Weak models write tool calls as prose. We started executing them.
An agent reported success after making zero tool calls — the model had written the call into its reply as a code block. Why the obvious guard missed it, the three shapes we have seen since, and why we now materialise prose into real calls instead of just retrying.
September 23, 2026