Tool calls

How models invoke tools in a chat, what tools are available, and how to keep them safe.

Last updated

A chat-attached model can call tools to read your data instead of guessing. Cocobox exposes the same set of tools as the MCP SQL server, so you get parity between in-app chats and external editors connected via MCP.

What’s available

ToolWhat it does
sql_list_connectionsLists connections the chat has access to.
sql_list_tablesLists tables on a connection.
sql_describeReturns column metadata for a table or view.
sql_runExecutes a statement and returns rows.
sql_explainReturns the engine’s EXPLAIN output.
sql_historyRecent statements + results for context.

Tools without “list” or “describe” prefixes touch the database; tools with them only read metadata.

Approval policy

Every tool call is mediated by a policy:

  • Read statements (SELECT, SHOW, EXPLAIN) — auto-approved by default.
  • Write statements (INSERT, UPDATE, DELETE, DDL) — always require manual approval.
  • Connections you don’t have access to — never callable.

Per-workspace, admins can:

  • Require approval for all reads (paranoid mode).
  • Disable specific tools entirely.
  • Auto-approve writes only for specific connections (e.g. a sandbox).

What you see

When the model proposes a tool call, the chat displays:

  • Tool name and arguments (formatted, copyable).
  • The exact SQL that will run (if applicable).
  • The connection it’ll run against.
  • Three buttons: Approve, Edit (modify the SQL or args, then approve), Reject (with optional reason; the model gets the rejection as feedback).

After approval, the tool runs server-side at your permissions on that connection. The result is shown inline (rows, an explain plan, an error). The model continues from there.

Iteration loop

Models commonly chain tools:

  1. sql_list_tables to find candidates.
  2. sql_describe on the most likely one.
  3. sql_run with a tentative query.
  4. Read the result, refine, run again.

Each step is its own approval (or auto-approval). You can stop the loop at any time; the model receives “user cancelled” and stops calling tools.

Cost

Tool calls are free (they don’t consume credits). Only the model turns surrounding them do.

Auditing

Every tool call is logged in the audit log with the chat id, model, tool name, arguments, result code, and approver. Useful for “who and what ran this query at 2am Sunday.”