Agents should not call tools
Most enterprise agent stacks are built the same way. You give a model a list of tools. It picks one. The tool runs. If you are careful, you put an allowlist in front of the tool list and you write the calls to a log. Then you write a governance