ThinnestAI is now an Official Meta Tech Provider
Back to Blog

Tools, Not Skills: What Your Agent Can Do, and Why Every One of Them Starts Off

T
Thinnest AI Team
Feb 27, 2026• 6 min read
Tools, Not Skills: What Your Agent Can Do, and Why Every One of Them Starts Off

What a tool is here

A tool is something the agent can do rather than say: check an order, search the catalogue, look something up in your own system, capture a lead mid-conversation, hand the thread to a person. Connect one and the agent can call it during a conversation, in whichever of the 37 reply languages the customer is using, on the website widget, WhatsApp, Telegram or a phone call.

There is no "Skill" object here — no packaged bundle of prompt text you build once and attach to fifteen agents. What an agent gets is a set of instructions, a knowledge base, and a short list of things it is allowed to call. This post is about the third one.

Where tools come from

  • 21 pre-registered MCP servers. Addresses read from the registry and grouped by what they do, so connecting a known service is a click rather than a URL you have to find.
  • A directory of 1,434 services, generated from the official registry. Twenty of those addresses are hand-verified; the rest are listed as published. That distinction is worth stating plainly, because "it is in the directory" and "we tested it" are different claims and blurring them is how a customer finds out the hard way.
  • Any MCP address you paste. If you run your own server, you do not need us to have heard of it.
  • Your own HTTP endpoints, through Actions. The agent calls a URL you own with arguments it worked out from the conversation.
  • Outbound webhooks. Signed deliveries to any HTTPS endpoint — the lane that reaches Sheets, Zoho and effectively any CRM through Zapier today.
  • Built-in web search. It runs provider-side, so it is available only on models that offer it, and your own material is always searched first.

Signing in, and where the credentials sit

Third-party tools sign in through an OAuth popup. Tokens are sealed with AES-256-GCM and renewed automatically, so nobody signs in twice, and they are unreadable by the dashboard database role even with a hand-written query.

Before we fetch any URL you give us, it is validated and DNS-resolved — an address that resolves to something inside our own network is refused rather than requested. Third-party tools are namespaced too, so none of them can register itself under the name of a built-in and quietly take over knowledge retrieval.

Off by default. Eight per agent. Both on purpose.

Every tool an agent discovers arrives switched off. Enabling one is a separate, deliberate act per tool. And an agent stops at eight enabled tools.

Two reasons, both boring and both real.

  • These tools are reachable from a public chat. The person on the other end may be a stranger working out how to talk your model into something. Nothing being on by default means nothing gets exposed because somebody clicked Next through a setup screen.
  • Every tool schema is re-sent on every turn. Models get measurably worse at choosing as the list grows. A twelve-tool agent is not a more capable agent than an eight-tool one; it is a less reliable one with a longer prompt.

Platforms advertise thousands of integrations. The number that decides whether your agent works is how many are live on one agent at once — and ours has a ceiling.

Shopify, in two lanes

Shopify ships, and it ships as two separate connections because the two halves have genuinely different trust requirements:

  • Storefront, no authentication. Catalogue, cart and checkout. It exposes what the storefront already shows any visitor, which is why it needs no credentials at all.
  • Admin API, over OAuth. Order status and tracking. These need the merchant's permission because they are about a specific person's order, not the shop window.

The caveat: Shopify, Asana and Xero refuse dynamic client registration, so connecting them today means registering an app yourself. That is a stopgap we are not going to describe as one-click.

Try one without owning an API

Actions has the widest gap in this product between understanding a feature and having watched it work. To try one you need an endpoint of your own, reachable from here, with a request shape you have already decided on — and most people evaluating a platform have none of the three.

So there is a pretend clinic backend at /api/demo/clinic. Five operations: hours and address, open times, book a visit, take a message, and an emergency escalation that answers with the words to say rather than an error the agent cannot voice. Deterministic, no key required, nothing stored. It is wired to the Patient intake agent in the pre-built library, whose instructions already name these endpoints — so you can create that agent, paste the URLs into Actions, and watch a booking come back with a reference number in it.

It is a mock and it says so in every response. A booking succeeds and is forgotten.

Webhooks out

Five events, chosen per endpoint: a lead, an escalation, a resolution, a finished call (outcome, seconds, campaign) and a finished campaign (counters). Deliveries are signed so your side can verify they came from us. A webhook that fails five times in a row is switched off, and the notifications feed tells you it happened rather than leaving you to find the gap in your data.

Consent is not the only guardrail

Everything a tenant adds — a crawled page, an uploaded PDF, a tool's own description — is fenced and labelled as data before it reaches the model, so text you ingest cannot issue instructions to your agent. That boundary is tested rather than asserted: eight live prompt-injection attacks run against the public endpoint as part of the test suite.

What we do not offer

No reusable Skill modules with drag-to-reorder priority. No visual canvas of nodes and edges. No agent-to-agent delegation. And no bring-your-own model keys — models are curated and platform-managed, which is what lets a flat per-minute rate include the LLM at all.

Get started

Open an agent, go to Tools, and turn on the two you actually need. Then create the Patient intake agent, point Actions at the demo clinic, and see a tool call resolve before you build anything against your own systems.

Connect your first tool free →

No credit card required • Trial includes 25 voice minutes and 200 chat replies

Frequently Asked Questions

Subscribe to our newsletter

Get the latest AI updates delivered directly to your inbox.