Tool Preferences in Agentic LLMs are Unreliable

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Faghih, Kazem, Wang, Wenxiao, Cheng, Yize, Bharti, Siddhant, Sriramanan, Gaurang, Balasubramanian, Sriram, Hosseini, Parsa, Feizi, Soheil
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916959581372416
author Faghih, Kazem
Wang, Wenxiao
Cheng, Yize
Bharti, Siddhant
Sriramanan, Gaurang
Balasubramanian, Sriram
Hosseini, Parsa
Feizi, Soheil
author_facet Faghih, Kazem
Wang, Wenxiao
Cheng, Yize
Bharti, Siddhant
Sriramanan, Gaurang
Balasubramanian, Sriram
Hosseini, Parsa
Feizi, Soheil
contents Large language models (LLMs) can now access a wide range of external tools, thanks to the Model Context Protocol (MCP). This greatly expands their abilities as various agents. However, LLMs rely entirely on the text descriptions of tools to decide which ones to use--a process that is surprisingly fragile. In this work, we expose a vulnerability in prevalent tool/function-calling protocols by investigating a series of edits to tool descriptions, some of which can drastically increase a tool's usage from LLMs when competing with alternatives. Through controlled experiments, we show that tools with properly edited descriptions receive over 10 times more usage from GPT-4.1 and Qwen2.5-7B than tools with original descriptions. We further evaluate how various edits to tool descriptions perform when competing directly with one another and how these trends generalize or differ across a broader set of 17 different models. These phenomena, while giving developers a powerful way to promote their tools, underscore the need for a more reliable foundation for agentic LLMs to select and utilize tools and resources. Our code is publicly available at https://github.com/kazemf78/llm-unreliable-tool-preferences.
format Preprint
id arxiv_https___arxiv_org_abs_2505_18135
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Tool Preferences in Agentic LLMs are Unreliable
Faghih, Kazem
Wang, Wenxiao
Cheng, Yize
Bharti, Siddhant
Sriramanan, Gaurang
Balasubramanian, Sriram
Hosseini, Parsa
Feizi, Soheil
Artificial Intelligence
Computation and Language
Cryptography and Security
Machine Learning
Large language models (LLMs) can now access a wide range of external tools, thanks to the Model Context Protocol (MCP). This greatly expands their abilities as various agents. However, LLMs rely entirely on the text descriptions of tools to decide which ones to use--a process that is surprisingly fragile. In this work, we expose a vulnerability in prevalent tool/function-calling protocols by investigating a series of edits to tool descriptions, some of which can drastically increase a tool's usage from LLMs when competing with alternatives. Through controlled experiments, we show that tools with properly edited descriptions receive over 10 times more usage from GPT-4.1 and Qwen2.5-7B than tools with original descriptions. We further evaluate how various edits to tool descriptions perform when competing directly with one another and how these trends generalize or differ across a broader set of 17 different models. These phenomena, while giving developers a powerful way to promote their tools, underscore the need for a more reliable foundation for agentic LLMs to select and utilize tools and resources. Our code is publicly available at https://github.com/kazemf78/llm-unreliable-tool-preferences.
title Tool Preferences in Agentic LLMs are Unreliable
topic Artificial Intelligence
Computation and Language
Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2505.18135