Tool calls
How models invoke tools in a chat, what tools are available, and how to keep them safe.
A chat-attached model can call tools to read your data instead of guessing. Cocobox exposes the same set of tools as the MCP SQL server, so you get parity between in-app chats and external editors connected via MCP.
What’s available
| Tool | What it does |
|---|---|
sql_list_connections | Lists connections the chat has access to. |
sql_list_tables | Lists tables on a connection. |
sql_describe | Returns column metadata for a table or view. |
sql_run | Executes a statement and returns rows. |
sql_explain | Returns the engine’s EXPLAIN output. |
sql_history | Recent statements + results for context. |
Tools without “list” or “describe” prefixes touch the database; tools with them only read metadata.
Approval policy
Every tool call is mediated by a policy:
- Read statements (
SELECT,SHOW,EXPLAIN) — auto-approved by default. - Write statements (
INSERT,UPDATE,DELETE, DDL) — always require manual approval. - Connections you don’t have access to — never callable.
Per-workspace, admins can:
- Require approval for all reads (paranoid mode).
- Disable specific tools entirely.
- Auto-approve writes only for specific connections (e.g. a sandbox).
What you see
When the model proposes a tool call, the chat displays:
- Tool name and arguments (formatted, copyable).
- The exact SQL that will run (if applicable).
- The connection it’ll run against.
- Three buttons: Approve, Edit (modify the SQL or args, then approve), Reject (with optional reason; the model gets the rejection as feedback).
After approval, the tool runs server-side at your permissions on that connection. The result is shown inline (rows, an explain plan, an error). The model continues from there.
Iteration loop
Models commonly chain tools:
sql_list_tablesto find candidates.sql_describeon the most likely one.sql_runwith a tentative query.- Read the result, refine, run again.
Each step is its own approval (or auto-approval). You can stop the loop at any time; the model receives “user cancelled” and stops calling tools.
Cost
Tool calls are free (they don’t consume credits). Only the model turns surrounding them do.
Auditing
Every tool call is logged in the audit log with the chat id, model, tool name, arguments, result code, and approver. Useful for “who and what ran this query at 2am Sunday.”