Python: [Feature]: A deterministic pre-execution verification middleware for agent actions — AgentDojo v2.2 re-run: ASR=0 / FP=0 (open artifacts, full fix-cycle trajectory inside)
Maintainer thường phản hồi trong vòng 1 ngày
@eavanvalkenburg đang làm issue này rồi.
Từ ngày 7/10/2026.
Đánh giá
Issue này chưa được đánh giá.
Mô tả
Description
Discussions like #8862 (budget enforcement in AgentLoopMiddleware) and #7853 (sandbox abstraction for tool execution) point at the same gap: agent frameworks today observe actions, but the decision to block a dangerous action before it executes is usually left ad hoc. We built that missing piece and would like to offer it to this community as a candidate middleware contract.
What it is
agent-action-verifier (https://github.com/Lsy1533133/agent-action-verifier) is a deterministic pre-execution enforcement layer: every pending action (tool call, network egress, file write) is checked against the agent's declared plan before execution. The judge is fixed-constant math — no LLM call in the enforcement path, no learned parameters — so it adds microsecond-scale cost per action (P99 = 0.13 ms in the synthetic stress suite; production latency not yet measured) and is deterministic and auditable by construction.
Closed-loop results (each reported number is backed by a checksummed artifact in the repo)
- AgentDojo official benchmark, real LLM in the loop (97 tasks × 2 rounds, official injection suite, official
security()judgment): ASR = 0, FP = 0 in the v2.2 full re-run (FP-rate 95% upper bound ≈3.8% at n=97 benign rounds) - Published fix-cycle trajectory FP 16 → 1 → 0 across v1.2 → v2.1 → v2.2 — same-source iteration, failures included, not independent stability trials
- Cross-model spot check: GLM subset (24 benign + 24 attack): FP = 0, ASR = 0
- Synthetic stress layer (100,000 seeded scenarios): FN = 0, FP = 0; interception Wilson-95 lower bound 99.99%+ on that synthetic distribution
- White-box adaptive attacks: 49 cases, 16 adaptive vector families — 43 hard-blocked, 0 bypass; 6 boundary cases documented and not counted as bypasses under the stated threat model
Integration shape (matches your middleware seam)
Wrap the action-dispatch point; the verifier receives (declared plan, pending action) and returns PASS / VETO + rule id. verifier_interface.pyi in the repo specifies the contract; typical adapter is ~10 lines around an AgentLoopMiddleware. Rule families: out-of-plan action, egress breach, scope escalation, tool-consent violation, dangerous value class, arithmetic guard, uninitialised state.
Honest boundaries
Synthetic scenarios are abstracted from publicly disclosed incident categories, not production traffic. Same-source fix cycles ≠ independent stability trials. GLM subset vs full run differ in model and sample size and are not directly comparable. This layer complements monitoring/alignment — it does not replace them.
Verify it yourself
python verify_artifacts.py in the repo recomputes every SHA-256 chain and the Wilson-95 bounds from raw counts — no trust required, stdlib only.
We'd genuinely value feedback on the metrics methodology, and if a deterministic enforcement seam fits the framework's roadmap, if maintainers see a fit, we can align the contract with the framework's middleware design.
Code Sample
Language/SDK
Both
- Ngôn ngữ chính
- Python
- Star
- 13.9k
- Fork
- 2.4k
- Merge trung bình
- 1 ngày 18 giờ
- Pull request đã merge (30 ngày)
- 443
Chuẩn bị môi trường
Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của microsoft/agent-framework
-
.NET: Proposal: add an llms.txtĐang mở.NET python triage
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 85/100
microsoft/agent-framework#9092 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Python: raw-data content mappings lose annotations and attachment metadataCó thể đã có người làm @moonbox3 đã nhận 8 ngày trước. Đang mởpython triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
microsoft/agent-framework#8632 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Python: Clarify when to use platformCó thể đã có người làm @eavanvalkenburg đã nhận 8 ngày trước. Đang mởpython triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
microsoft/agent-framework#8599 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
.NET Compaction - Update docs to refer to `AIContextProvider` deep diveCó thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mở.NET compaction documentation
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 82/100
microsoft/agent-framework#4629 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Python: [Bug]: Media type detection documentation examples contain invalid base64Có thể đã có người làm @eavanvalkenburg đã nhận hôm nay. Đang mởagents python reproduced
microsoft/agent-framework#9187 · 1 bình luận · 1 người được giao ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của microsoft/agent-framework
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
Maintainer thường phản hồi trong vòng 1 ngày
-
SR_SECURITY_DESCRIPTOR.fromString drops the SACL when no DACL is presentCó thể đã có người làm @paul7436 đã nhận hôm nay. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
equinor/fmu-sumo-uploader#302 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
modelscope/evalscope#1821 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Sanity on ansible-core devel fails: ignore-2.23.txt references the removed import-3.9 testCó thể đã có người làm @yurnov đã nhận hôm nay. Đang mởneeds_triage
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 91/100
ansible-collections/kubernetes.core#1275 ·
Maintainer thường phản hồi trong vòng 1 ngày