fix(guardrails): resolve tool guardrails on tools named with special characters [AL-610] - #1114
Merged
andreizdrali-uipath merged 3 commits intoSep 25, 2026
Conversation
…characters
A custom Tool-scope guardrail with an all-fields rule failed agent startup
with INVALID_GUARDRAIL_CONFIG when the tool's name had a space or special
character. The selector holds the name as typed ("My Function"), tools are
registered sanitized ("My_Function"), and the selector is only sanitized
after the rules are converted. Process tools' display_name is the process
name, so that fallback did not match either.
Compare the sanitized match name with the tool name, keeping the
display_name fallback that MCP tools rely on.
Fixes AL-610.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
andreizdrali-uipath
marked this pull request as ready for review
September 24, 2026 12:55
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Resolve the ambiguous display-name versus sanitized-name tool matching before approval.
Review effort: Lite
Findings: None
What changed in this PR
Fixes tool guardrail resolution for tool names containing spaces or special characters.
Changes:
- Matches selectors against sanitized tool names.
- Preserves MCP display-name fallback.
- Adds regression tests and bumps version to 0.18.15.
| File | Description |
|---|---|
uv.lock |
Updates locked package version. |
tests/agent/guardrails/test_guardrails_factory.py |
Adds process-tool and MCP matching tests. |
src/uipath_langchain/agent/guardrails/guardrails_factory.py |
Resolves sanitized tool selectors. |
pyproject.toml |
Bumps package version. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
valentinabojan
approved these changes
Sep 25, 2026
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
andreizdrali-uipath
enabled auto-merge (squash)
September 25, 2026 11:29
valentinabojan
approved these changes
Sep 25, 2026
|
andreizdrali-uipath
deleted the
fix/guardrail-match-names-sanitized-al-610
branch
September 25, 2026 12:21
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Fixes AL-610, found while testing AL-607.
Problem
A custom Tool-scope guardrail with an "all fields" rule fails agent startup with
INVALID_GUARDRAIL_CONFIG("Tool 'My Function' not found in available tools") when the tool's name has a space or special character, or is longer than 64 characters._compute_field_sources_for_guardrailcompares the selector's name as typed (My Function) with the sanitized tool name (My_Function). The selector is sanitized only after the rules are converted.The
display_namefallback only helps when it holds the raw tool name, as it does for integration tools. It doesn't for:Function_1)display_nameFix
Compare
sanitize_tool_name(match_name)witht.name, and keep the rawdisplay_namefallback that MCP tools rely on. The subgraph already matches the guardrail to the tool by this sanitized name, and the C# runtime compares names the same way.No agent that starts today fails after this change: every tool factory registers its tool under a sanitized name, so any selector that matched
t.namebefore still matches it. Voice agents rebuild guardrails on every tool call, so with such a guardrail every voice tool call failed; they now work too.Bumps to 0.18.15.
Tests
My FunctionandSend E-mail (v2)!(both failed before the fix), plus an MCP display-name case to guard the fallback.uv run pytest: 3455 passed, 3 skipped, 2 failed. Both failures are intest_output_file_tool.pyand also fail onmainon Windows (CSV MIME type from the registry, symlink privilege).just lint,just formatand mypy are clean.🤖 Generated with Claude Code