Agents That Write Their Own Tools at Runtime — Sandhya Subramani, AWS
Source
youtube.com
Author
AI Engineer
Date
Why it matters
Shows that a system promptThe standing instructions a model receives before any user input — defining its role, rules, tools, and tone for the whole conversation.Full definition → plus editor, shell and load_tool lets an agent author tools and sub-agents at runtime. It also lists the evals and sandboxing needed before trusting a self-modifying agent.
Key takeaways · AI-distilled
In AWS developer advocate Sandhya Subramani's demo with the open-source Strands Agents SDK, an AI agentAn AI system that doesn't just answer once but works toward a goal in a loop — taking actions, reading the results, and deciding what to do next.Full definition → that starts with zero tools writes a calculator and a character counter when asked, then uses them without restarting.
The same approach extends to sub-agents: a travel-planner demo assembles its own sub-agents, and the talk walks through swarm, graph, handoff and workflow patterns.
Proposed evals for self-modifying agents check goal success, tool choice, parameters and inter-agent flow, with guardrailsThe checks around a model that block bad inputs and outputs — filters, validators, and permission rules the model itself can't override.Full definition → of sandboxAn isolated environment where AI-generated code or agent actions run without being able to touch anything real.Full definition → execution, constrained permissions and observability.
Terms in this piece · Glossary
sandbox — An isolated environment where AI-generated code or agent actions run without being able to touch anything real.
system prompt — The standing instructions a model receives before any user input — defining its role, rules, tools, and tone for the whole conversation.
AI agent — An AI system that doesn't just answer once but works toward a goal in a loop — taking actions, reading the results, and deciding what to do next.
guardrails — The checks around a model that block bad inputs and outputs — filters, validators, and permission rules the model itself can't override.