한국어
The model lives in user mode; the host is the kernel. A tool list is a syscall table, and the boundary does not care how eloquent the request was.essay · standmeet2026.10.07 · essay
2026.10.07·3 min read#agent-os

Tools Are Syscalls

The model lives in user mode; the host is the kernel. A tool list is a syscall table, and the boundary does not care how eloquent the request was.

A running program lives in user mode. It may compute anything it likes, but it cannot touch the world: every file read, every packet sent, every byte written crosses a narrow, numbered, permission-checked boundary — the system call table — into a kernel that decides whether the request is legitimate. The elegance of the arrangement is that the program's intelligence is irrelevant to the boundary's discipline. A brilliant program and a compromised one knock on the same door and show the same credentials.

An agent is a user-mode program whose computation happens to be language. The model may reason about anything, but it cannot touch the world except through its tools — and a tool list is a syscall table: a finite, named, typed set of crossings, each with arguments the host validates before acting. This is not a metaphor imposed from outside; it is the literal architecture of every agent host worth trusting. The host is the kernel. The model never gets ring 0.

Three pieces of kernel discipline deserve to be copied verbatim. Validation at the boundary: arguments are checked where they cross, not where they were composed — a model's confident malformed request is just a malformed request. Least privilege as a table property: a process cannot call what is not in its table, and an agent cannot invoke what is not in its tool list; capability is granted by enumeration, not by persuasion. When a visitor's role narrows what the agent may read, that is a protection ring doing its ordinary work — the access code resolves to a role, the role to a capability set, and the boundary enforces it without caring how eloquent the request was. And auditability: kernels log syscalls because the crossing is the one place everything consequential must pass. An agent host that logs tool calls has the same property — a complete record of the only moments the system touched reality.

The inversion is also instructive. Frameworks that blur the boundary — letting generated code execute directly, treating tool results and model text as one undifferentiated stream — are the monolithic, everything-in-ring-0 designs that operating systems abandoned for cause. Prompt injection is what user mode calls a confused deputy problem, and it has the confused deputy's classic solution: the deputy checks the credentials of the request, not the confidence of the requester.

Keep the model brilliant and the boundary boring. That division of labor — intelligence in user mode, discipline in the kernel — is sixty years old, and it has never once been improved by letting the program hold the door for itself.