Skip to content

MAINT: Target Tool Calling Capability Improvements - #2852

Merged
Richard Lundeen (richlundeen) merged 6 commits into
microsoft:mainfrom
richlundeen:richlundeen-tool-call-support-plan
Sep 30, 2026
Merged

Richard Lundeen (richlundeen) merged 6 commits into
microsoft:mainfrom
richlundeen:richlundeen-tool-call-support-plan

Conversation

@richlundeen

@richlundeen Richard Lundeen (richlundeen) commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

PyRIT already represented tool calls and results as input modalities, but support for using them as conversation history was inconsistent across target adapters. Capability discovery did not test tool-history acceptance, and callers had no shared validation API to check history without sending a request. Synthetic tool results also lacked a distinct role, so copied conversations, scoring, and display could lose the distinction between injected history and actual execution evidence.

This PR uses the existing input modalities as the tool-history capability contract, without adding a separate boolean. It adds shared tool-content models, consistent Chat/Responses parsing and serialization of converted values, and validate_tool_history() for checks without sending requests. Capability probes test history acceptance without running configured tools or opening provider sessions, while preserving target settings and identity. Responses targets also support execute_tools=False to return the first response without local tool execution. The new simulated_tool role and shared prepended-history marking preserve synthetic content through conversation copies, scoring, UI, and exports. Trace-based scoring uses actual execution evidence rather than injected message claims. Send-time validation remains after normalization, so ADAPT behavior is unchanged.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Bring the shared tool-content models and no-send target preflight from PR microsoft#2853 into the tool capability change. Reuse payload validation across Chat, LiteLLM, and Responses while keeping editor persistence in its own PR.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Preserve complete tool execution and request-local retry/pacing from microsoft#2718. Share the request helper with single-response mode, suppress provider activity during capability probes, and preserve configured target identities.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Comment thread pyrit/prompt_target/common/discover_target_capabilities.py Outdated
Comment thread pyrit/prompt_target/common/tool_call_history.py
Comment thread pyrit/models/messages/message_piece.py
Comment thread pyrit/prompt_target/openai/openai_response_target.py
Filter nested SDK tool settings during probes, render objective tool exchanges as adversarial context, label simulated tools correctly, and separate strict draft validation from provider argument replay. Include focused regressions and shorten the target overview.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Mark prepended seed history without marking outgoing user prompts. Preserve synthetic assistant/tool roles and update the role contract regression for simulated_tool.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@richlundeen
Richard Lundeen (richlundeen) added this pull request to the merge queue Sep 30, 2026
Merged via the queue into microsoft:main with commit ea9d0b4 Sep 30, 2026
49 checks passed
@richlundeen
Richard Lundeen (richlundeen) deleted the richlundeen-tool-call-support-plan branch September 30, 2026 00:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants