* .NET: Add Hosted-AgentSkills sample for Foundry Skills integration Add a new hosted agent sample that demonstrates how to load behavioral guidelines from Foundry Skills at startup using AgentSkillsProvider and the progressive disclosure pattern (advertise -> load on demand). The sample: - Downloads SKILL.md files from Foundry via ProjectAgentSkills SDK - Extracts ZIP archives with zip-slip protection - Wires skills into AgentSkillsProvider as an AIContextProvider - Hosts the agent via the Responses protocol Ships two Contoso Outdoors skills matching the Python sample (PR #5822): - support-style: tone, formatting, signature guidelines - escalation-policy: when and how to escalate tickets Includes convenience provisioning gated behind PROVISION_SAMPLE_SKILLS env var, clearly documented as NOT a production pattern. Closes #5776 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * .NET: Add unit tests and integration test for Hosted-AgentSkills Unit tests (14 tests, all passing): - ZIP extraction with zip-slip guard (valid archive, traversal attack, sibling-prefix attack, directory entries) - Skill name validation (rejects dots, separators, traversal patterns) - AgentSkillsProvider with downloaded skills (advertises both skills, load_skill returns canary tokens, unknown skill returns error) Container integration test: - New 'agent-skills' scenario in the test container that creates Contoso Outdoors skills on disk and wires AgentSkillsProvider - AgentSkillsHostedAgentFixture + 4 integration tests verifying: - Routine questions load support-style skill (STYLE-CANARY-3318) - Escalation triggers load escalation-policy (ESC-CANARY-7742) - Skills are advertised in system prompt - load_skill tool is invoked via FunctionCallContent Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * .NET: Add smoke test, bootstrap, and docs for agent-skills integration - Add scripts/smoke.ps1 for local Docker smoke testing: builds the contributor image, runs the container, verifies both skills are loaded via canary tokens (STYLE-CANARY-3318, ESC-CANARY-7742) - Add 'agent-skills' to the bootstrap script scenario list - Add agent-skills row to the integration test README scenarios table - Exclude HostedAgentSkillsPatternTests from net472 (uses net8.0+ APIs) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * .NET: Update commented-out package versions to latest across all hosted samples Update the end-user PackageReference versions (in the commented-out sections) from 1.0.0 to the current latest NuGet versions: - Microsoft.Agents.AI: 1.6.1 - Microsoft.Agents.AI.Foundry: 1.6.1-preview.260514.1 - Microsoft.Agents.AI.Foundry.Hosting: 1.6.1-preview.260514.1 - Microsoft.Agents.AI.Hosting: 1.6.1-preview.260514.1 - Microsoft.Agents.AI.OpenAI: 1.6.1 - Microsoft.Agents.AI.Workflows: 1.6.1 Also adds explicit versions to Hosted-Workflow-Handoff which had bare PackageReference entries without Version attributes. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * .NET: Fix broken markdown links in Hosted-AgentSkills README Remove references to non-existent ../../README.md. Replace with inline instructions matching other hosted samples that don't have a parent README. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * .NET: Use OS-appropriate string comparison in zip-slip guard Use Ordinal on Unix (case-sensitive FS) and OrdinalIgnoreCase on Windows to prevent case-based path bypass on Linux containers. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Hosted-Files
A hosted agent that demonstrates two distinct file knowledge sources through scoped, security-hardened tools:
- Bundled files (image-baked) — files the author packages with the agent at build time. Live at
/app/resources/inside the container, copied from this project'sresources/folder via the csproj<Content Include="resources\**\*" CopyToOutputDirectory="PreserveNewest" />rule. - Session files (per-session
$HOMEvolume) — files the user uploads at runtime via the alphaAzure.AI.Projects.AgentSessionFilesSDK. Live at$HOMEinside the per-session container. The Foundry platform setsHOME=/home/sessionby default and roots the session-files API there percontainer-image-spec.mdline 172: "If you use the session files API,$HOMEis also the base path for those operations; any paths given in those API endpoints will be relative to$HOME."
Tool surface
Each source is exposed via its own tool pair, rooted at its own directory. The model picks by intent.
| Tool | Source | Root |
|---|---|---|
ListBundledFiles |
Bundled (image-baked) | /app/resources/ |
ReadBundledFile |
Bundled (image-baked) | /app/resources/ |
ListSessionFiles |
Session-uploaded | $HOME (/home/session) |
ReadSessionFile |
Session-uploaded | $HOME (/home/session) |
Security model — distinct tools, distinct sandboxes
Each tool takes a fileName (no directory components allowed) and enforces three layers of defence inside the implementation:
Path.GetFileName(input)strips any directory parts from the model-supplied name."../../etc/passwd"becomes"passwd".Path.GetFullPath(Combine(root, name))canonicalises the path.fullPath.StartsWith(root + DirectorySeparatorChar)rejects anything that resolves outside the tool's root.
Failures return a controlled "File '<input>' not found in <scope>." rather than throwing or exposing the canonical path.
This is why the agent has four narrowly-scoped tools instead of a single ReadFile(path):
- Smaller per-tool attack surface. Each tool has one purpose, one root, and no path-typed parameter. Even a buggy implementation can only leak its own directory.
- Cross-boundary access is impossible by schema. A prompt-injection attempt to make the bundled tool read a session path (or vice versa) does not even compile in the tool schema the model sees.
- Read-only, non-recursive listing. No write tools, no glob, no
...
Companion
Using-Samples/SessionFilesClient — a thin chat REPL (same shape as SimpleAgent) that points at the deployed Hosted-Files endpoint via FoundryAgent and lets you ask questions whose answers come from either file source.
Live proof of the session-files contract
The end-to-end alpha-SDK round trip (client uploads via AgentSessionFiles.UploadSessionFileAsync → file arrives at $HOME/<name> inside the per-session container → agent's ReadSessionFile tool reads it → response quotes the verbatim contents) is exercised live by SessionFilesHostedAgentTests.UploadedFile_IsReadByHostedAgentAsync against the matching session-files scenario in the integration test container.
Prerequisites
- .NET 10 SDK
- An Azure AI Foundry project with a deployed model (e.g.,
gpt-4o) - Azure CLI logged in (
az login)
Configuration
Copy the template and fill in your project endpoint:
cp .env.example .env
Edit .env:
AZURE_AI_PROJECT_ENDPOINT=https://<your-account>.services.ai.azure.com/api/projects/<your-project>
ASPNETCORE_URLS=http://+:8088
ASPNETCORE_ENVIRONMENT=Development
AZURE_AI_MODEL_DEPLOYMENT_NAME=gpt-4o
.envis gitignored. The.env.exampletemplate is checked in as a reference.
Running directly (contributors)
cd dotnet/samples/04-hosting/FoundryHostedAgents/responses/Hosted-Files
AGENT_NAME=hosted-files dotnet run
The agent starts on http://localhost:8088.
Try it from the SessionFilesClient REPL
Bundled files (works against any deployment, including local)
cd ../Using-Samples/SessionFilesClient
$env:AGENT_ENDPOINT = "http://localhost:8088"
$env:AGENT_NAME = "hosted-files"
dotnet run
You> What is the total revenue in the contoso file?
Agent> The contoso file reports total revenue of "$1,482.6M".
The agent calls ListBundledFiles, sees contoso_q1_2026_report.txt, calls ReadBundledFile("contoso_q1_2026_report.txt") (which resolves under /app/resources/), and quotes the figure verbatim.
Session files (against a deployed agent)
Upload a file to a specific session via azd ai agent files upload or via the alpha AgentSessionFiles SDK (see the integration test for the SDK call), then ask the agent about it. The agent's ReadSessionFile tool reads from $HOME and surfaces the content the same way.
Running with Docker
This project uses ProjectReference, so use Dockerfile.contributor which takes a pre-published output:
dotnet publish -c Debug -f net10.0 -r linux-musl-x64 --self-contained false -o out
docker build -f Dockerfile.contributor -t hosted-files .
export AZURE_BEARER_TOKEN=$(az account get-access-token --resource https://ai.azure.com --query accessToken -o tsv)
docker run --rm -p 8088:8088 \
-e AGENT_NAME=hosted-files \
-e AZURE_BEARER_TOKEN=$AZURE_BEARER_TOKEN \
--env-file .env \
hosted-files
The bundled resources/ folder is part of the published output and ships inside the image.
NuGet package users
If consuming the Agent Framework as a NuGet package, use the standard Dockerfile instead of Dockerfile.contributor and switch the ProjectReference entries in HostedFiles.csproj to PackageReference (commented section in the csproj).
Adding more bundled files
Drop additional text files into resources/. The csproj <Content Include="resources\**\*" CopyToOutputDirectory="PreserveNewest" /> rule picks them up on the next dotnet build / docker build.
Overrides
| Env var | Purpose | Default |
|---|---|---|
BUNDLED_FILES_DIR |
Override the bundled-files root the tools read from. | <process base dir>/resources (/app/resources/ in container) |
HOME |
The per-session sandbox volume root the session-files tools read from. Set by the Foundry platform; can be overridden for local testing. | /home/session |