Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

BUG: label queries only return the final conversation of an attack

Open Beginner friendly
#3,095 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 2 days

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
85/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
python
Domain
databases

Research direction

The bug is in _get_message_pieces_memory_label_conditions in sqlite_memory.py and azure_sql_memory.py, where the join only pulls pieces from the final conversation of an attack. Adjust the join condition to also match ConversationEntry.attack_result_id == AttackResultEntry.id to include all conversations tied to the attack result, then run the provided mock target repro to confirm label queries return all expected pieces for PromptSendingAttack and RedTeamingAttack.

Written by the indexing model from the issue text.

Description

get_message_pieces_async(labels=...) only returns pieces from the attack result's final conversation_id. Labels now live on AttackResultEntry, and the condition (_get_message_pieces_memory_label_conditions in sqlite_memory.py and azure_sql_memory.py) only joins on AttackResultEntry.conversation_id == PromptMemoryEntry.conversation_id. The docstring says it also matches labels on the piece itself, but that branch is gone.

So everything else an attack sent drops out of label queries: PromptSendingAttack retry attempts, Crescendo's pruned conversations, the adversarial chat in RedTeaming/Crescendo/TAP, and every TAP branch except the best one. The memory docs still say labels apply "to all prompts sent by any attack".

Repro with mock targets:

PromptSendingAttack(max_attempts_on_failure=2): pieces sent in this attack=6, returned by labels query=2
RedTeamingAttack: objective-conv pieces=4, adversarial-conv pieces=5, returned by labels query=4

The Conversation table already has attack_result_id for these conversations, so one option is to also match ConversationEntry.conversation_id == PromptMemoryEntry.conversation_id AND ConversationEntry.attack_result_id == AttackResultEntry.id. Whether adversarial-chat prompts should come back is a design call (they'd also get picked up by label-based batch scoring), so filing as an issue first. #3063 touches the same functions for dotted keys.

Dominant language
Python
Stars
4.6k
Forks
944
Avg merge
3d 1h
Merged PRs (30d)
278

Getting set up

Open in Codespaces

Starts the project's dev container in your browser, under your own GitHub account.

  • No Dockerfile or Docker Compose file
  • Has a pull request template
  • No contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from microsoft/PyRIT

All issues in microsoft/PyRIT

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.