Cover of the book “Les pièces d'action”, volume 4 of 6 of Pierre Vinet’s Bibliothèque IA, on a dark background with the accent color amber
AI Library · Volume 4 of 6 · Belt 4

French-language books

Action Parts

Original title (in French): Les pièces d'action

Connect, test and secure everything that makes a model act, without an agent

  • Chapters 29 to 36
  • 275 pages
  • 24 figures
  • Format 8.5 x 11 in, full color

Coming soon on Amazon

This volume will be published in Kindle and paperback editions. Leave your email to be notified at publication.

Get notified at publication

About this volume

Action Parts is the fourth volume of the Bibliothèque IA, a six-volume collection on artificial intelligence. This is a French-language book. Its thesis fits in one sentence: the model calls nothing. It writes a text that asks for a call; your program executes, and decides whether to execute. Everything that frames a model that acts sits in the gap between the request and the execution. This volume installs, one at a time, the parts that make a means of action manageable: the declared tool, the sandbox that contains code, the permission that decides, the connector to an organization's systems, the MCP standard protocol, the skill and the protected secret. Each part is connected and tested on its own, without an agent. Eight chapters cover function calling, sandboxes, permissions, hooks and approvals, acting on the web and on a computer, APIs and webhooks, MCP, skills and standing instructions, and secrets and identities. The book has 24 figures, typed call-out boxes, Quebec and Canada notes, a glossary, three appendices and the memo sheet for the fourth belt, with procedures for Windows 11, macOS on Apple silicon and Ubuntu 26.04 LTS. It assumes volumes 1 to 3 and is aimed at whoever connects these parts, as well as those who order or use them and need to judge a choice. Volume 5 then assembles the parts into an agent.

What you will be able to do

  • Write a tool declaration (name, description, parameter schema) and walk through the complete cycle of a call, naming who holds control at each step
  • Measure in tokens what a tool catalogue costs before any call takes place
  • Tell the three families of sandboxes apart (local container, managed microVM, provider interpreter) and say what each one does not protect
  • Write a permission rule, place a hook at the right moment of the cycle and choose a pattern for human approval
  • Verify a webhook signature and put three protections in place: signature, timestamp and idempotency key
  • Test an MCP server without an agent, create a minimal one and write a skill that follows the open specification
  • Store a secret in your system’s vault without it appearing in the terminal history or in a plain-text file

Table of contents

Partie VI — Les pièces d'action
  1. 29L'outil : l'appel de fonction et les outils natifs
    • 29.1 Ce qu'est un outil, et ce que le mot recouvre ailleurs
    • 29.2 Le schéma : déclarer ce que le modèle peut appeler
    • 29.3 Le cycle complet d'un appel
    • 29.4 Concevoir un bon outil
    • 29.5 Les outils natifs des fournisseurs
    • 29.6 Ce qu'un outil coûte
    • 29.7 Atelier : un appel de fonction en Python et en TypeScript
  2. 30Exécuter du code en sécurité : les bacs à sable
    • 30.1 Pourquoi l'exécution de code change tout
    • 30.2 Le conteneur local
    • 30.3 La microVM gérée
    • 30.4 L'interpréteur intégré chez le fournisseur
    • 30.5 Ce qu'un bac à sable ne protège pas
    • 30.6 Choisir, et ce que chaque famille coûte
  3. 31Garde-fous : permissions, crochets et approbations
    • 31.1 Délimiter d'abord, demander ensuite
    • 31.2 Les permissions
    • 31.3 Les crochets
    • 31.4 La validation humaine
    • 31.5 Les postes de supervision et les boîtes de réception
    • 31.6 Ce que les garde-fous ne couvrent pas
  4. 32Agir sur le Web et sur l'ordinateur
    • 32.1 Trois couches qu'on confond tout le temps
    • 32.2 La bibliothèque de pilotage
    • 32.3 L'agent de navigation
    • 32.4 L'infrastructure de navigateurs hébergés
    • 32.5 L'usage d'ordinateur
    • 32.6 Ce que le droit et les conditions d'utilisation permettent
  5. 33Les connecteurs : API, webhooks et intégrations
    • 33.1 Ce qu'un modèle doit savoir d'une interface
    • 33.2 REST et GraphQL
    • 33.3 S'authentifier
    • 33.4 Les webhooks
    • 33.5 Les intégrations prêtes à l'emploi
    • 33.6 Du texte au SQL, et jusqu'où ça marche
  6. 34MCP : le connecteur standard
    • 34.1 Le problème que MCP résout
    • 34.2 Hôte, client et serveur
    • 34.3 Les trois primitives
    • 34.4 Le protocole sans état
    • 34.5 Les transports
    • 34.6 Tester un serveur sans agent
    • 34.7 Créer un serveur
    • 34.8 La sécurité
    • 34.9 Les passerelles et les registres
    • 34.10 Qui gouverne le protocole
  7. 35Les compétences et les instructions permanentes
    • 35.1 Pourquoi ce chapitre arrive si tard
    • 35.2 Ce que « compétence » veut dire, et chez qui
    • 35.3 Le format et la divulgation progressive
    • 35.4 Créer une compétence
    • 35.5 Les catalogues, et la confiance qu'ils supposent
    • 35.6 Les fichiers d'instructions permanentes
    • 35.7 Quand plusieurs fichiers se contredisent
  8. 36Secrets et identités
    • 36.1 Le secret, et pourquoi il ne doit jamais toucher le disque en clair
    • 36.2 Les coffres des trois systèmes
    • 36.3 Les gestionnaires d'équipe
    • 36.4 Les variables d'environnement et leurs pièges
    • 36.5 OAuth pour un programme local
    • 36.6 L'identité des agents

Excerpt

Le vendredi après-midi, un client appelle les Ateliers Rivard pour savoir si la chaise de travail RV-448 est encore en stock, et à quel prix. Simon, seul développeur de l'entreprise, a branché depuis trois semaines un modèle de langage sur la boîte de courriels du service à la clientèle. Le modèle rédige des réponses impeccables, sauf sur ce point précis, où il invente un prix avec un aplomb parfait. Il n'a aucun moyen de le connaître : le prix vit dans une base de données que personne ne lui a montrée, et un modèle ne consulte rien. Ce qui manque n'est pas une meilleure consigne, c'est une pièce, et cette pièce s'appelle l'outil.

Excerpt from “Les pièces d'action” — Chapitre 29, ouverture (avant le § 29.1)

Technical details

TitleLes pièces d'action
SubtitleBrancher, tester et sécuriser tout ce qui fait agir un modèle — sans agent
Title translated into EnglishAction Parts
SeriesBibliothèque IA
VolumeVolume 4 of 6
AuthorPierre Vinet
PublisherPierre Vinet
LanguageFrench
Chapters8 (29–36)
Pages275
Figures24
Format8.5 x 11 in, color
Planned editionsKindle and paperback

Who it is for

Developers, integrators and technical leads who connect the means to act to a model, along with those who order or use them without having coded them and must judge a choice.

Prerequisites

Volumes 1 to 3 read, and nothing more. An action part is declared, coded or configured: the volume is aimed first at those who connect; no notion of agent is required.

Train your teams, or put AI to work in your SME?

These books teach; we also work alongside companies in the field. Let’s talk for thirty minutes about your situation, no strings attached.