Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Python: feat: governance filter for function calls — deterministic policy evaluation, cost tracking, audit (TealTiger)

Đang mở
#14,056 7 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 2 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức phù hợp với người mới
32/100
Loại issue
Tính năng
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Ít trao đổi
Công nghệ
csharp, python
Lĩnh vực
ai, security

Hướng nghiên cứu

Bắt đầu với các điểm vào Python IFunctionInvocationFilter và FunctionInvocationContext, cùng với tài liệu và pipeline filter hiện có của Semantic Kernel. Làm rõ liệu công việc này thuộc về một sample trong repository hay một tích hợp bên ngoài, sau đó xác định phạm vi đầu tiên được giới hạn rõ ràng và các tiêu chí nghiệm thu cho việc đánh giá policy, theo dõi chi phí, bản ghi audit và circuit breaking cho provider.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

.NET python triage

Is your feature request related to a problem? Please describe.

Semantic Kernel's Filter system (IFunctionInvocationFilter, IAutoFunctionInvocationFilter) provides the right interception points for governance, but there's no built-in or community governance filter that:

  • Evaluates deterministic policies before function/plugin execution
  • Enforces per-agent cost budgets (block calls that would exceed daily/session limits)
  • Tracks and attributes LLM cost per agent, per plugin, per session
  • Produces structured audit records for compliance (EU AI Act Article 12)
  • Provides per-provider circuit breaking to prevent cascading failures

Today you'd need to implement custom IFunctionInvocationFilter logic in every project, which doesn't scale.

Describe the solution you'd like

A governance filter that plugs into SK's existing filter pipeline:

Python:

from semantic_kernel import Kernel
from sk_tealtiger import TealTigerFilter

kernel = Kernel()

# Zero-config: observe all function calls, track cost, detect PII
kernel.add_filter("function_invocation", TealTigerFilter())

# With policies
from tealtiger import TealEngine
engine = TealEngine(policies=company_policies, mode="ENFORCE")
kernel.add_filter("function_invocation", TealTigerFilter(engine=engine))

C# (if community demand exists):

var kernel = Kernel.CreateBuilder()
    .AddFilter<TealTigerGovernanceFilter>()
    .Build();

The filter would:

  • Intercept FunctionInvocationContext before execution
  • Evaluate policy against the function name, arguments, and caller context
  • Return ALLOW (proceed), DENY (throw), or REVISE (modify args)
  • Track token cost after execution and check against budget limits
  • Emit structured audit entries with correlation IDs
  • Circuit-break on repeated provider failures

Describe alternatives you've considered

  • Custom IFunctionInvocationFilter per project — works but verbose, no reuse across projects
  • External proxy/sidecar — adds network latency, incompatible with offline/in-process constraint
  • Azure Content Safety service — cloud-dependent, LLM-based (non-deterministic), doesn't handle cost/budget/tool-restriction

Additional context

  • TealTiger — open-source AI agent security platform (Apache-2.0, NVIDIA Inception)
  • Published on PyPI (tealtiger v1.3.0) and npm (tealtiger-ai-sdk v0.1.0)
  • Covers 8/10 OWASP Agentic Security Index categories
  • All governance is deterministic and in-process — no external service, <5ms overhead, works offline
  • Already integrated with LangChain, Vercel AI SDK, CrewAI, and proposals open for LlamaIndex, AG2, Haystack, Pydantic AI, Mastra
  • SK's existing Filter system (per blog post) is the natural integration point
  • EU AI Act compliance angle: structured audit records with retention_until, input/output traceability

References:

Contribution plan: Happy to contribute a Python IFunctionInvocationFilter implementation as a community sample or standalone pip package. Would this be welcome as a sample in the repo or as an external community integration?

Ngôn ngữ chính
C#
Star
28.6k
Fork
4.8k
Merge trung bình
13 giờ 24 phút
Pull request đã merge (30 ngày)
11

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của microsoft/semantic-kernel

Tất cả issue của microsoft/semantic-kernel

Issue tương tự

Thêm issue về C#

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.