Repository navigation
Python: Warn about unsupported FIDES CodeAct tools - #9175
Eduard van Valkenburg (eavanvalkenburg) merged 2 commits into
Conversation
There was a problem hiding this comment.
🟡 Changes recommended
Both implementations re-warn for all previously registered FIDES tools whenever any additional tool is added.
2 open findings
What changed in this PR
Adds diagnostics and documentation for unsupported FIDES usage with CodeAct integrations.
Changes:
- Warns when Monty or Hyperlight registers tools with FIDES metadata.
- Documents the compatibility boundary and mitigation guidance.
- Adds coverage for registration paths and metadata variants.
| File | Description |
|---|---|
python/samples/02-agents/security/FIDES_DEVELOPER_GUIDE.md |
Documents CodeAct limitations. |
python/packages/monty/tests/monty/test_monty_codeact.py |
Tests Monty warnings. |
python/packages/monty/README.md |
Adds compatibility guidance. |
python/packages/monty/agent_framework_monty/_execute_code_tool.py |
Implements Monty warnings. |
python/packages/hyperlight/tests/hyperlight/test_hyperlight_codeact.py |
Tests Hyperlight warnings. |
python/packages/hyperlight/README.md |
Adds compatibility guidance. |
python/packages/hyperlight/agent_framework_hyperlight/_execute_code_tool.py |
Implements Hyperlight warnings. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
There was a problem hiding this comment.
MAF Automated Review — Iteration 1
Result: No findings
Scope: full PR (1 commit(s)): dea2c8c172b1
Model: gpt-5.6-sol
Overview
The PR adds matching best-effort diagnostics to both CodeAct providers and clearly documents that nested host-tool calls bypass FIDES middleware enforcement. Key-presence checks cover all recognized metadata, including falsy values, while preserving tool identity, invocation behavior, and approval handling. Tests exercise both constructors and providers, dynamic registration, unannotated tools, and late metadata discovered through run-scoped snapshots; no Critical, High, or Medium defect was established.
Reviewed the supplied pull-request change set across correctness, security/reliability, architecture, and failure behavior.
No publishable findings remained after source verification for this scope.

Motivation & Context
CodeAct providers invoke registered host tools from generated code through a low-level tool path rather than the agent's function-middleware pipeline. FIDES metadata on those tools is therefore not enforced for nested calls. The existing package documentation did not state this compatibility boundary, and registering a tool with FIDES metadata produced no diagnostic.
Description & Review Guide
Related Issue
N/A. This compatibility clarification is not linked to a public issue. No matching open pull request was found.
Contribution Checklist
breaking changelabel (or add "[BREAKING]" to the title prefix, before or after any language prefix) — a workflow keeps the label and title prefix in sync automatically.