JSON Schema makes agent tools production-ready
NIST AI 800-5 finds commenters agree agent threats are novel and existing controls need adaptation. Schema syntax is not the bar.
TLDR
Claim: valid JSON against a schema is enough to ship side-effecting agent tools. NIST Trustworthy and Responsible AI 800-5 (May 18, 2026) summarizes CAISI's agent-security RFI: commenters widely agreed agents present novel threats and fundamental cybersecurity practices require adaptation. The January 2026 RFI foregrounded indirect prompt injection and misaligned objectives. Verdict: overstated for workflows with side effects.