Repair Economics for Tool-Calling LLM Agents: the Gain, the Side Effects and the Cost of Failure Recovery
Agents built on large language models (LLMs) do their work by calling tools, and tools fail. The default engineering answer — “wrap it in a retry” — is never costed. We study repair economics: what a failure-recovery strategy buys in task success, what it costs in API calls, and what it leaves behind in duplicate or unplanned side effects. We build a controlled testbed in which faults are injected deterministically on the server, repair policies act in a framework layer the agent cannot see, and grading reads only the server-side state, never the agent's own account. Four task families and seven fault types (acknowledgement loss, rate limiting, transient server error, schema drift, silently truncated payloads, permission denial and credential expiry) give 20 applicable task–fault cells, which we run against six policies at $0 per run because no model is involved: none, retry, validate, tx, idem, and an oracle that looks up the minimally sufficient action per error code. A second study puts an LLM agent under exactly the same faults with the policy layer switched off. Four results stand out. (i) Idempotency, not complexity, is the dividing line: idem attains the highest success rate (48/60) with zero duplicate side effects and 28% fewer calls than the heavier transactional policy (306 vs. 426). (ii) Counter-intuitively, adding response validation produces more duplicated writes than plain retry (9 vs. 6 over 60 cells): when a write has in fact landed but its response looks wrong, a validating client declares failure and sends it again. (iii) On a permanent error, diligence is pure waste: no policy succeeds under permission denial, yet retry and validate burn twice the calls of policies that stop at the first 403. (iv) Credential expiry is not a retry problem but a refresh problem — only policies that re-acquire a token recover. Left to its own devices the agent recovers well — 98 of 124 episodes, against 10% for a policy-less framework and 60% for blind retry on the same cells — but it never once used an idempotency key, in any condition, including the two that name the flag in the instructions; and the condition with an explicit per-fault recipe left more duplicate writes (6) than the condition with no warning at all (3), because the recipe says “read first, then re-send under the same key” and the agent did the reading without the key. Instruction is not the same as mechanism, and the gap between them is measurable in the database. The deposit contains the manuscript PDF (21 pages), the testbed, the task definitions, the deterministic matrix (360 runs) and the agent study (124 episodes) with the raw server-side states and audit logs, the analysis and figure scripts, and the evidence table that maps every number in the text to the file it came from.
Authors
- Heng Li (ORCID: https://orcid.org/0000-0003-4874-2874)
Institutions
- Central South University (CN)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-10-03
- DOI
- https://doi.org/10.5281/zenodo.23117823
- Primary Topic
- Software System Performance and Reliability
- Type
- preprint