© 2025 Mamta Upadhyay. This article is the intellectual property of the author. No part may be reproduced without permission
Welcome back to the LLM Build Series! In this post, we take a hands-on approach to build your first AI agent. It is lightweight, understandable and fully local. There is a lot of hype around autonomous agents today, but the core ideas are surprisingly simple. You do not need a fleet of GPUs or a massive orchestration framework to get started.
This walkthrough is for anyone curious about:
✔ How AI agents actually work under the hood
✔ How to prototype one locally using open-source models
✔ The core loop of planning, tool use and response
We are not building a full-blown AutoGPT replica. Instead, this will be a compact, functional prototype that mimics how many open-source agents operate behind the scenes.
What you will need
To follow along, you will need:
✔ Python 3.8+
✔ Ollama installed with a model like mistral
✔ duckduckgo-search and openai Python packages
Install dependencies:
mamta@ai-labs:$ pip install duckduckgo-search openai
Run a local LLM model:
mamta@ai-labs:$ ollama run mistral
This exposes an OpenAI-compatible endpoint at localhost:11434, which we can interact with like a regular LLM API.
Step 1: Define the Goal and Agent Planning Loop
We want the agent to accept a natural goal like:
"What are the current threats in AI security?"
Then break it into 2–3 actionable steps.
mamta@ai-labs:$ cat planner.py
from openai import OpenAI
client = OpenAI(base_url="http://localhost:11434/v1", api_key="ollama")
def query_llm(prompt):
response = client.chat.completions.create(
model="mistral",
messages=[{"role": "user", "content": prompt}]
)
return response.choices[0].message.content
def plan_steps(goal):
prompt = f"Break down the following goal into 2–3 clear steps: {goal}"
return query_llm(prompt)
This is the agent’s “planner” converting a goal into actionable subgoals.
Step 2: Add a Simple Tool
To simulate tool use, we use DuckDuckGo Search to fetch public information:
mamta@ai-labs:$ cat tools.py
from duckduckgo_search import DDGS
def search_tool(query):
with DDGS() as ddgs:
results = ddgs.text(query)
return results[0]['body'] if results else "No results found."
You could swap this with any tool like file readers, APIs or even calculators. This structure lets you plug in additional tools later.
Step 3: Create the Agent Execution Loop
This loop connects everything:
mamta@ai-labs:$ cat agent_runner.py
from planner import plan_steps, query_llm
from tools import search_tool
def run_agent(goal):
print("Planning steps...")
steps = plan_steps(goal)
print("\nPlanned Steps:\n", steps)
print("\nRunning tool on step 1...")
result = search_tool(goal)
print("\nTool Result:\n", result)
print("\nSummarizing response...")
summary_prompt = f"Using this result, summarize a final answer to: {goal}\n\n{result}"
final_answer = query_llm(summary_prompt)
print("\nFinal Answer:\n", final_answer)
if __name__ == "__main__":
import sys
if len(sys.argv) > 1:
user_goal = " ".join(sys.argv[1:])
else:
user_goal = input("Enter a goal for the agent: ")
run_agent(user_goal)
This allows you to run the script directly from the command line like this:
python agent_runner.py "What are the current threats in AI security?"
Security Notes
Even a basic agent like this can be vulnerable to prompt injection, especially through web scraped content, tool misuse or unvalidated feedback loops. You should treat agent input and memory the same way you treat user input in secure web apps. Never trust it blindly.
What you Built
In this tutorial, you created:
✔ A planning function using a local LLM
✔ A simple tool integration (web search)
✔ An agent loop that chains planning, action and summarization
This is the core pattern behind many agentic frameworks. You now have a working foundation to build multi-step workflows, tool routing and memory/context awareness.
Source Code
The full code is available here: 👉 https://github.com/m-pentest/my-first-agent
You can clone it and run the agent locally:
git clone https://github.com/mamtaupadhyay/my-first-agent.git cd my-first-agent python agent_runner.py "What are the current threats in AI security?"
Wrap
In the next post in the series, we will add memory to this agent. This will allow your agent to remember past queries, personalize answers and store task histories.
And yes, it will also open up new attack surfaces, which we will explore from a red team perspective.
Stay tuned!
Discover more from The Secure AI Blog
Subscribe to get the latest posts sent to your email.