[Feature] Official HOL Guard FunctionInvocationFilter security sample
Los mantenedores suelen responder en 4 días
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 55/100
- Tipo de issue
- Nueva funcionalidad
- Claridad
- Bastante claro
- Estado de actividad
- Activo
- Stack tecnológico
- csharp
- Área
- ai, documentation, security
Línea de trabajo
Comienza con el ejemplo existente de FunctionInvocationApproval y el límite IFunctionInvocationFilter; después revisa el adaptador HOL Guard y las pruebas del contrato de invocación en el pull request 52 de hashgraph-online/hol-guard-plugin. Se considera terminado cuando un ejemplo oficial o un ejemplo de la documentación muestra una configuración local explícita y cubre allow, deny, review y fail-closed para respuestas no disponibles o malformadas, sin requerir un inicio de sesión en Cloud.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Proposal
Add a small official Semantic Kernel sample/docs example that integrates HOL Guard at the existing IFunctionInvocationFilter boundary. This is not a request for a new generic filter API.
Semantic Kernel already demonstrates that an invocation filter can prevent execution by not calling next(context) in the FunctionInvocationApproval sample. HOL Guard can use that same boundary to evaluate a function invocation locally before execution.
Suggested sample behavior
- install/configure HOL Guard explicitly in the sample
- register a
HolGuardFunctionInvocationFilter : IFunctionInvocationFilter - send the function name + arguments to the local HOL Guard decision path before
next(context) allow-> callnext(context)exactly oncedeny-> return a blocked result and never execute the underlying functionreview-> require an explicit host approval callback; otherwise fail closed- timeout/unavailable/malformed/ambiguous Guard response -> fail closed
- keep HOL Guard Cloud optional; local-only use should work without a Cloud login
Existing implementation evidence
We already maintain a small Semantic Kernel adapter and real invocation-contract tests here: https://github.com/hashgraph-online/hol-guard-plugin/pull/52
That proof is pinned against Semantic Kernel and tests allow/deny/review/unavailable paths, including zero downstream execution on deny. I’m proposing only an official Semantic Kernel sample/docs placement so users can discover and apply HOL Guard through the framework’s existing supported filter seam.
If this placement makes sense, I can follow the project’s fork-first workflow and keep the PR limited to the agreed sample/docs scope.
- Lenguaje dominante
- C#
- Estrellas
- 28.6k
- Forks
- 4.8k
- Merge medio
- 1 d 3 h
- PR fusionados (30 d)
- 16
Preparar el entorno
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de microsoft/semantic-kernel
-
python triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
microsoft/semantic-kernel#14512 · 1 comentario ·
Los mantenedores suelen responder en 4 días
-
.NET python triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
microsoft/semantic-kernel#14511 ·
Los mantenedores suelen responder en 4 días
-
python triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
microsoft/semantic-kernel#14491 · 1 comentario ·
Los mantenedores suelen responder en 4 días
-
python triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
microsoft/semantic-kernel#14490 · 1 comentario ·
Los mantenedores suelen responder en 4 días
-
Python: [Python] structured_outputs_transform reuses ChatHistory across calls (prompt pollution)Abiertopython triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
microsoft/semantic-kernel#14483 · 2 comentarios ·
Los mantenedores suelen responder en 4 días
Todos los issues de microsoft/semantic-kernel
Issues similares
-
bug P3
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
nightscout/nocturne#1908 ·
Los mantenedores suelen responder en 1 día
-
bug documentation Needs: Triage :mag:
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
-
WPF: each page's `Title` overwrites the window title, and returning to a page does not restore itAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
Los mantenedores suelen responder en 1 día
-
agentic-workflows area/Docs partner/agentic-workflows
Dificultad 1/5 Menos de una hora Aptitud para principiantes 82/100
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
jamesmontemagno/tiny-clips#378 · 2 comentarios ·
Los mantenedores suelen responder en 1 día