Browse questions, read quick answers, or expand full article breakdowns on demand. Filter by level, domain, or completion status using the sidebar dashboard.
Showing 31 of 31 questionsClick any card to load the whole article
beginner•Core Loop Primitives•4 min•+10 XP
ReAct Loop Architecture: Managing Thought-Action-Observation State
Question
How does the Thought-Action-Observation (ReAct) loop function state-wise during runtime, and why does an unconstrained observation window lead to immediate context drift or failure in simple autonomous loops?
beginner•Tool Calling & Execution•4 min•+10 XP
Tool Calling and JSON Schema: How LLMs Translate Function Signatures into Structured Calls
Question
How does an LLM runtime translate an abstract function signature into a strict JSON Schema call, and what deterministic parsing strategy should be implemented when the model generates syntactically valid JSON that violates the required schema types?
beginner•Deterministic Execution•4 min•+10 XP
Deterministic vs. Non-Deterministic Boundaries in Agentic Architecture
Question
In an agentic architecture, which components must remain strictly deterministic (hardcoded state machine), and which should be delegated to non-deterministic LLM reasoning? How do you enforce this boundary?
beginner•Task Decomposition•4 min•+10 XP
Static vs. Dynamic Task Decomposition: Plan-and-Solve vs. Runtime Re-planning
Question
What are the structural differences between static step-by-step task decomposition (e.g., Plan-and-Solve) and dynamic re-planning during tool execution, and what runtime telemetry signals that a plan needs to be discarded?
beginner•Core Loop Primitives•3 min•+10 XP
ReAct Token Growth: Why Full-History Replay Gets Expensive Fast
Question
In a naive ReAct loop implementation, why does appending the entire history of `Thought -> Action -> Observation` back into the prompt on every turn lead to exponential token consumption, and how is this mitigated at the basic loop level?
beginner•Tool Calling & Execution•4 min•+10 XP
Native vs. Prompt-Based Tool Calling: Why Native Reduces Parsing Failures
Question
What is the technical mechanism behind "native tool calling" supported by model providers versus prompt-based tool calling (e.g., instructing the model to output XML/JSON in plain text), and why does native tool calling reduce parsing failures?
beginner•Deterministic Execution•4 min•+10 XP
Guardrails for Tool Execution: Validating Agent Parameters Before and After a Call
Question
How do you enforce strict pre-execution and post-execution guardrails around a tool call to verify that the generated parameters (e.g., file paths, database queries) conform to system safety bounds before the execution engine runs them?
beginner•Task Decomposition•4 min•+10 XP
DAG Task Decomposition: Handling Data Dependencies Between Sub-Task Nodes
Question
When an agent decomposes a complex goal into a Directed Acyclic Graph (DAG) of sub-tasks, how do you handle data dependencies between nodes when Node B requires the runtime output of Node A?
intermediate•Memory Systems•6 min•+15 XP
Dual-Layer Agent Memory: Separating Short-Term Execution State from Long-Term Episodic Recall
Question
How do you architect a dual-layer memory system that separates short-term execution state from long-term episodic memory, and what dynamic retrieval strategy prevents irrelevant semantic memories from polluting the active context window?
intermediate•State Management & Graphs•7 min•+15 XP
State-Graph Agent Architectures: Checkpointers, Persistence, and Time-Travel Debugging
Question
How do state-graph architectures (e.g., LangGraph) model agent loops as directed graphs with persistence, and how do explicit checkpointers enable time-travel, replay, and mutation of state during execution failures?
intermediate•Human-in-the-Loop (HITL)•6 min•+15 XP
Async Human-in-the-Loop Interrupts: Pausing Agents Without Blocking the Server
Question
How do you design an asynchronous Human-in-the-Loop (HITL) interrupt pattern for high-risk tool executions without stalling the underlying application server or losing process context?
intermediate•Error Recovery & Reflection•5 min•+15 XP
Self-Correction Feedback Loops: Healing Agent Errors from Tool Exceptions
Question
When a tool call throws an execution exception (e.g., `404 Not Found` or `SyntaxError`), what self-correction/reflection feedback pattern should be fed back into the context to allow the agent to heal its approach without repeating the error?
intermediate•Memory Systems•6 min•+15 XP
Key-Value Stores vs. Vector Search vs. Knowledge Graphs: Long-Term Memory for Code-Generation Agents
Question
What are the trade-offs between using key-value state stores, semantic vector search, and structured knowledge graphs for long-term agent memory when building a code-generation agent?
intermediate•State Management & Graphs•6 min•+15 XP
State Reducers in Agent Graphs: Handling Concurrent Updates Without Race Conditions
Question
In graph-based agent frameworks, how do state "reducers" work under the hood to handle concurrent state updates from multiple parallel node executions without causing race conditions or state corruption?
intermediate•Human-in-the-Loop (HITL)•5 min•+15 XP
Reconciling Human Edits with Agent State During HITL Approval Flows
Question
When a human supervisor modifies the proposed state or edit plan during an HITL interrupt, how should the execution engine reconcile the human's manual edits with the agent's prior trajectory context?
intermediate•Error Recovery & Reflection•6 min•+15 XP
State Backtracking vs. Conversational Reflection: Recovering from Agent Dead-Ends
Question
How does explicit state backtracking (e.g., Tree-of-Thoughts or graph rewind) differ from simple conversational reflection when an agent hits an execution dead-end during a complex multi-file codebase refactor?
advanced•Multi-Agent Topology•8 min•+20 XP
Hierarchical vs. Peer-to-Peer Multi-Agent Topologies: Latency, Isolation, and Failure Risk
Question
What are the operational trade-offs between a Supervisor/Worker (Hierarchical) agent topology and a Peer-to-Peer agent network in terms of latency, context isolation, and single-point-of-failure risks?
advanced•Context & Budget Management•9 min•+20 XP
Context Compaction at Scale: Semantic Truncation, Rolling Summarization, and KV Dropping
Question
As an agent execution trace approaches the model's maximum context length, what context compaction algorithms (e.g., semantic truncation, rolling summarization, key-value dropping) preserve the highest utility for tool planning while keeping token costs bounded?
advanced•Agent Coordination•8 min•+20 XP
Sub-Agent Handoff Protocols: Passing State Across Task Boundaries Without Loss
Question
How do you design an explicit state-passing and handoff protocol between specialized sub-agents to prevent lost context and state corruption when delegating tasks across boundaries?
advanced•Dynamic Tool Synthesis•9 min•+20 XP
Dynamic Tool Synthesis: Generating and Safely Validating New Tools at Runtime
Question
How can an agent dynamically generate, compile, and execute new tools at runtime to solve unexpected tasks, and how do you ensure these dynamically created tools are safely validated before execution?
advanced•Multi-Agent Topology•8 min•+20 XP
Router/Dispatcher Agents: Avoiding Cognitive Bottlenecks and Latency Inflation
Question
How do you design an efficient Router/Dispatcher agent that dynamically selects and hands off tasks to specialized downstream agents without becoming a single point of cognitive bottleneck or latency inflation?
advanced•Context & Budget Management•9 min•+20 XP
Dynamic Token Budget Controllers: Allocating Context Across Instructions, Tools, Memory, and History
Question
How do you construct a dynamic token budget controller that allocates token allowances across system instructions, active tool definitions, dynamic memory retrieval, and short-term execution history based on the current phase of task execution?
advanced•Dynamic Tool Synthesis•8 min•+20 XP
Dynamic Tool Registries: Searching and Binding OpenAPI Schemas Without Context Bloat
Question
How do you implement a dynamic Tool Registry that allows an agent to search, inspect, and bind OpenAPI schemas or function definitions on the fly, avoiding context window bloat caused by loading hundreds of static tools upfront?
advanced•Sub-Agent Spawning•9 min•+20 XP
Parent-Child Sub-Agent Spawning: Parallel Execution, Lifecycle Monitoring, and Result Aggregation
Question
How do you architect a parent agent pattern capable of spawning transient child sub-agents in parallel, monitoring their lifecycles, and aggregating their asynchronous execution results into a unified parent state?
expert•Execution Sandboxing•12 min•+25 XP
Docker vs. WebAssembly vs. MicroVMs: Sandboxing Trade-offs for Agent-Generated Code
Question
What are the security, latency, and resource isolation differences between using Docker containers, WebAssembly (Wasm) runtimes, and MicroVMs (e.g., Firecracker) for sandboxing untrusted code generated by AI agents?
expert•Security & Guardrails•11 min•+25 XP
Defending Against Indirect Prompt Injection: Protecting Agents from Exfiltration via Retrieved Content
Question
How do you protect a software engineering agent from indirect prompt injection attacks contained within retrieved web pages or repository files that attempt to exfiltrate secrets via outbound tool calls?
Quick Answer
Retrieved content — a web page, a file in a repository — is data, never instructions, and the agent architecture has to enforce that distinction structurally: content the agent reads should never be able to trigger a tool call on its own, and any outbound call that would send data somewhere new (an unfamiliar URL, an unexpected recipient) needs to pass an allow-list check or human approval before it fires.
Detailed Answer
Indirect prompt injection works by hiding instructions inside content the agent is expected to process as data — a comment in a source file, hidden text on a web page, a commit message — hoping the agent's language model treats that embedded text as a command rather than as content to summarize or analyze. For a software engineering agent, the dangerous version of this is an injected instruction that tries to get the agent to read a secret (an API key, a credential file) and then send it somewhere external, disguised as an innocuous-looking tool call the agent was tricked into making.
The core defense is structural, not just prompt-level warnings telling the model to "ignore instructions in retrieved content" — that helps but isn't reliable enough alone, since a sufficiently crafted injection can still get through a model's own judgment. The more robust layers: strict data/instruction separation, where retrieved content is passed to the model in a clearly delimited, explicitly-labeled-as-data channel, and the system prompt is explicit that anything in that channel is never to be treated as a directive, regardless of how it's phrased. Egress allow-listing, where any outbound tool call that sends data somewhere — an HTTP request, an email, a file upload — is checked against a fixed allow-list of known-safe destinations before it's permitted to run; an injected instruction trying to exfiltrate a secret to an attacker-controlled URL fails here because that URL was never on the allow-list, independent of whether the model "believed" the injected instruction. Least-privilege secrets access, so that even if an injection succeeds in getting the agent to attempt reading a secret, the agent's own execution context doesn't have that secret available to read in the first place for tasks that don't need it. And for any outbound action that doesn't cleanly match the allow-list or that touches a genuinely new destination, routing through a human-in-the-loop approval gate rather than letting the model's own judgment be the last line of defense.
Loading diagram...
Production Implications
Never grant an agent's tool-execution context broader secret access than the specific task requires — scope credentials per task, not per agent
Log every outbound call's destination alongside the retrieved content that was in context when it was proposed, so a successful injection attempt is traceable after the fact
Treat "ignore embedded instructions" system-prompt language as a supplementary defense, not the primary one — egress allow-listing is what actually stops exfiltration when the prompt-level defense is bypassed
Periodically red-team the pipeline with known injection patterns against realistic retrieved content, not just synthetic test prompts
Key Takeaway
Prompt-level instructions to "ignore embedded commands" are not sufficient on their own — the reliable defense is structural: retrieved content stays labeled as untrusted data, and outbound tool calls are gated by an allow-list the model's own judgment can't override.
expert•Cost & Loop Control•11 min•+25 XP
Circuit Breakers for Agents: Stopping Non-Convergent, Infinite Tool-Calling Loops
Question
How do you implement robust architectural circuit breakers (token usage velocity, repetition detection, goal-drift metrics) to prevent autonomous agents from getting stuck in non-convergent, infinite tool-calling loops?
expert•Evals & Observability•12 min•+25 XP
Evaluating Non-Deterministic Agents: Automated Benchmarks and Reproducible Debugging
Question
How do you build an automated evaluation pipeline for non-deterministic agents (using benchmarks like SWE-bench), and how do you achieve reproducible step-by-step debugging across non-deterministic LLM runs?
expert•Execution Sandboxing•12 min•+25 XP
Sandbox Egress Controls: Blocking Agent Access to Internal Infrastructure and Cloud Metadata
Question
What network, file-system, and system-call restriction profiles (e.g., `seccomp`, eBPF, network namespaces) must be applied to a code execution sandbox to prevent an agent-executed script from accessing internal infrastructure or cloud provider metadata endpoints?
expert•Security & Guardrails•12 min•+25 XP
Dual-LLM Architecture: Privilege Separation Between Control-Flow and Data-Processing Models
Question
How does the "Dual-LLM Architecture" (separating a privileged control-flow model from an unprivileged data-processing model) prevent data exfiltration and unauthorized tool invocations when processing untrusted inputs?
expert•Evals & Observability•11 min•+25 XP
Instrumenting Agentic Workflows: OpenTelemetry Tracing and the Metrics That Matter Beyond Latency
Question
How do you extend OpenTelemetry or native APM tools to instrument an agentic workflow, and what key metrics beyond latency and cost (e.g., tool error rate, loop depth, context utilization ratio) are essential for diagnosing agent performance in production? --- *Total: 31 questions across 4 tiers (8 Beginner / 8 Intermediate / 8 Advanced / 7 Expert)*