learned to make agent tools resilient and safe.
- Surface errors as observations the agent can handle
- Validate inputs and bound timeouts, retries, and iterations
- Apply least privilege and allowlists
- Require approval for destructive actions and log everything
用 AI 导师学习 AI Agents with LangChain & Autonomous Workflows — 免费
在浏览器中编写并运行真实代码,获得全天候 AI 导师的即时帮助,并在网页或应用中继续学习。
- 课程
- 12
- 课程
- 50
常见问题解答
「错误处理与安全的工具执行」课时是免费的吗?
是的 — 「错误处理与安全的工具执行」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 AI Agents with LangChain & Autonomous Workflows 课程的其余内容,请升级到 CoddyKit PRO。 AI Agents with LangChain & Autonomous Workflows 课程共包含 4 节课。
「错误处理与安全的工具执行」这节课中我会学到什么?
通过优雅地处理失败、验证输入并限制自主执行期间工具可以执行的操作,让代理工具更加健壮和安全。 你通过在浏览器中直接运行的动手代码来练习 AI Agents with LangChain & Autonomous Workflows,全天候 AI 导师会在你学习这节课的过程中回答你的问题。
学习 AI Agents with LangChain & Autonomous Workflows 需要有经验吗?
无需任何先前经验。CoddyKit 上的 AI Agents with LangChain & Autonomous Workflows 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 4 节课,共 4 节。
「错误处理与安全的工具执行」课时需要多长时间?
大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。
我能在这节 AI Agents with LangChain & Autonomous Workflows 课中编写并运行代码吗?
能。每节 AI Agents with LangChain & Autonomous Workflows 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。