[Feature] Official HOL Guard FunctionInvocationFilter security sample
Maintainer thường phản hồi trong vòng 2 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 55/100
- Loại issue
- Tính năng
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- csharp
- Lĩnh vực
- ai, documentation, security
Hướng nghiên cứu
Bắt đầu với sample FunctionInvocationApproval hiện có và boundary IFunctionInvocationFilter, sau đó xem xét adapter HOL Guard và các invocation-contract test trong pull request 52 của hashgraph-online/hol-guard-plugin. Được coi là hoàn thành khi một sample chính thức hoặc ví dụ trong tài liệu thể hiện cấu hình cục bộ rõ ràng và bao quát allow, deny, review cùng fail-closed đối với các response không khả dụng hoặc không đúng định dạng, mà không yêu cầu đăng nhập Cloud.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Proposal
Add a small official Semantic Kernel sample/docs example that integrates HOL Guard at the existing IFunctionInvocationFilter boundary. This is not a request for a new generic filter API.
Semantic Kernel already demonstrates that an invocation filter can prevent execution by not calling next(context) in the FunctionInvocationApproval sample. HOL Guard can use that same boundary to evaluate a function invocation locally before execution.
Suggested sample behavior
- install/configure HOL Guard explicitly in the sample
- register a
HolGuardFunctionInvocationFilter : IFunctionInvocationFilter - send the function name + arguments to the local HOL Guard decision path before
next(context) allow-> callnext(context)exactly oncedeny-> return a blocked result and never execute the underlying functionreview-> require an explicit host approval callback; otherwise fail closed- timeout/unavailable/malformed/ambiguous Guard response -> fail closed
- keep HOL Guard Cloud optional; local-only use should work without a Cloud login
Existing implementation evidence
We already maintain a small Semantic Kernel adapter and real invocation-contract tests here: https://github.com/hashgraph-online/hol-guard-plugin/pull/52
That proof is pinned against Semantic Kernel and tests allow/deny/review/unavailable paths, including zero downstream execution on deny. I’m proposing only an official Semantic Kernel sample/docs placement so users can discover and apply HOL Guard through the framework’s existing supported filter seam.
If this placement makes sense, I can follow the project’s fork-first workflow and keep the PR limited to the agreed sample/docs scope.
- Ngôn ngữ chính
- C#
- Star
- 28.6k
- Fork
- 4.8k
- Merge trung bình
- 13 giờ 24 phút
- Pull request đã merge (30 ngày)
- 11
Chuẩn bị môi trường
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của microsoft/semantic-kernel
-
python triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
microsoft/semantic-kernel#14491 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
-
python triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
microsoft/semantic-kernel#14490 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Python: [Python] structured_outputs_transform reuses ChatHistory across calls (prompt pollution)Đang mởpython triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
microsoft/semantic-kernel#14483 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
-
.NET python triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
microsoft/semantic-kernel#14482 · 3 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Python: [Python] as_agent_framework_tool drops parameter defaults (optionals become required)Đang mởpython triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
microsoft/semantic-kernel#14481 ·
Maintainer thường phản hồi trong vòng 2 ngày
Tất cả issue của microsoft/semantic-kernel
Issue tương tự
-
agentic-workflows area/Docs partner/agentic-workflows
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
microsoft/fluentui-blazor#5364 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
.NET triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
microsoft/agent-framework#8811 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
.NET Docs
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 82/100
getsentry/sentry-dotnet#5637 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
QuantConnect/Lean#9842 ·
Maintainer thường phản hồi trong vòng 1 ngày