Python: feat: governance filter for function calls — deterministic policy evaluation, cost tracking, audit (TealTiger)
メンテナーはふだん 2 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 32/100
調査の方向性
Python の IFunctionInvocationFilter と FunctionInvocationContext のエントリポイントから始め、Semantic Kernel の既存のフィルターに関するドキュメントとパイプラインも確認する。作業をリポジトリのサンプルとして行うのか、外部統合として行うのかを明確にし、そのうえで、ポリシー評価、コスト追跡、監査記録、プロバイダーのサーキットブレーカーに関する、範囲を限定した最初のスコープと受け入れ基準を定義する。
索引モデルが issue の本文から書いたものです。
説明
Is your feature request related to a problem? Please describe.
Semantic Kernel's Filter system (IFunctionInvocationFilter, IAutoFunctionInvocationFilter) provides the right interception points for governance, but there's no built-in or community governance filter that:
- Evaluates deterministic policies before function/plugin execution
- Enforces per-agent cost budgets (block calls that would exceed daily/session limits)
- Tracks and attributes LLM cost per agent, per plugin, per session
- Produces structured audit records for compliance (EU AI Act Article 12)
- Provides per-provider circuit breaking to prevent cascading failures
Today you'd need to implement custom IFunctionInvocationFilter logic in every project, which doesn't scale.
Describe the solution you'd like
A governance filter that plugs into SK's existing filter pipeline:
Python:
from semantic_kernel import Kernel
from sk_tealtiger import TealTigerFilter
kernel = Kernel()
# Zero-config: observe all function calls, track cost, detect PII
kernel.add_filter("function_invocation", TealTigerFilter())
# With policies
from tealtiger import TealEngine
engine = TealEngine(policies=company_policies, mode="ENFORCE")
kernel.add_filter("function_invocation", TealTigerFilter(engine=engine))
C# (if community demand exists):
var kernel = Kernel.CreateBuilder()
.AddFilter<TealTigerGovernanceFilter>()
.Build();
The filter would:
- Intercept
FunctionInvocationContextbefore execution - Evaluate policy against the function name, arguments, and caller context
- Return ALLOW (proceed), DENY (throw), or REVISE (modify args)
- Track token cost after execution and check against budget limits
- Emit structured audit entries with correlation IDs
- Circuit-break on repeated provider failures
Describe alternatives you've considered
- Custom
IFunctionInvocationFilterper project — works but verbose, no reuse across projects - External proxy/sidecar — adds network latency, incompatible with offline/in-process constraint
- Azure Content Safety service — cloud-dependent, LLM-based (non-deterministic), doesn't handle cost/budget/tool-restriction
Additional context
- TealTiger — open-source AI agent security platform (Apache-2.0, NVIDIA Inception)
- Published on PyPI (
tealtigerv1.3.0) and npm (tealtiger-ai-sdkv0.1.0) - Covers 8/10 OWASP Agentic Security Index categories
- All governance is deterministic and in-process — no external service, <5ms overhead, works offline
- Already integrated with LangChain, Vercel AI SDK, CrewAI, and proposals open for LlamaIndex, AG2, Haystack, Pydantic AI, Mastra
- SK's existing Filter system (per blog post) is the natural integration point
- EU AI Act compliance angle: structured audit records with
retention_until, input/output traceability
References:
- https://github.com/agentguard-ai/tealtiger — TealTiger source (Apache-2.0)
- https://pypi.org/project/tealtiger/ — TealTiger on PyPI (v1.3.0)
- https://www.npmjs.com/package/tealtiger-ai-sdk — Vercel AI SDK middleware (v0.1.0)
- https://devblogs.microsoft.com/agent-framework/filters-in-semantic-kernel/ — SK Filters blog post
- https://owasp.org/www-project-top-10-for-large-language-model-applications/ — OWASP Agentic Security Index
Contribution plan: Happy to contribute a Python IFunctionInvocationFilter implementation as a community sample or standalone pip package. Would this be welcome as a sample in the repo or as an external community integration?
- 主要言語
- C#
- スター
- 28.6k
- フォーク
- 4.8k
- 平均マージ
- 13時間 24分
- マージ済み PR(30日)
- 11
環境構築
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
microsoft/semantic-kernel のほかの issue
-
python triage
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
microsoft/semantic-kernel#14491 · コメント 1 件 ·
メンテナーはふだん 2 日以内に返信
-
python triage
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
microsoft/semantic-kernel#14490 · コメント 1 件 ·
メンテナーはふだん 2 日以内に返信
-
Python: [Python] structured_outputs_transform reuses ChatHistory across calls (prompt pollution)オープンpython triage
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
microsoft/semantic-kernel#14483 · コメント 2 件 ·
メンテナーはふだん 2 日以内に返信
-
.NET python triage
難易度 2/5 1〜3時間 初心者へのやさしさ 74/100
microsoft/semantic-kernel#14482 · コメント 3 件 ·
メンテナーはふだん 2 日以内に返信
-
python triage
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
microsoft/semantic-kernel#14481 ·
メンテナーはふだん 2 日以内に返信
microsoft/semantic-kernel の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
SubtitleEdit/subtitleedit#15462 ·
メンテナーはふだん 1 日以内に返信
-
:watch: Not Triaged
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
メンテナーはふだん 1 日以内に返信
-
comp:instrumentation.aspnetcore
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
open-telemetry/opentelemetry-dotnet-contrib#5427 ·
メンテナーはふだん 1 日以内に返信
-
design-proposal
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
dotnet/aspnetcore#69592 ·
メンテナーはふだん 1 日以内に返信
-
Client Container Registry customer-reported needs-team-attention question Service Attention
難易度 2/5 1〜3時間 初心者へのやさしさ 74/100
Azure/azure-sdk-for-net#63470 · コメント 3 件 · リアクション 1 件 ·
メンテナーはふだん 1 日以内に返信