Repository navigation
Conversation
Evaluate the tool calls of MCP servers configured in the OpenAI Agents SDK before the tools/call request is sent, behind DD_AI_GUARD_COLLECT_MCP_ENABLED. The openai_agents contrib dispatches two core events, with no AI Guard import: openai_agents.mcp.invoke_tool.before around MCPUtil.invoke_mcp_tool (agent-driven calls, which know the model call ID and model-visible name) and openai_agents.mcp.call_tool.before around every concrete SDK server call_tool (direct calls). An agent-driven call is evaluated once, at the adapter. Evaluations carry the configured server name (never the SDK-generated name, which embeds the stdio command or raw URL), the sanitized URL, the transport and the original tool name. OpenAI Chat and Responses listeners record the model's tool calls so an agent-driven call reuses its real call ID and conversation; direct calls get a local ID and no history. APPSEC-70369 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codeowners resolved asResolved from the full PR diff against |
Circular import analysis
|
Dependency direction analysis📈 Existing violations got worse1 pre-existing violation(s) increased in severity (e.g. their target became more depended-on, or got pulled into an import cycle), though the edge itself isn't new:
|
❌ ErrorsYour PR has failed checks. Please review the issues below and take necessary action before merging. 🚦 3 Pipeline jobs failed
ℹ️ InfoNo other issues found (see more)🧪 All tests passed Useful? React with 👍 / 👎 This comment will be updated automatically if new data arrives.🔗 Commit SHA: ddba254 | Docs | View more details | Give us feedback! |
BenchmarksBenchmark execution time: 2026-10-07 09:55:42 Comparing candidate commit ddba254 in PR branch Found 4 performance improvements and 8 performance regressions! Performance is the same for 595 metrics, 10 unstable metrics, 6 known flaky benchmarks, 18 flaky benchmarks without significant changes.
|
Description
Jira: APPSEC-70369
Stacked on #20850 (OpenAI hosted MCP): this PR targets that branch and contains only the client-managed openai-agents part.
Evaluates the tool calls of MCP servers configured in the OpenAI Agents SDK (
MCPServerStdio,MCPServerSse,MCPServerStreamableHttp) before thetools/callrequest is sent, behindDD_AI_GUARD_COLLECT_MCP_ENABLED(defaultfalse).Detection on the model SDK side. The openai_agents contrib dispatches two core events (no AI Guard import in contrib):
openai_agents.mcp.invoke_tool.beforeMCPUtil.invoke_mcp_toolopenai_agents.mcp.call_tool.beforecall_toolof every concrete SDK server class (0.23 overrides it withoutsuper())server.call_tool()callsAn agent-driven call is evaluated once, at the adapter; the lower check skips it through a one-shot marker, set only when the call may proceed (a blocked call cannot excuse a later direct call). A re-entrancy guard keeps an override calling
super()to one dispatch.Payload.
function.nameis the model-visible name,mcp.tool_namethe original MCP tool name.mcp.nameis the configured server name only: the SDK-generated names (stdio: <command>,sse: <url>) embed the command or raw URL and are dropped.mcp.urlis sanitized; transport comes from the server class. Headers, auth, stdio command, arguments and environment are never sent.Correlation. The OpenAI Chat and Responses after-listeners record the model's tool calls (per context, keyed by call ID). An agent-driven call reuses its real call ID and the conversation that produced it; sibling calls are evaluated when they run. Direct calls get a local
dd_mcp_<uuid>ID and no fabricated history.Blocking follows existing semantics (
AIGuardAbortError, aBaseException, propagates out ofRunner.run); monitor mode and evaluation errors preserve execution. Newopenai_agentsvalue for the integration telemetry tag.Testing
New
ai_guard_openai_agentssuite (Python 3.10-3.13; openai-agents 0.0.x withopenai<1.100, and latest):tools/call, monitor and fail-openRunner.runwith a mocked model returning a function call and a stubbed MCP session (allow and block)Locally: 16/16 on openai-agents 0.23.1 (py3.12, py3.10) and 0.0.19 (py3.12);
ai_guard_openai(222) and contribopenai_agents(agents 0.14 and 0.0) still pass.Risks
invoke_mcp_tool; their calls are still evaluated through the lowercall_toolcheck, as direct calls.MCPServersubclasses outside the SDK are covered for agent-driven calls only.Additional Notes
Merge order: merge this PR into the #20850 branch before #20850 merges, so both land in
maintogether. If #20850 merges first, this PR is retargeted tomainand must be merged on its own.🤖 Generated with Claude Code