Plugging your AI agent into a shared tool protocol might be exactly what's making its behavior hard to predict.
How does protocol mediation affect determinism in agentic function calls?
This explores what happens to predictability when an LLM agent reaches its tools through a protocol layer (like MCP) instead of calling functions directly — and whether that mediation is the thing introducing the non-determinism.
This reads the question as asking whether the protocol layer itself — the standardized middle that sits between an agent and its tools — is what makes agentic function calls unpredictable, or whether it's incidental. The corpus has a sharp, opinionated answer at the center of it. One production account Why do protocol-based tool integrations fail in production workflows? found that routing tool access through MCP introduced non-deterministic failures, not because the protocol was buggy, but because mediation forces the model to do two fuzzy things at runtime: pick which tool from an ambiguous menu, and infer parameters from loose descriptions. Stripping that out — explicit direct function calls, one tool per agent — restored determinism. The tell is in the survey it cites: 85% of production teams build custom agents and skip frameworks entirely. The instinct is to remove the layer that's deciding for the model.
But the corpus immediately complicates the 'just remove the protocol' story. A competing note Should coordination protocols wrap existing systems or replace them? argues protocols win adoption precisely by wrapping existing systems like MCP under a shared substrate rather than replacing them — value accrues without ecosystem rewrites. So there's real tension here: the production lesson says mediation costs you determinism, while the coordination lesson says you can't realistically rip mediation out without losing interoperability. The synthesis isn't 'protocols bad' — it's that every inference the protocol does on the model's behalf (tool selection, parameter binding) is a place where determinism leaks.
Why does that leak compound rather than stay local? Look at how coordination degrades at scale Why do multi-agent systems fail to coordinate at scale?: agents accept information from neighbors without verifying it, so a single ambiguous resolution propagates as error rather than getting caught. Mediation adds exactly these uncritical handoffs. And the FLOWSTEER work shows the same surface is exploitable — a crafted prompt can bias tool routing and task assignment at planning time, before any infrastructure runs Can prompts alone reshape multi-agent workflows without system access?, with the damage amplified when injected into high-influence positions where dependencies converge How does a signal's position in a workflow change its influence?. The same indirection that makes tool selection non-deterministic also makes it steerable. Non-determinism and attackability turn out to be the same property viewed from two angles.
The most interesting move, though, is what the corpus offers as the alternative to fuzzy mediation: not 'less protocol' but a more legible substrate. Code, one note argues, is uniquely good for agent reasoning because it's simultaneously executable, inspectable, and stateful — you can verify what happened, not just hope Can code serve as the operational substrate for agent reasoning?. That reframes the whole question. Determinism isn't lost because there's a layer between agent and tool; it's lost when that layer is a natural-language guessing game instead of something checkable. A protocol that hands the model an inspectable, verifiable call is a different animal from one that hands it an ambiguous menu — even if both are 'mediation.' The thing to fix is the inference burden, not the existence of the middle.
Sources 6 notes
MCP integration caused non-deterministic failures through ambiguous tool selection and parameter inference. Replacing it with explicit direct function calls and single-tool-per-agent design restored determinism. A 306-practitioner survey confirms 85% of production teams build custom agents, forgoing frameworks.
Research shows that agent coordination standards achieve adoption by composing existing protocols like MCP and DIDComm under a shared substrate, rather than competing to replace them. Bridging lets value accrue incrementally without forcing ecosystem-wide rewrites.
AgentsNet benchmark shows agents fail to coordinate strategies either by agreeing too late or adopting strategies without informing neighbors. Agents accept neighbor information without verification, enabling error propagation while remaining capable of detecting direct conflicts.
FLOWSTEER demonstrates that a crafted prompt can steer planner-executor systems by biasing workflow formation before infrastructure is invoked, raising malicious success by up to 55 percent. This attack surface exists because contamination enters upstream of workflow inspection defenses.
Malicious signals injected into high-influence subtasks propagate far more than those in peripheral nodes, and signals framed as task-relevant evidence are relayed by downstream agents. FLOWSTEER exploits both regularities to steer multi-agent workflows.
Show all 6 sources
Research shows code uniquely enables agent reasoning, action, and verification by being simultaneously executable, inspectable, and stateful. This unified code-centered loop improves reasoning and verification together compared to natural-language or prose-based approaches.
Papers this line draws on 8
The research behind the notes this line reads — ranked by how closely each paper relates.
- Towards a Science of Scaling Agent Systems
- FLOWSTEER: Prompt-Only Workflow Steering Exposes Planning-Time Vulnerabilities in Multi-Agent LLM Systems
- AgentsNet: Coordination and Collaborative Reasoning in Multi-Agent LLMs
- Drop the Hierarchy and Roles: How Self-Organizing LLM Agents Outperform Designed Structures
- A Practical Guide for Designing, Developing, and Deploying Production-Grade Agentic AI Workflows
- SafeFlow: Semantic Information-Flow Control for Blocking Malicious Propagation in Multi-Agent Systems
- A Technical Taxonomy of LLM Agent Communication Protocols
- A Comparative Study of MCP and A2A for Inter-Agent Coordination in LLM-Based Systems