Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Python: feat: governance filter for function calls — deterministic policy evaluation, cost tracking, audit (TealTiger)

オープン
#14,056 コメント 7 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 2 日以内に返信

まだ誰も着手していません。

評価

難易度
5/5
見積もり時間
1週間以上
初心者へのやさしさ
32/100
issue の種類
機能追加
明瞭さ
おおむね明確
活発さ
静か
技術スタック
csharp, python
領域
ai, security

調査の方向性

Python の IFunctionInvocationFilter と FunctionInvocationContext のエントリポイントから始め、Semantic Kernel の既存のフィルターに関するドキュメントとパイプラインも確認する。作業をリポジトリのサンプルとして行うのか、外部統合として行うのかを明確にし、そのうえで、ポリシー評価、コスト追跡、監査記録、プロバイダーのサーキットブレーカーに関する、範囲を限定した最初のスコープと受け入れ基準を定義する。

索引モデルが issue の本文から書いたものです。

説明

.NET python triage

Is your feature request related to a problem? Please describe.

Semantic Kernel's Filter system (IFunctionInvocationFilter, IAutoFunctionInvocationFilter) provides the right interception points for governance, but there's no built-in or community governance filter that:

  • Evaluates deterministic policies before function/plugin execution
  • Enforces per-agent cost budgets (block calls that would exceed daily/session limits)
  • Tracks and attributes LLM cost per agent, per plugin, per session
  • Produces structured audit records for compliance (EU AI Act Article 12)
  • Provides per-provider circuit breaking to prevent cascading failures

Today you'd need to implement custom IFunctionInvocationFilter logic in every project, which doesn't scale.

Describe the solution you'd like

A governance filter that plugs into SK's existing filter pipeline:

Python:

from semantic_kernel import Kernel
from sk_tealtiger import TealTigerFilter

kernel = Kernel()

# Zero-config: observe all function calls, track cost, detect PII
kernel.add_filter("function_invocation", TealTigerFilter())

# With policies
from tealtiger import TealEngine
engine = TealEngine(policies=company_policies, mode="ENFORCE")
kernel.add_filter("function_invocation", TealTigerFilter(engine=engine))

C# (if community demand exists):

var kernel = Kernel.CreateBuilder()
    .AddFilter<TealTigerGovernanceFilter>()
    .Build();

The filter would:

  • Intercept FunctionInvocationContext before execution
  • Evaluate policy against the function name, arguments, and caller context
  • Return ALLOW (proceed), DENY (throw), or REVISE (modify args)
  • Track token cost after execution and check against budget limits
  • Emit structured audit entries with correlation IDs
  • Circuit-break on repeated provider failures

Describe alternatives you've considered

  • Custom IFunctionInvocationFilter per project — works but verbose, no reuse across projects
  • External proxy/sidecar — adds network latency, incompatible with offline/in-process constraint
  • Azure Content Safety service — cloud-dependent, LLM-based (non-deterministic), doesn't handle cost/budget/tool-restriction

Additional context

  • TealTiger — open-source AI agent security platform (Apache-2.0, NVIDIA Inception)
  • Published on PyPI (tealtiger v1.3.0) and npm (tealtiger-ai-sdk v0.1.0)
  • Covers 8/10 OWASP Agentic Security Index categories
  • All governance is deterministic and in-process — no external service, <5ms overhead, works offline
  • Already integrated with LangChain, Vercel AI SDK, CrewAI, and proposals open for LlamaIndex, AG2, Haystack, Pydantic AI, Mastra
  • SK's existing Filter system (per blog post) is the natural integration point
  • EU AI Act compliance angle: structured audit records with retention_until, input/output traceability

References:

Contribution plan: Happy to contribute a Python IFunctionInvocationFilter implementation as a community sample or standalone pip package. Would this be welcome as a sample in the repo or as an external community integration?

主要言語
C#
スター
28.6k
フォーク
4.8k
平均マージ
13時間 24分
マージ済み PR(30日)
11

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

microsoft/semantic-kernel のほかの issue

microsoft/semantic-kernel の issue をすべて見る

似ている issue

C# の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。