Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Python: [Feature Request] Memory Poisoning Protection for Semantic Kernel via OWASP Agent Memory Guard

Đang mở
#14,047 5 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 2 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức phù hợp với người mới
25/100
Loại issue
Tính năng
Độ rõ ràng
Cần làm rõ
Mức độ hoạt động
Ít trao đổi
Công nghệ
csharp, python
Lĩnh vực
ai, security

Hướng nghiên cứu

Issue không nêu tên tệp hoặc bài kiểm thử nào của Semantic Kernel. Hãy bắt đầu bằng việc xem xét các điểm tích hợp của ChatHistory, VolatileMemoryStore và các memory store tùy chỉnh, sau đó kiểm tra package agent-memory-guard được liên kết. Công việc được xem là hoàn tất khi có phạm vi tích hợp đã thống nhất kèm tiêu chí xác thực, hoặc một hướng triển khai được xác định rõ phạm vi.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

python triage

Problem

Semantic Kernel agents with persistent memory (ChatHistory, VolatileMemoryStore, or custom stores) are vulnerable to memory poisoning attacks. Adversarial inputs stored in memory can cause agents to leak secrets, ignore instructions, or produce corrupted outputs. OWASP identifies this as a top risk for LLM applications.

Proposed Solution

OWASP Agent Memory Guard (AMG) is an open-source Python library that wraps any memory store as a transparent security layer:

  • pip install agent-memory-guard
  • Scans every memory write for prompt injection, PII leakage, and tampering
  • 92.5% detection rate on AgentThreatBench
  • <5ms latency per scan

Links

Would the Semantic Kernel team consider integrating AMG as a security layer for agent memory? Happy to contribute a PR.

Ngôn ngữ chính
C#
Star
28.6k
Fork
4.8k
Merge trung bình
13 giờ 24 phút
Pull request đã merge (30 ngày)
11

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của microsoft/semantic-kernel

Tất cả issue của microsoft/semantic-kernel

Issue tương tự

Thêm issue về C#

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.