%%{init: {'theme': 'base', 'themeVariables': {'fontSize': '13px'}}}%%
flowchart LR
A[Goal] --> B[Plan]
B --> C[Act: call a tool]
C --> D[Observe result]
D --> E{Done?}
E -->|No| B
E -->|Yes| F[Stop and report]
style E fill:#f9f,stroke:#333,stroke-width:2px
style F fill:#90EE90,stroke:#333,stroke-width:2px
Main takeaways
What an agent is
- Agent = model + tools + loop + goal; chatbots answer, agents act
- An old idea (sense, plan, act); LLMs changed the planning step
- ReAct: the model asks, software acts, the result returns as text
How far to trust them
- Autonomy is a dial, from fixed workflows to agents nobody checks
- Errors compound: 95% per step is only 36% over 20 steps
- Before you delegate: can I undo it, and how much can I lose?
Keeping them safe
- Prompts are not guardrails: use permissions, sandboxes, undo, limits
- Prompt injection: untrusted text can hijack the loop (lethal trifecta)
















