skip to content

In CrewAI, what happens when a Task defines tools and its Agent already has tools?

level: juniorimportance: should knowfreq 52%

answer

  1. two attachment points, one wins
  2. step-level list is authoritative
  3. nothing is inherited when you override
  4. least privilege per step, not per crew

basics

~20 s

Tools listed on a CrewAI Task take precedence for that task: the assigned agent works with the task's tool list rather than its own. Leave Task.tools unset to use the agent's tools; set it to narrow or replace the toolset for one step.

solid answer

~50 s

CrewAI lets you attach tools at two levels. `Agent(tools=[...])` describes the capabilities the role carries everywhere — the researcher always has search, the analyst always has the interpreter. `Task(tools=[...])` describes what is available for one step, and when it is set it takes precedence over the agent's own list for that task's execution. The practical rule: if you specify task tools, list *everything* that step needs, because you are replacing the agent's toolset rather than adding to it. This is the main lever you have for narrowing blast radius: an agent that holds a scraper and a filesystem writer can be run on a summarise-only task with just `FileReadTool()`, so no prompt-injected instruction in the scraped page can reach a write. It also shrinks the prompt — every tool the agent holds costs description tokens on every model call and adds one more wrong option for the LLM to pick.

code

python · 16 lines
python
from crewai import Agent, Task
from crewai_tools import FileReadTool, ScrapeWebsiteTool

researcher = Agent(
    role="Researcher",
    goal="Collect and condense source material",
    backstory="Reads widely and cites carefully.",
    tools=[ScrapeWebsiteTool(), FileReadTool()],
)

summarise = Task(
    description="Summarise the notes already saved in notes.md.",
    expected_output="A five-bullet summary.",
    agent=researcher,
    tools=[FileReadTool()],
)

go deeper

for a junior

Know both places tools can be attached — Agent(tools=[...]) and Task(tools=[...]) — and that the task's list is what the agent works with for that step when you set it.

for a middle

Explain that overriding replaces rather than extends, so the task list must be complete, and give the reasons to override: fewer tools in the prompt, fewer options to mis-select, a differently configured tool instance.

for a senior

Treat the per-task list as a least-privilege boundary. Show a concrete split where a step ingesting untrusted content holds no write or execute tool, and describe how you diagnose a step that lost a tool it needed.

for a principal

Own it as policy across the crew: which capability classes may ever co-occur in one step, where the trust boundary between ingestion and action sits, and how tool assignment is reviewed as part of the crew design rather than left to whoever wrote the task.

## Two attachment points In CrewAI a tool can be attached to an `Agent` or to a `Task`. - `Agent(role=..., goal=..., backstory=..., tools=[...])` — the agent's standing capabilities. Every task this agent executes sees these unless the task overrides them. - `Task(description=..., expected_output=..., agent=..., tools=[...])` — the toolset for this step. When present, it is what the agent is given for that task; the agent's own list is not merged in. The mental model that keeps you out of trouble: **agent tools describe a role, task tools describe a step**, and a step's list is authoritative when you write one. If you set `Task.tools` and forget to include a tool the step still needs, the agent will not have it — a very common first bug, and it surfaces as the LLM inventing a tool call for something that is not in its list, or narrating that it lacks access. ## Why narrow at the task level ### Blast radius This is the security-relevant reason. Consider a researcher agent holding `ScrapeWebsiteTool()`, `FileReadTool()` and a custom `PublishTool()`. Any page it scrapes is untrusted text that lands in the agent's context, and untrusted text can contain instructions. If the publishing tool is in the same step's toolset, a successful injection has somewhere to go. Give the scraping task only the scraper and the file reader, and put publishing in a later task held by a different agent that never sees raw page content. The tool list is the only hard boundary here — the prompt is not one. ### Prompt cost and selection accuracy Every tool the agent holds for a step contributes its name, description and argument schema to the prompt on *every* model call in that step's loop. Twelve tools is a meaningful block of context repeated per iteration, and it is also twelve options the model must discriminate between. Selection accuracy degrades as the catalogue grows, so a task that genuinely needs two tools should be given two. ### Determinism A step with one tool is close to deterministic in structure: the model either calls it or answers. A step with eight is a search problem. When you are hardening a flaky crew, cutting the per-task toolset is usually a faster win than rewriting the task description. ## When to keep tools on the agent instead Put a tool on the agent when it is genuinely part of the role and used across most of that agent's tasks — a support agent's ticket lookup, an analyst's query tool. Duplicating it into every task is noise and drifts out of sync. Agent-level assignment also pairs naturally with per-agent LLM choice and with a YAML-configured crew, where the roles are the stable structure and the tasks change more often. ## Practical checklist 1. Default to agent-level tools for role capabilities. 2. Override at the task level when the step needs *fewer* tools, or a differently-configured instance of the same tool (for example a `FileReadTool` pinned to a specific path). 3. When you override, restate every tool the step needs — nothing is inherited. 4. Never let a step that ingests untrusted external text also hold a write, publish, or execute tool. Split it into two tasks. 5. Watch the agent's reasoning output when a step misbehaves: "I don't have a tool for that" almost always means an override dropped something. ## What interviewers are checking The surface answer is "task tools win". The answer they want next is *why you would ever bother*: least privilege per step, prompt budget, and selection accuracy. Candidates who only know the agent-level form tend to build one over-equipped agent and then debug tool-selection problems by rewriting prompts, which is the slow path.

  • Give a concrete case where narrowing tools per task is a security control, not just tidiness.
    An agent that scrapes web pages holds untrusted text in its context, and that text can carry instructions. If the same step also holds a publishing or file-writing tool, an injection has a path to act. Running the scrape task with only the scraper, and doing the write in a separate task held by an agent that never sees raw page content, removes the path structurally rather than by prompt wording.
  • What is the failure symptom when you override Task.tools and forget one the step needs?
    The agent reports that it lacks the capability, or hallucinates a call to a tool that is not in its list and then has to recover. Because task tools replace rather than extend the agent's list, the omission is silent at configuration time — nothing errors — and only shows up in the agent's reasoning at run time. Restate the full list whenever you override.
  • Why does an over-equipped agent get worse, not better, at picking tools?
    Every tool contributes its name, description and argument schema to the prompt on each iteration of the agent's loop, so a large catalogue both consumes context repeatedly and gives the model more near-neighbours to confuse. Selection accuracy falls as the list grows, which is why trimming the per-step toolset often fixes flakiness faster than rewriting the task description.

saying these in an interview costs you the question

  • Says task tools are appended to the agent's tools
  • Believes tools can only be attached to agents in CrewAI
  • Gives every agent every tool and tunes prompts to compensate
  • Puts a scraping tool and a write tool in the same task's list
  • Thinks a tool the agent holds is free until it is called

context