[Feature] Official HOL Guard FunctionInvocationFilter security sample
I maintainer di solito rispondono entro 2 giorni
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 55/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Attiva
- Stack tecnologico
- csharp
- Ambito
- ai, documentation, security
Direzione di ricerca
Inizia con l’esempio FunctionInvocationApproval esistente e con il confine IFunctionInvocationFilter, quindi esamina l’adapter HOL Guard e i test del contratto di invocazione nella pull request 52 di hashgraph-online/hol-guard-plugin. Il lavoro è completato quando un esempio ufficiale o un esempio della documentazione mostra una configurazione locale esplicita e copre allow, deny, review e fail-closed per risposte non disponibili o malformate, senza richiedere un accesso a Cloud.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Proposal
Add a small official Semantic Kernel sample/docs example that integrates HOL Guard at the existing IFunctionInvocationFilter boundary. This is not a request for a new generic filter API.
Semantic Kernel already demonstrates that an invocation filter can prevent execution by not calling next(context) in the FunctionInvocationApproval sample. HOL Guard can use that same boundary to evaluate a function invocation locally before execution.
Suggested sample behavior
- install/configure HOL Guard explicitly in the sample
- register a
HolGuardFunctionInvocationFilter : IFunctionInvocationFilter - send the function name + arguments to the local HOL Guard decision path before
next(context) allow-> callnext(context)exactly oncedeny-> return a blocked result and never execute the underlying functionreview-> require an explicit host approval callback; otherwise fail closed- timeout/unavailable/malformed/ambiguous Guard response -> fail closed
- keep HOL Guard Cloud optional; local-only use should work without a Cloud login
Existing implementation evidence
We already maintain a small Semantic Kernel adapter and real invocation-contract tests here: https://github.com/hashgraph-online/hol-guard-plugin/pull/52
That proof is pinned against Semantic Kernel and tests allow/deny/review/unavailable paths, including zero downstream execution on deny. I’m proposing only an official Semantic Kernel sample/docs placement so users can discover and apply HOL Guard through the framework’s existing supported filter seam.
If this placement makes sense, I can follow the project’s fork-first workflow and keep the PR limited to the agreed sample/docs scope.
- Lingua principale
- C#
- Stelle
- 28.6k
- Fork
- 4.8k
- Merge medio
- 13h 24m
- PR unite (30g)
- 11
Preparare l'ambiente
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di microsoft/semantic-kernel
-
python triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
microsoft/semantic-kernel#14491 · 1 commento ·
I maintainer di solito rispondono entro 2 giorni
-
python triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
microsoft/semantic-kernel#14490 · 1 commento ·
I maintainer di solito rispondono entro 2 giorni
-
Python: [Python] structured_outputs_transform reuses ChatHistory across calls (prompt pollution)Apertapython triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
microsoft/semantic-kernel#14483 · 2 commenti ·
I maintainer di solito rispondono entro 2 giorni
-
.NET python triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 74/100
microsoft/semantic-kernel#14482 · 3 commenti ·
I maintainer di solito rispondono entro 2 giorni
-
Python: [Python] as_agent_framework_tool drops parameter defaults (optionals become required)Apertapython triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
microsoft/semantic-kernel#14481 ·
I maintainer di solito rispondono entro 2 giorni
Tutte le issue di microsoft/semantic-kernel
Issue simili
-
go 🏃 testing 🧪
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
valkey-io/valkey-glide#7239 ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
SubtitleEdit/subtitleedit#15462 ·
I maintainer di solito rispondono entro 1 giorno
-
:watch: Not Triaged
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
I maintainer di solito rispondono entro 1 giorno
-
comp:instrumentation.aspnetcore
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
open-telemetry/opentelemetry-dotnet-contrib#5427 ·
I maintainer di solito rispondono entro 1 giorno
-
[feature request] Condier making `TelemetrySpan`'s constructor and `Activity` property publicApertaenhancement needs-triage pkg:OpenTelemetry
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
open-telemetry/opentelemetry-dotnet#7851 · 4 commenti ·
I maintainer di solito rispondono entro 1 giorno