惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

M
MIT News - Artificial intelligence
D
Darknet – Hacking Tools, Hacker News & Cyber Security
SecWiki News
SecWiki News
Latest news
Latest news
A
Arctic Wolf
Know Your Adversary
Know Your Adversary
G
GRAHAM CLULEY
L
Lohrmann on Cybersecurity
T
Tor Project blog
T
Threatpost
S
Schneier on Security
P
Palo Alto Networks Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
Cyberwarzone
Cyberwarzone
C
Cybersecurity and Infrastructure Security Agency CISA
C
CERT Recently Published Vulnerability Notes
博客园_首页
P
Privacy & Cybersecurity Law Blog
I
Intezer
PCI Perspectives
PCI Perspectives
Spread Privacy
Spread Privacy
G
Google Developers Blog
H
Help Net Security
WordPress大学
WordPress大学
aimingoo的专栏
aimingoo的专栏
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
V
Visual Studio Blog
U
Unit 42
Application and Cybersecurity Blog
Application and Cybersecurity Blog
W
WeLiveSecurity
D
DataBreaches.Net
N
News and Events Feed by Topic
AI
AI
The Register - Security
The Register - Security
云风的 BLOG
云风的 BLOG
The GitHub Blog
The GitHub Blog
Help Net Security
Help Net Security
K
Kaspersky official blog
Recent Announcements
Recent Announcements
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
S
Security @ Cisco Blogs
H
Hacker News: Front Page
Jina AI
Jina AI
S
Secure Thoughts
Project Zero
Project Zero
T
The Exploit Database - CXSecurity.com
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
B
Blog RSS Feed
爱范儿
爱范儿

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
OpenAI Agents SDK的5个隐藏用法 🔥
· 2026-05-31 · via DEV Community

你知道吗?OpenAI 官方 Agents SDK 已经支持连接任何 MCP Server,但 90% 的开发者还在把它当成高级聊天机器人用。

这个框架在 GitHub 上有 26,779 Stars,HN Algolia 上关于 MCP 支持的讨论获得了 807 分(2026 年最高分之一)。它不仅仅是一个多 Agent 框架——它内置了大量生产级功能,但大多数教程从未提及。

今天我们深入挖掘 5 个隐藏用法,让你在 2026 年构建 AI 应用时遥遥领先。


隐藏用法 #1:3行代码连接任何 MCP Server

大多数人的用法: 手动编写 JSON Schema 定义工具函数,写大量冗长的 function_call 处理器。

隐藏技巧: SDK 原生支持 MCP 协议。只需 3 行代码就能连接任何 Model Context Protocol Server,不需要手写任何工具定义。

from agents.mcp import MCPToolset

# 连接 MCP Server(如文件系统 MCP、Slack MCP 等)
tools = MCPToolset(
    command="npx",
    args=["@modelcontextprotocol/server-filesystem", "/path/to/dir"]
)

agent = Agent(
    name="文件助手",
    instructions="你可以读取和写入工作区中的文件。",
    tools=tools
)

Enter fullscreen mode Exit fullscreen mode

效果: 你的 Agent 立即获得 MCP Server 暴露的所有工具权限——文件操作、API 调用、数据库查询——无需手写任何工具定义。

数据来源: OpenAI Agents SDK GitHub 26,779 Stars,HN Algolia "OpenAI adds MCP support to Agents SDK" 807分(故事 #43485566)


隐藏用法 #2:Sandbox Agent — 在容器中运行真实代码

大多数人的用法: 让 Agent 生成代码,然后手动在外部执行。

隐藏技巧: SandboxAgent 在完全隔离的容器中运行——支持文件系统访问、git 操作,以及跨对话轮次的持久化工作区。

from agents import Runner
from agents.sandbox import Manifest, SandboxAgent, SandboxRunConfig
from agents.sandbox.entries import GitRepo
from agents.sandbox.sandboxes import UnixLocalSandboxClient

agent = SandboxAgent(
    name="代码审查助手",
    instructions="审查代码仓库并提出改进建议。",
    default_manifest=Manifest(
        entries={"repo": GitRepo(repo="openai/openai-agents-python", ref="main")}
    )
)

result = Runner.run_sync(
    agent,
    "总结这个仓库的架构。",
    run_config=RunConfig(sandbox=SandboxRunConfig(client=UnixLocalSandboxClient()))
)
print(result.final_output)

Enter fullscreen mode Exit fullscreen mode

效果: Agent 自动克隆仓库、检查文件、运行命令、施加补丁——全部在隔离的 Linux 容器内完成,跨对话轮次保持完整工作区状态。

数据来源: OpenAI Agents SDK GitHub 26,779 Stars,官方文档 openai.github.io/openai-agents-python/sandbox_agents/


隐藏用法 #3:Guardrails 在入口处拦截无效输入

大多数人的用法: 完全跳过输入验证,或者事后用正则表达式打补丁。

隐藏技巧: Guardrail 作为独立验证步骤,在 Agent 处理任何输入之前运行——带有结构化的通过/失败结果和自动恢复机制。

from agents import Agent, Guardrail, GuardrailFunctionOutput
from pydantic import BaseModel

class UserIntent(BaseModel):
    is_code_request: bool
    requested_language: str | None

def check_intent(output: GuardrailFunctionOutput) -> bool:
    """仅允许代码相关请求通过。"""
    return output.output.is_code_request

guardrail = Guardrail(
    name="code_request_filter",
    n=1,
    output_type=UserIntent,
    on_fail=check_intent
)

agent = Agent(
    name="开发助手",
    instructions="帮助用户编写和调试代码。",
    input_guardrails=[guardrail]
)

Enter fullscreen mode Exit fullscreen mode

效果: 任何非代码输入在到达 LLM 之前就被拦截——在入口处减少幻觉和跑题响应。

数据来源: OpenAI Agents SDK GitHub 26,779 Stars,官方文档 openai.github.io/openai-agents-python/guardrails/


隐藏用法 #4:Tracing 让你真正看到 Agent 在想什么

大多数人的用法: 添加 print 语句然后祈祷——对工具调用序列、Token 使用量或中间推理过程完全没有可见性。

隐藏技巧: SDK 内置 Tracing 功能,记录每一步:Agent 推理、工具调用、LLM 响应和延迟——全部可在可视化仪表板中查看。

from agents import Runner, Agent
from agents.tracing import trace

# 用 trace() 包裹任何 Agent 运行,自动完成仪表化
with trace(agent_name="my-assistant", tags=["production", "v1"]):
    agent = Agent(name="我的助手", instructions="你是一个有用的助手。")
    result = Runner.run_sync(agent, "用 Python 写一个 Hello World。")
    print(result.final_output)

# 在以下地址查看 traces:https://platform.openai.com/traces

Enter fullscreen mode Exit fullscreen mode

效果: 每次 Agent 运行都会生成结构化 trace,包含每次 LLM 调用、工具调用和 Guardrail 检查的跨度信息——使调试多轮对话像阅读时间线一样简单。

数据来源: OpenAI Agents SDK GitHub 26,779 Stars,官方文档 openai.github.io/openai-agents-python/tracing/


隐藏用法 #5:Realtime Agent — 语音对话背后有完整 Agent 能力

大多数人的用法: 将 OpenAI Realtime API 单独使用,手动与 Agent 逻辑缝合在一起。

隐藏技巧: Agents SDK 原生支持 RealtimeAgent——语音对话背后有完整的 Agent 能力支撑:工具调用、Guardrails 和多 Agent 交接。

from agents.realtime import RealtimeAgent, RealtimeConfig
from agents import Runner

agent = RealtimeAgent(
    name="语音助手",
    instructions="你是一个有工具访问权限的语音助手。",
    voice="alloy"  # 使用 OpenAI 的语音模型
)

# 带有完整工具访问权限的语音 Agent——无需手动缝合
config = RealtimeConfig(model="gpt-realtime-2", tools=[...], guardrails=[...])
Runner.run(agent, config=config)

Enter fullscreen mode Exit fullscreen mode

效果: 语音对话可以真正使用工具——搜索网页、运行代码、查询数据库——同时在多轮对话中保持完整的上下文。OpenAI 自己的 Advanced Voice 框架内部也在使用这个 SDK(HN 266分)。

数据来源: OpenAI Agents SDK GitHub 26,779 Stars,HN Algolia "Open source framework OpenAI uses for Advanced Voice" 266分(故事 #41743327)


总结:5 个技巧

  1. MCP Server 集成 — 3 行代码连接任何 MCP Server,无需手写 Schema
  2. Sandbox Agent — 在隔离容器中运行 Agent,支持 git/文件系统访问
  3. Guardrails — 在入口处拦截无效输入,防止有害输出到达用户
  4. Tracing — 对 Agent 推理、工具调用和延迟获得完整可见性
  5. Realtime Voice Agent — 语音对话背后有完整 Agent 能力支撑

3 个内链:

你最喜欢的隐藏用法是什么?在评论区分享!