Skip to content

Python: Minor changes to inpsect_variable, quarantined_llm and tool approval exception - #5352

Merged
Eduard van Valkenburg (eavanvalkenburg) merged 1 commit into
microsoft:feature/python-fidesfrom
shrutitople:local-fides
Apr 20, 2026
Merged

Python: Minor changes to inpsect_variable, quarantined_llm and tool approval exception#5352
Eduard van Valkenburg (eavanvalkenburg) merged 1 commit into
microsoft:feature/python-fidesfrom
shrutitople:local-fides

Conversation

@shrutitople

Copy link
Copy Markdown
Contributor

Motivation and Context

Minor changes to the tool approval exception in _tools.py, and security tools --- inspect_variable and quarantined_llm.
Few other changes to documentation based on copilot review.

Description

[_security.py]— Simplify quarantined_llm by removing tool-internal auto-hide logic (auto_hide_result parameter). The tool now declares source_integrity="untrusted" and relies on the middleware's standard auto-hide path. Also changed inspect_variable from approval_mode="always_require" to "never_require" — security is enforced by context tainting instead.

[_tools.py] — Fix _auto_invoke_function to preserve function_approval_request type through MiddlewareTermination, so the approval flow in _handle_function_call_results activates correctly for security policy violations.

[test_security.py] — Update tests to match the simplified quarantined_llm API (no auto_hide_result), add test for source_integrity declaration, add test verifying function_approval_request is preserved through _auto_invoke_function, and update inspect_variable approval mode assertion.

[FIDES_DEVELOPER_GUIDE.md] — Update documentation to reflect the simplified auto-hide mechanism and inspect_variable approval changes.

[README.md]— Fix broken file paths in examples and "More Information" section.

FIDES_IMPLEMENTATION_SUMMARY.md — Fix ADR reference (0011 → 0024).

@moonbox3 Evan Mattson (moonbox3) added documentation Usage: [Issues, PRs], Target: documentation in the code base and learn docs python Usage: [Issues, PRs], Target: Python labels Apr 19, 2026
@github-actions github-actions Bot changed the title Minor changes to inpsect_variable, quarantined_llm and tool approval exception Python: Minor changes to inpsect_variable, quarantined_llm and tool approval exception Apr 19, 2026
@eavanvalkenburg
Eduard van Valkenburg (eavanvalkenburg) merged commit b6fcc85 into microsoft:feature/python-fides Apr 20, 2026
6 checks passed
Giles Odigwe (giles17) pushed a commit to giles17/agent-framework that referenced this pull request May 5, 2026
…5331)

* Python: Information-flow control based prompt injection defense (microsoft#5024)

* fides integration

* documentation

* documentation

* documentation

* human-approval on policy violation

* numenous hyena 'works'

* IFC based implementation

* minor edits in documentation

* rebasing the branch and running the email example

* Add security tests for IFC middleware

* Fix Role.TOOL NameError in approval handling

* tiered labelling scheme

* 3 tier labelling scheme in middleware

* Adapt security middleware to list[Content] tool results

* Refactor SecureAgentConfig as context provider and address Copilot review comments

* Update FIDES docs to reflect context provider pattern and update code for ContextProvider rename

* Fix security examples: use OpenAIChatClient instead of non-existent AzureOpenAIChatClient

* Address PR review: consolidate security modules, remove ContentLineage, update docs

* remove unrelated files

* remove comment from _tools.py and rename decision file

* Fix CI failures: Bandit B110, broken md links, hosted approval passthrough

* apply template to decision doc 0024

* minor fixes to decision doc 0024

---------

Co-authored-by: Aashish <t-akolluri@microsoft.com>

* Python: follow up FIDES security flow (microsoft#5330)

* Python: follow up FIDES security flow

Refine the secure approval path, mark the security classes with the FIDES experimental feature label, and clean up the related docs/tests. Also fix workspace-level validation regressions uncovered while running the full Python check suite.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Python: remove FIDES GitHub MCP sample

Drop the GitHub MCP security sample from the FIDES follow-up branch while keeping the remaining security docs and samples intact.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Address PR review: fix paths and update FIDES implementation (microsoft#5352)

* Python: updated import naming and comment from review (microsoft#5421)

* updated import naming and comment from review

* Add approval replay None call-id test

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Python: Address PR 5331 comments and track sesssion while calling Agent in email_security_example (microsoft#5446)

* Address PR review: fix paths and update FIDES implementation

* Address PR comments and add session tracking in email example in samples

* Fix session creation and resolve merge conflict in docstring example

* Resolve merge conflict in docstring example

* Python: add test for empty-message pruning in approval result replacement (microsoft#5617)

Adds test coverage for the second-pass logic in
`_replace_approval_contents_with_results` that removes messages whose
`contents` list becomes empty after first-pass content removal.

Addresses review comment on PR microsoft#5331:
microsoft#5331 (comment)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: shrutitople <shruti.tople@gmail.com>
Co-authored-by: Aashish <t-akolluri@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Usage: [Issues, PRs], Target: documentation in the code base and learn docs python Usage: [Issues, PRs], Target: Python

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants