Skip to content

Python: Warn about unsupported FIDES CodeAct tools - #9175

Merged
Eduard van Valkenburg (eavanvalkenburg) merged 2 commits into
microsoft:mainfrom
eavanvalkenburg:monty-policy-investigation
Oct 8, 2026
Merged

Eduard van Valkenburg (eavanvalkenburg) merged 2 commits into
microsoft:mainfrom
eavanvalkenburg:monty-policy-investigation

Conversation

@eavanvalkenburg

Copy link
Copy Markdown
Member

Motivation & Context

CodeAct providers invoke registered host tools from generated code through a low-level tool path rather than the agent's function-middleware pipeline. FIDES metadata on those tools is therefore not enforced for nested calls. The existing package documentation did not state this compatibility boundary, and registering a tool with FIDES metadata produced no diagnostic.

Description & Review Guide

  • What are the major changes? Monty and Hyperlight now log a registration-time warning when a managed tool contains recognized FIDES metadata. Their package READMEs and the FIDES guide document that this integration is currently unsupported. Unit tests cover constructors, providers, dynamic registration, falsy metadata values, unannotated tools, and run-scoped snapshots.
  • What is the impact of these changes? Invocation, middleware, approval, native-result, and registered-tool counter behavior is unchanged. The warning is diagnostic only and cannot detect every FIDES configuration because defaults also apply to unannotated tools.
  • What do you want reviewers to focus on? Please review the compatibility wording, recognized metadata keys, and the registration-time warning behavior.

Related Issue

N/A. This compatibility clarification is not linked to a public issue. No matching open pull request was found.

Contribution Checklist

  • The code builds clean without any errors or warnings
  • All unit tests pass, and I have added new tests where possible
  • The PR follows the Contribution Guidelines
  • This PR is linked to an issue and there is no other open PR for this issue (see Related Issue above).
  • This is not a breaking change. If it is a breaking change, add the breaking change label (or add "[BREAKING]" to the title prefix, before or after any language prefix) — a workflow keeps the label and title prefix in sync automatically.

Copilot AI balanced review requested due to automatic review settings October 7, 2026 17:18
@agent-framework-automation agent-framework-automation Bot added documentation Usage: [Issues, PRs], Target: documentation in the code base and learn docs python Usage: [Issues, PRs], Target: Python labels Oct 7, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Both implementations re-warn for all previously registered FIDES tools whenever any additional tool is added.

2 open findings
What changed in this PR

Adds diagnostics and documentation for unsupported FIDES usage with CodeAct integrations.

Changes:

  • Warns when Monty or Hyperlight registers tools with FIDES metadata.
  • Documents the compatibility boundary and mitigation guidance.
  • Adds coverage for registration paths and metadata variants.
File Description
python/​samples/​02-agents/​security/​FIDES_DEVELOPER_GUIDE.md Documents CodeAct limitations.
python/​packages/​monty/​tests/​monty/​test_monty_codeact.py Tests Monty warnings.
python/​packages/​monty/​README.md Adds compatibility guidance.
python/​packages/​monty/​agent_framework_monty/​_execute_code_tool.py Implements Monty warnings.
python/​packages/​hyperlight/​tests/​hyperlight/​test_hyperlight_codeact.py Tests Hyperlight warnings.
python/​packages/​hyperlight/​README.md Adds compatibility guidance.
python/​packages/​hyperlight/​agent_framework_hyperlight/​_execute_code_tool.py Implements Hyperlight warnings.

🧠 Review effort: Balanced


💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment thread python/packages/hyperlight/agent_framework_hyperlight/_execute_code_tool.py Outdated
Comment thread python/packages/monty/agent_framework_monty/_execute_code_tool.py Outdated

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

MAF Automated Review — Iteration 1

Result: No findings
Scope: full PR (1 commit(s)): dea2c8c172b1
Model: gpt-5.6-sol

Overview

The PR adds matching best-effort diagnostics to both CodeAct providers and clearly documents that nested host-tool calls bypass FIDES middleware enforcement. Key-presence checks cover all recognized metadata, including falsy values, while preserving tool identity, invocation behavior, and approval handling. Tests exercise both constructors and providers, dynamic registration, unannotated tools, and late metadata discovered through run-scoped snapshots; no Critical, High, or Medium defect was established.

Reviewed the supplied pull-request change set across correctness, security/reliability, architecture, and failure behavior.
No publishable findings remained after source verification for this scope.

Merged via the queue into microsoft:main with commit 26fa33f Oct 8, 2026
46 checks passed
@eavanvalkenburg
Eduard van Valkenburg (eavanvalkenburg) deleted the monty-policy-investigation branch October 8, 2026 08:33

This branch was successfully deployed

1 active deployment
github-app-auth — 3624f796 Deployed Oct 8, 2026 by eavanvalkenburg via add_label #24749
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Usage: [Issues, PRs], Target: documentation in the code base and learn docs python Usage: [Issues, PRs], Target: Python

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants