Repository navigation
Semaprax adapter as a concrete test of AutoGen tool-call policy hooks #8308
Riedl Kevin, Bsc. (wsdt)
started this conversation in
Feature suggestions
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
AutoGen already has an open proposal for a
GuardrailProviderat the tool-call boundary (#7405). A Semaprax adapter would be a useful concrete test case for that design: it takes a typed tool proposal, checks tool identity and arguments against explicit capabilities, and returns allow or deny before the tool runs.The key integration question is whether one policy wrapper can cover both
FunctionTool.run_json()andWorkbench.call_tool()without separate behavior for dynamically discovered MCP tools. A minimal example could allow a read tool, deny a write with out-of-scope arguments, and show a policy error that does not dispatch. It should bind the decision to a stable call identity so a changed argument set cannot reuse an old decision. AutoGen would remain responsible for execution and agent handoffs.This is an opt-in experimental integration, not a request to embed Semaprax in AutoGen. If #7405 is the right tracking issue, this discussion can supply acceptance cases or be folded into it. Which extension point would maintainers prefer for a prototype?
Semaprax: https://github.com/wavect/semaprax
All reactions