Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

Foundry Toolbox Radar Logo

Foundry Toolbox Radar (foundry-toolbox-radar-lab)

Python 3.10+ License: MIT CI Status OWASP LLM Aligned Pre-Commit Ready GitHub Action

Enterprise-grade pre-deployment governance, identity auditing, indirect prompt-injection detection, and data-leakage scanner for Microsoft Foundry Toolboxes and autonomous AI agents.


Note

Open-Source Community Project Disclaimer

This is an independent open-source community project developed for enterprise AI practitioners. It is not an official Microsoft repository or supported product. All Microsoft Foundry, Azure Agent Service, and Microsoft Entra ID architectures are grounded in public Microsoft Learn specifications.


Executive Summary

When deploying autonomous agents on Microsoft Foundry, connecting Model Context Protocol (MCP) servers and tools through a Toolbox is instantaneous. However, under-governed tool configurations introduce severe security and operational risks:

  • Ungated Mutating Actions: Autonomous agents executing state-changing operations (delete, update, send, drop, kill) without explicit human confirmation.
  • Static Credential Creep: Hardcoded CustomKeys (API keys, PATs) shared across agent instances instead of Microsoft Entra token passthrough.
  • Indirect Prompt Injection & Tool Poisoning: Malicious instructions, jailbreaks, or exfiltration hooks embedded inside third-party tool docstrings and metadata.
  • Prompt & Context Leakage: Live API tokens, internal emails, and customer PII exposed through tool descriptions and sample outputs.
  • Scope Inflation: Wildcard permissions (*) or overly broad /.default scopes granting excess cloud privileges.

foundry-toolbox-radar-lab delivers a shift-left defense engine: a zero-latency, 100% offline static analyzer that audits Toolbox YAML definitions before they are attached to hosted agents or merged into production.


Architecture & CI/CD Pipeline

flowchart LR
    subgraph Development["1. Developer Workspace"]
        A["Toolbox YAML\n(toolbox.yaml)"] --> B["Pre-Commit Hook\n(local lint)"]
    end

    subgraph Pipeline["2. Automated Pull Request Gate"]
        B --> C["GitHub Actions PR"]
        C --> D["radar scan --json"]
        D --> E{"Governance\nAudit"}
    end

    subgraph Enforcement["3. Gate Decision"]
        E -->|HIGH >= 1| F["[FAIL] Block PR Merge\n(Exit Code 1)"]
        E -->|HIGH == 0| G["[PASS] Allow PR Merge\n(Exit Code 0)"]
    end

    subgraph Production["4. Microsoft Foundry Agent Service"]
        G --> H["azd up / Hosted Agent\n(Secure Deployment)"]
    end

    classDef pass fill:#107c41,stroke:#0b5a2f,color:#fff;
    classDef fail fill:#d83b01,stroke:#a80000,color:#fff;
    classDef gate fill:#0078d4,stroke:#004e8c,color:#fff;

    class G,H pass;
    class F fail;
    class D,E gate;
Loading

Quickstart

1. Installation

Clone the repository and install the CLI:

git clone https://github.com/nithin42/Foundry-Toolbox-Radar-Lab.git
cd Foundry-Toolbox-Radar-Lab
pip install -e .

Verify installation:

radar --help

2. Audit a Toolbox Configuration

Scan any local Toolbox YAML configuration:

radar tool/tests/fixtures/risky_toolbox.yaml

Terminal Audit Report:

======================================================================================
  FOUNDRY TOOLBOX RADAR -- GOVERNANCE AUDIT REPORT
  Target: risky_toolbox.yaml
======================================================================================
  Total Findings: 12 (HIGH: 8 | MEDIUM: 3 | LOW: 1)
--------------------------------------------------------------------------------------
  SEV      RULE      TOOL NAME                SUMMARY
--------------------------------------------------------------------------------------
  [HIGH]   RULE-01   delete_database_recor... Tool appears to perform mutating actions but does not enforce human approval (require_approval=False).
           Evidence:    name: delete_database_records, require_approval: False
           Remediation: Set 'require_approval: true' (or 'always') on mutating tools to prevent unauthorized autonomous actions.
--------------------------------------------------------------------------------------
  [HIGH]   RULE-02   unauthenticated_metri... No authentication type configured for tool/connection. Endpoints may be exposed unauthenticated.
           Evidence:    authType: 'None'
           Remediation: Specify a supported 'authType' ('UserEntraToken', 'AgenticIdentityToken', 'OAuth2', or 'CustomKeys').
--------------------------------------------------------------------------------------
  [MEDIUM] RULE-03   legacy_erp_connector     Tool uses static 'CustomKeys' authentication (API key/PAT). Shared keys lack user attribution and automatic credential rotation.
           Evidence:    authType: CustomKeys
           Remediation: Upgrade connection to Microsoft Entra identity ('AgenticIdentityToken' or 'UserEntraToken') or 'OAuth2'.
--------------------------------------------------------------------------------------
  [MEDIUM] RULE-04   user_delegated_sharep... Tool uses 'UserEntraToken' passthrough but lacks a specific 'audience' App ID URI.
           Evidence:    authType: UserEntraToken, audience: None
           Remediation: Define a valid Entra App ID URI or Resource ID in 'audience' to avoid token rejection or broad token exchange.
--------------------------------------------------------------------------------------
  [HIGH]   RULE-05   customer_lookup_leaky    Potential Email Address detected in 'sample_output'. Risk of sensitive data exposure to LLM context.
           Evidence:    alice.smith@executive-corp.com
           Remediation: Sanitize or synthesize sample outputs. Replace real PII or secret values with placeholders.
--------------------------------------------------------------------------------------
  [HIGH]   RULE-05   customer_lookup_leaky    Potential AI API Key detected in 'sample_output'. Risk of sensitive data exposure to LLM context.
           Evidence:    sk-98765...
           Remediation: Sanitize or synthesize sample outputs. Replace real PII or secret values with placeholders.
--------------------------------------------------------------------------------------
  [LOW]    RULE-06   broad_cloud_manager      Wildcard character '*' detected in target, audience, or scope definition.
           Evidence:    https://management.azure.com/.default api://*
           Remediation: Specify explicit resource identifiers and endpoints instead of wildcard patterns.
--------------------------------------------------------------------------------------
  [HIGH]   RULE-07   poisoned_search_assis... Potential Instruction Hijacking / Override detected in 'description'. Tool metadata attempts to hijack agent control flow or exfiltrate context.
           Evidence:    Ignore previous instructions
           Remediation: Remove instruction-override phrases, prompt injection attacks, and exfiltration directives from tool metadata.
--------------------------------------------------------------------------------------
======================================================================================
  [FAILED] 8 HIGH severity finding(s) detected. Gate blocked.
======================================================================================

Integration Modes

Option A: GitHub Actions Quality Gate

Embed radar directly into .github/workflows/governance-gate.yml:

name: Toolbox Governance Gate

on:
  pull_request:
    paths:
      - '**.yaml'
      - '**.yml'

jobs:
  audit:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - name: Run Foundry Toolbox Radar Gate
        uses: nithin42/Foundry-Toolbox-Radar-Lab@main
        with:
          config: ./src/toolbox.yaml
          json: false
          strict: false

Option B: Local Git Pre-Commit Hook

Add foundry-toolbox-radar to your .pre-commit-config.yaml to prevent insecure configurations from being committed:

repos:
  - repo: https://github.com/nithin42/Foundry-Toolbox-Radar-Lab
    rev: main
    hooks:
      - id: foundry-toolbox-radar

Option C: Machine-Readable CI JSON Mode

Emit structured JSON for Azure DevOps, GitHub Actions, or SIEM pipelines:

radar ./src/toolbox.yaml --json
{
  "file": "./src/toolbox.yaml",
  "total_findings": 0,
  "high": 0,
  "medium": 0,
  "low": 0,
  "passed": true,
  "findings": []
}

Governance Rules & OWASP LLM Mapping

All checks map directly to industry standards including the OWASP Top 10 for Large Language Models:

Rule ID Severity Name OWASP LLM Category Enforcement Check
RULE-01 HIGH MUTATING_WITHOUT_APPROVAL LLM06: Excessive Agency Verifies mutating tools (delete, create, update, send, drop) enforce require_approval: true.
RULE-02 HIGH MISSING_OR_INVALID_AUTH LLM07: System Auth Failures Blocks connections with missing, None, or unrecognized authentication types.
RULE-03 MEDIUM STATIC_CREDENTIAL_RISK LLM02: Sensitive Data Disclosure Flags static CustomKeys (API keys/PATs) in favor of managed Entra identities.
RULE-04 MEDIUM MISSING_ENTRA_AUDIENCE LLM07: Least Privilege Ensures UserEntraToken connections define a specific App ID URI in audience.
RULE-05 HIGH / MED PII_OR_SECRET_LEAKAGE LLM02: Sensitive Data Disclosure Scans description (MED) and sample_output (HIGH) for emails, SSNs, phone numbers, and API tokens.
RULE-06 LOW OVERLY_BROAD_SCOPE LLM06: Excessive Agency Flags wildcard characters (*) and unrestricted /.default scopes.
RULE-07 HIGH PROMPT_INJECTION_POISONING LLM01: Prompt Injection Detects instruction hijacking, role alterations, and data exfiltration directives in tool metadata.

Hands-On Workshop Curriculum

A complete, step-by-step curriculum for engineering teams building secure agents on Microsoft Foundry:

Module Guide Focus Area Prerequisites
Lab 01 Your First Toolbox Managed toolbox provisioning, GitHub MCP server connection, and Streamable HTTP testing. Azure Subscription, azd CLI
Lab 02 Multi-Tool Governance Custom serverless MCP on Azure Functions, 3-tier RBAC segregation, and live radar auditing. Lab 01, Functions Core Tools
Lab 03 Deploy & Gate Hosted agent deployment with azd up and automated PR merge gates in GitHub Actions. Labs 01 & 02, GitHub Repo

Official Microsoft Learn References


License

This project is licensed under the MIT License.

About

Pre-deployment governance, identity auditing, and data-leakage scanner for Microsoft Foundry Toolboxes and autonomous AI agents.

Resources

Stars

25 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages