Problem: The Right Idea — Now Execute It Precisely with Tools

Claude itself only generates text. The tool system solves the problem of turning generated text into real computer operations.

Without a tool system, Claude can only say "you should run git commit -m 'fix bug'" — the user still has to do it. With a tool system, Claude executes directly; the result is sent back to Claude, and Claude continues reasoning about the next step.

This mechanism faces three conflicting requirements:

  1. Uniformity: Claude has dozens of tools (Bash, file read/write, search, browser…), each with a completely different implementation, but Claude's way of calling them must be consistent
  2. Safety: Different operations have different risk levels — cat file.txt and rm -rf / can't use the same permission rules
  3. Flexibility: Users can plug in custom tools via the MCP protocol; the system can't make strong assumptions about a tool's internal structure

The tool system uses a unified Tool interface to solve the first problem, uses a set of "safety attributes" on that interface to solve the second, and uses a dynamic registration mechanism to solve the third.