Agentic Workflow Workshop

Don WoodlockAbout 4 min readFeb 17, 2026Watch original
THE SUMMARYAI-generated

Key Concepts

  • Agentic AI: A paradigm shift in AI utilizing LLMs with agency – the ability to make decisions, call tools, and navigate non-deterministic workflows.
  • RAG vs. Agentic Workflows: RAG provides fixed-context answers, while Agentic workflows iteratively gather information through tool calls, mimicking human reasoning.
  • MCP (Model Context Protocol): A standardized protocol for LLM tool access, enabling language-agnostic integration and vendor control.
  • Prompt Injection: A critical security vulnerability where unintended data, potentially containing sensitive information, is included in prompts sent to LLMs.
  • Three AI Development Approaches: Hand-coding, Machine Learning (ML), and Agentic workflows, each with distinct strengths and weaknesses.

Introduction to Agentic AI & its Core Components (Part 1)

The workshop began with an introduction to Agentic AI, defined as a distinct style of utilizing Large Language Models (LLMs) characterized by multi-step workflows, tool calling, and non-deterministic workflows. Don contrasted this with Retrieval Augmented Generation (RAG), noting that while RAG is faster, it’s limited by pre-defined context. Agentic AI, conversely, allows for more flexible context gathering and the ability to take action beyond simply answering questions, granting the LLM “agency” – the ability to make decisions and control the workflow. He emphasized that Agentic AI allows the LLM to actively interact with its environment through tools. The evolution of tool calling was outlined, starting with XML-based approaches, progressing through frameworks like LangChain and LangGraph, and culminating in native tool calling support within LLM APIs (Anthropic, OpenAI) within the last 18 months.

Direct Orchestration & the Model Context Protocol (MCP) (Part 1)

Marta led a hands-on exercise demonstrating “direct orchestration” – building an agent from scratch without high-level frameworks. The example application was a shopping assistant, implemented by defining Python functions for cart manipulation, providing a system prompt with tool descriptions, and implementing an agentic loop that sends prompts, parses responses for tool calls, executes tools, and relays output back to the LLM. The agent is the orchestrator of the workflow, while the LLM provides the reasoning. Georgia then introduced the Model Context Protocol (MCP) as a solution to the “end times integration problem” – the difficulty of integrating LLMs with diverse tools. MCP aims to standardize tool access and enable language-agnostic integration, utilizing JSON RPC for communication and offering benefits like language agnosticism and vendor control.

Implementing Agentic Workflows with MCP & LangChain (Part 2)

The second segment detailed the implementation of agentic workflows using the MCP and LangChain frameworks. The MCP protocol enables LLMs to discover and utilize tools at runtime, offering language agnosticism and vendor control over data returned. While frameworks like LangChain provide convenience, they introduce language and interface lock-in. The segment demonstrated setting up an MCP server to host functions using FastAPI and SSC Server Transport (for local execution) or HTTP (for remote execution), and interacting with it via a Python SDK. A real-world example of modernizing a legacy web application using a single "bash" tool was presented, alongside a cautionary demonstration of a prompt injection attack involving a malicious shell command embedded in a lab result comment, highlighting security risks.

Security Concerns & the Three Approaches to AI (Part 3)

The final segment focused on the potential for “prompt injection” – the unintentional inclusion of sensitive data into prompts sent to LLMs, emphasizing that the vulnerability lies in unvalidated external data. The presentation then contrasted three approaches to AI development: traditional hand-coding (99% of current work), Machine Learning (ML) – exemplified by cat vs. dog image recognition – and Agentic workflows. ML leverages “data as the brain,” learning through inference and pattern matching, while Agentic workflows position the LLM as the brain, requiring configuration (approximately 250 lines of code) and enabling “tool calling” for decision-making. Agentic workflows excel at navigating the “non-deterministic nature of life” and handling complex, unpredictable scenarios like scheduling a patient appointment, surpassing the capabilities of hand-coded algorithms and traditional ML.


Conclusion

The workshop demonstrated a significant shift in AI development with the introduction of Agentic AI. By granting LLMs agency through tool calling and iterative workflows, Agentic systems offer a powerful approach to solving complex, real-world problems. While frameworks like LangChain and protocols like MCP simplify implementation, security considerations – particularly prompt injection – remain paramount. The potential of Agentic AI lies in its ability to adapt to unpredictable situations and “work your way through” complexities, representing a promising evolution beyond traditional AI paradigms.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.