Built-in tools cover general work. To connect an agent to your own systems, you can let the agent write its own tools, connect it to external MCP servers, and give it skills: named procedures it loads only when needed. All three are managed on the agent's Tools & MCP tab.
Let the agent create its own tools with create_tool
With the create_tool built-in tool, the agent can write a new tool (Python code plus a parameter schema), test it in its sandbox and save it to the project. The next time a similar task comes up, the agent calls the saved tool instead of writing code again, which is much faster and uses far fewer tokens.
- Open Tools & MCP > Behaviour > Built-in tools.
- Add both
create_toolandterminal.create_toolneeds the terminal to write and test code. - Click Save.
- In Playground, ask for a tool, for example: "Create a tool that calculates the first N prime numbers."
- The agent writes the code, tests it and saves it. It can then call the new tool by name (for example
first_n_primes). - Open a new session and ask a task the tool covers ("Calculate the first 10 primes"). The agent calls the saved tool directly.
Tools the agent creates appear under Agent-created tools and are automatically available in every conversation for the project.
This pattern suits business actions: for example tools to renew, suspend or generate a licence in your own software, which an assistant or chat widget can then call.
Review, edit and control agent-created tools
A tool the agent writes is not a black box. A person can review and change it before relying on it.
- Open Tools & MCP and scroll to Agent-created tools. Each row shows Name, Description, Updated and Enabled.
- Click the edit (pencil) icon to open the tool. You can change:
- Description: what the tool does. The model reads this to decide when to call it.
- Parameters (JSON schema): the arguments the tool accepts.
- Code (Python): the code receives an
argsdict with the parameters and prints its result to stdout.
- Click Save.
- To stop the agent from using a tool without deleting it, turn off Enabled. Use the delete (bin) icon to remove it.
Review the code of every agent-created tool before using it in production, especially tools that call external systems.
Inject secrets into a tool
Tools that call external APIs (a CRM, a billing system) need credentials. Store them once as project secrets and pass them to the tools that need them.
- Add the credential on the project's Secrets tab (Add secret).
- Open the tool from Agent-created tools (pencil icon).
- Under Project secrets, either turn on Inject all project secrets, or pick specific ones in Secrets to inject (empty = none).
- In the tool code, read the value as an environment variable, for example
os.environ["NAME"]. - Click Save.
Selected secrets are passed to the tool's sandbox as environment variables. The plain-text value never reaches the model. Inject only the secrets a tool actually needs.
Connect an external MCP server
If a system already offers an MCP (Model Context Protocol) server, connect it and the agent can use the tools it exposes. For systems without MCP, wrap their API as an agent-created tool instead.
- Open Tools & MCP and scroll to Connections ("Connect external tool servers over MCP — HTTP/SSE or stdio").
- Click Add server.
- In URL or Command, enter the server's URL (HTTP/SSE) or the command that starts it (stdio).
- In Headers, add any headers the server needs, such as an authorization header. Use one header per line in
KEY: VALUEformat. - Click Save on the server entry, then save the section. The entry shows whether the server has been probed.
- Test in Playground with a request that needs one of the server's tools.
The configuration is the same as in other MCP clients: a server address plus headers. MCP servers differ in how closely they follow the protocol, so test each new server with a few real requests before relying on it.
Add a skill to an agent
A skill is a named, saved set of instructions: a procedure the agent loads only when it needs it. Only a short description is sent with every prompt; the full instructions cost no context until the agent loads them. Skills are text, saved and versioned in the project, not code.
- Open Tools & MCP > Behaviour > Built-in tools and add
load_skill. Without it, skills are stored but the agent never sees them; the Skills section shows a warning with a Go to built-in tools button. - Click Save.
- Scroll to Skills and click New skill.
- Fill in:
- Name: letters, digits, spaces, hyphens and underscores. The model calls
load_skillwith this exact name. - Description: one line that reaches every prompt. Say when to use the skill. Only the first 200 characters are sent.
- Instructions: the procedure itself (up to 100,000 characters).
- Name: letters, digits, spaces, hyphens and underscores. The model calls
- Click Save.
Add skills one at a time, or install one from the Library when one is available there.
Write the description as a trigger ("Use when the user asks to…") so the agent knows when to load the skill.
Common questions
Why doesn't the create_tool tool work on my agent?
It needs the terminal built-in tool as well. Add both under Built-in tools and save.
Can I change the code the agent wrote?
Yes. Open the tool under Agent-created tools with the pencil icon and edit the description, parameter schema or Python code.
How do I stop the agent using one of its tools?
Turn off Enabled for that tool under Agent-created tools. The tool is kept and can be re-enabled later.
Does the model see the API keys I inject into a tool?
No. Secrets are passed to the tool's sandbox as environment variables; the plain-text value never reaches the model.
The system I want to connect has no MCP server. What now?
Let the agent create a tool that calls the system's API, then review the code and inject the credentials as secrets.
My skills don't seem to be used. Why?
Add the load_skill built-in tool. Also check that each skill's Description says clearly when the skill should be used.
What is the difference between a tool and a skill?
A tool runs code and returns a result. A skill is text instructions that the agent reads when it decides the skill is relevant.