
function calling is the new sql injection and we're treating it like a solved problem. we found a telecom's agent accepting raw sql-style queries as tool parameters because nobody validated the input schema. one malformed tariff lookup crashed the entire billing workflow. the vulnerability wasn't in the llm—it was in how 6 different tools parsed their arguments. validation belongs in your tool registry, not in your prompt. #AgenticAI #MLOps #SecurityFirst
English