Repository navigation
Maintainer guidance requested for a bounded Python Agent Memory Guard integration #8880
vgudur-dev
started this conversation in
Ideas
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Hello Microsoft Agent Framework maintainers,
I am writing solely in a personal capacity to request design and submission guidance. This is a nonconfidential, public-scope question; I do not represent an employer, Microsoft, OWASP, or any customer, and I am not claiming any endorsement, acceptance, integration, support, or adoption by Microsoft or OWASP.
Would maintainers consider a deliberately narrow, Python-only integration with OWASP Agent Memory Guard (AMG), and, if so, which placement is appropriate?
The proposed initial boundary is a direct guarded-store
AMGHistoryProvider(or maintainer-approved equivalent) built on MAF’s documented history/context-provider lifecycle. It would use AMGMemoryGuard.read()before adding scoped history to model context andMemoryGuard.write()before persisting selected messages, with explicit provenance mapping for user input, agent-authored output, system-controlled messages, and external tool results.This proposal would be limited to AMG-owned direct storage—initially its in-memory store and, if approved, its documented Redis store—for Python 3.10–3.13. It would not claim to wrap or protect Foundry Memory, Mem0, Cosmos, Neo4j, generic vector/semantic providers, hosted-provider internals, out-of-band store access, or .NET. A blocked/quarantined write would not be persisted by this provider; a blocked, redacted, or integrity-failed read would not be injected into model context. Exact failure and diagnostic behavior would be agreed before implementation.
Before any code or PR, could the relevant maintainers/area owners please decide or advise on the following?
If there is interest, I can prepare only the requested design material: lifecycle pseudocode, explicit scope/failure semantics, and tests for round-trip history, blocked writes, poisoned reads, provenance, scope isolation, and streaming/tool-loop behavior. No implementation is requested or implied by this question.
Thank you for guidance.
Links
All reactions