A small habit that has paid for itself repeatedly: every tool I give an agent is named so that a reader can tell if it writes anything, without opening the code.
search_writing, show_page, list_projects are read-only, and the name says nothing else is possible. subscribe_newsletter, create_post, publish_post, send_newsletter are the ones that change state, and each one's name is a verb that admits it. There is no tool called handle_post or process_subscription on this site. Vague verbs are where accidental writes hide, because nobody double-checks a name that sounds harmless.
This started as a naming preference and became a review shortcut. When I read an agent's tool call log, I can tell what actually happened to the system by scanning verbs, before I read a single argument. It also shapes which tools need an ability gate and which do not: if the name says it writes, it needs content:write or stronger. If it does not, it should be safe to hand to anything, including a fully automated pipeline with no human in the loop.
The rule I keep coming back to: a tool's name is documentation that cannot go stale, because it is the only part of the interface the model actually reads every single time.