Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Python: feat: governance filter for function calls — deterministic policy evaluation, cost tracking, audit (TealTiger)

Aperta
#14,056 7 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 2 giorni

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
5/5
Tempo stimato
Più di una settimana
Idoneità per principianti
32/100
Tipo di issue
Funzionalità
Chiarezza
Abbastanza chiara
Stato di attività
Tranquilla
Stack tecnologico
csharp, python
Ambito
ai, security

Direzione di ricerca

Inizia dagli entry point Python IFunctionInvocationFilter e FunctionInvocationContext, insieme alla documentazione e alla pipeline dei filtri esistenti di Semantic Kernel. Chiarisci se il lavoro debba essere realizzato come esempio nel repository o come integrazione esterna, quindi definisci un primo ambito circoscritto e i criteri di accettazione per la valutazione delle policy, il monitoraggio dei costi, i record di audit e il circuit breaking dei provider.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

.NET python triage

Is your feature request related to a problem? Please describe.

Semantic Kernel's Filter system (IFunctionInvocationFilter, IAutoFunctionInvocationFilter) provides the right interception points for governance, but there's no built-in or community governance filter that:

  • Evaluates deterministic policies before function/plugin execution
  • Enforces per-agent cost budgets (block calls that would exceed daily/session limits)
  • Tracks and attributes LLM cost per agent, per plugin, per session
  • Produces structured audit records for compliance (EU AI Act Article 12)
  • Provides per-provider circuit breaking to prevent cascading failures

Today you'd need to implement custom IFunctionInvocationFilter logic in every project, which doesn't scale.

Describe the solution you'd like

A governance filter that plugs into SK's existing filter pipeline:

Python:

from semantic_kernel import Kernel
from sk_tealtiger import TealTigerFilter

kernel = Kernel()

# Zero-config: observe all function calls, track cost, detect PII
kernel.add_filter("function_invocation", TealTigerFilter())

# With policies
from tealtiger import TealEngine
engine = TealEngine(policies=company_policies, mode="ENFORCE")
kernel.add_filter("function_invocation", TealTigerFilter(engine=engine))

C# (if community demand exists):

var kernel = Kernel.CreateBuilder()
    .AddFilter<TealTigerGovernanceFilter>()
    .Build();

The filter would:

  • Intercept FunctionInvocationContext before execution
  • Evaluate policy against the function name, arguments, and caller context
  • Return ALLOW (proceed), DENY (throw), or REVISE (modify args)
  • Track token cost after execution and check against budget limits
  • Emit structured audit entries with correlation IDs
  • Circuit-break on repeated provider failures

Describe alternatives you've considered

  • Custom IFunctionInvocationFilter per project — works but verbose, no reuse across projects
  • External proxy/sidecar — adds network latency, incompatible with offline/in-process constraint
  • Azure Content Safety service — cloud-dependent, LLM-based (non-deterministic), doesn't handle cost/budget/tool-restriction

Additional context

  • TealTiger — open-source AI agent security platform (Apache-2.0, NVIDIA Inception)
  • Published on PyPI (tealtiger v1.3.0) and npm (tealtiger-ai-sdk v0.1.0)
  • Covers 8/10 OWASP Agentic Security Index categories
  • All governance is deterministic and in-process — no external service, <5ms overhead, works offline
  • Already integrated with LangChain, Vercel AI SDK, CrewAI, and proposals open for LlamaIndex, AG2, Haystack, Pydantic AI, Mastra
  • SK's existing Filter system (per blog post) is the natural integration point
  • EU AI Act compliance angle: structured audit records with retention_until, input/output traceability

References:

Contribution plan: Happy to contribute a Python IFunctionInvocationFilter implementation as a community sample or standalone pip package. Would this be welcome as a sample in the repo or as an external community integration?

Lingua principale
C#
Stelle
28.6k
Fork
4.8k
Merge medio
13h 24m
PR unite (30g)
11

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di microsoft/semantic-kernel

Tutte le issue di microsoft/semantic-kernel

Issue simili

Altre issue su C#

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.