Problem: The Right Idea — Now Execute It Precisely with Tools
Claude itself only generates text. The tool system solves the problem of turning generated text into real computer operations.
Without a tool system, Claude can only say "you should run git commit -m 'fix bug'" — the user still has to do it. With a tool system, Claude executes directly; the result is sent back to Claude, and Claude continues reasoning about the next step.
This mechanism faces three conflicting requirements:
- Uniformity: Claude has dozens of tools (Bash, file read/write, search, browser…), each with a completely different implementation, but Claude's way of calling them must be consistent
- Safety: Different operations have different risk levels —
cat file.txtandrm -rf /can't use the same permission rules - Flexibility: Users can plug in custom tools via the MCP protocol; the system can't make strong assumptions about a tool's internal structure
The tool system uses a unified Tool interface to solve the first problem, uses a set of "safety attributes" on that interface to solve the second, and uses a dynamic registration mechanism to solve the third.