George Weale 9d6d555d7a fix(artifacts): harden FileArtifactService against tampered metadata and partial writes (v1)
Port of the upstream "Secure and harden FileArtifactService against tampered
metadata and partial writes". Four defects, all in the file service:

The payload location was taken from `canonicalUri` in the on-disk metadata
document whenever the payload file itself was absent. That document lives
inside the artifact tree, so anything able to write there, or to win the race
between a delete and a load, could redirect a read to any file the process
could open. The payload location is now derived only from the storage layout,
and the `canonical_uri` returned to callers is recomputed from that layout
rather than read back from the document.

Saving an artifact named `metadata.json` destroyed it. The payload is stored
under the artifact directory's own name, so it was written first and then
overwritten by the metadata document, leaving a version directory holding
only metadata. Filenames are model-supplied, so this needed no attacker.
The name is now rejected at save time, caselessly, because a
case-insensitive filesystem resolves `Metadata.json` to the same file. The
rejection is on the save path only, so an artifact already stored under that
name stays readable and deletable.

A save that failed partway left the version directory behind, and a version
with a payload but no metadata reads as valid. Serializing `custom_metadata`
is caller-driven and can fail, which was enough to produce one. The whole
version directory is now removed if any step fails.

The metadata document was written in place with `write_text`, so a reader
could see a truncated document. It is now written to a temporary file in the
same directory and renamed over the destination. `tempfile.mkstemp` hardcodes
mode 0600 and `os.replace` carries that mode across, so the mode a normally
created file would get from the umask is restored first; otherwise the
metadata document and the payload beside it end up readable by different
principals.

Behaviour changes an existing 1.x user would notice:

- Saving an artifact named `metadata.json` in any casing now raises
  InputValidationError. It previously succeeded and silently destroyed the
  artifact it had just written.
- A save that fails partway now leaves nothing behind, where it previously
  left a version directory that `list_versions` reported.
- A metadata document naming a `canonicalUri` outside the artifact tree is
  ignored rather than followed, so an artifact whose payload is missing now
  loads as None.

`_umask_derived_file_mode()` calls `os.umask` twice at import time, which is
a process-global mutation. It is momentary, and sampling per write would race
against concurrent writers instead.

The upstream commit also threads `inline_data.display_name` through the save
and load paths and guards `inline_data.data is None`. Neither is ported:
both come from separate upstream changes that are not on this branch.
2026-08-18 20:25:08 +00:00
2025-12-04 13:54:17 -08:00
2025-11-03 13:33:53 -08:00

Agent Development Kit (ADK)

License PyPI Python Unit Tests r/agentdevelopmentkit Ask Code Wiki

<html>

An open-source, code-first Python framework for building, evaluating, and deploying sophisticated AI agents with flexibility and control.

</html>

Agent Development Kit (ADK) is a flexible and modular framework that applies software development principles to AI agent creation. It is designed to simplify building, deploying, and orchestrating agent workflows, from simple tasks to complex systems. While optimized for Gemini, ADK is model-agnostic, deployment-agnostic, and compatible with other frameworks.


🔥 What's new

  • Custom Service Registration: Add a service registry to provide a generic way to register custom service implementations to be used in FastAPI server. See short instruction. (391628f)

  • Rewind: Add the ability to rewind a session to before a previous invocation (9dce06f).

  • New CodeExecutor: Introduces a new AgentEngineSandboxCodeExecutor class that supports executing agent-generated code using the Vertex AI Code Execution Sandbox API (ee39a89)

Key Features

  • Rich Tool Ecosystem: Utilize pre-built tools, custom functions, OpenAPI specs, MCP tools or integrate existing tools to give agents diverse capabilities, all for tight integration with the Google ecosystem.

  • Code-First Development: Define agent logic, tools, and orchestration directly in Python for ultimate flexibility, testability, and versioning.

  • Agent Config: Build agents without code. Check out the Agent Config feature.

  • Tool Confirmation: A tool confirmation flow(HITL) that can guard tool execution with explicit confirmation and custom input.

  • Modular Multi-Agent Systems: Design scalable applications by composing multiple specialized agents into flexible hierarchies.

  • Deploy Anywhere: Easily containerize and deploy agents on Cloud Run or scale seamlessly with Vertex AI Agent Engine.

🚀 Installation

You can install the latest stable version of ADK using pip:

pip install google-adk

To install optional integrations, you can use the following command:

pip install "google-adk[extensions]"

The release cadence is roughly bi-weekly.

This version is recommended for most users as it represents the most recent official release.

Development Version

Bug fixes and new features are merged into the main branch on GitHub first. If you need access to changes that haven't been included in an official PyPI release yet, you can install directly from the main branch:

pip install git+https://github.com/google/adk-python.git@main

Note: The development version is built directly from the latest code commits. While it includes the newest fixes and features, it may also contain experimental changes or bugs not present in the stable release. Use it primarily for testing upcoming changes or accessing critical fixes before they are officially released.

🤖 Agent2Agent (A2A) Protocol and ADK Integration

For remote agent-to-agent communication, ADK integrates with the A2A protocol. See this example for how they can work together.

📚 Documentation

Explore the full documentation for detailed guides on building, evaluating, and deploying agents:

🏁 Feature Highlight

Define a single agent:

from google.adk.agents import Agent
from google.adk.tools import google_search

root_agent = Agent(
    name="search_assistant",
    model="gemini-2.5-flash", # Or your preferred Gemini model
    instruction="You are a helpful assistant. Answer user questions using Google Search when needed.",
    description="An assistant that can search the web.",
    tools=[google_search]
)

Define a multi-agent system:

Define a multi-agent system with coordinator agent, greeter agent, and task execution agent. Then ADK engine and the model will guide the agents to work together to accomplish the task.

from google.adk.agents import LlmAgent, BaseAgent

# Define individual agents
greeter = LlmAgent(name="greeter", model="gemini-2.5-flash", ...)
task_executor = LlmAgent(name="task_executor", model="gemini-2.5-flash", ...)

# Create parent agent and assign children via sub_agents
coordinator = LlmAgent(
    name="Coordinator",
    model="gemini-2.5-flash",
    description="I coordinate greetings and tasks.",
    sub_agents=[ # Assign sub_agents here
        greeter,
        task_executor
    ]
)

Development UI

A built-in development UI to help you test, evaluate, debug, and showcase your agent(s).

Evaluate Agents

adk eval \
    samples_for_testing/hello_world \
    samples_for_testing/hello_world/hello_world_eval_set_001.evalset.json

🤝 Contributing

We welcome contributions from the community! Whether it's bug reports, feature requests, documentation improvements, or code contributions, please see our

Community Repo

We have adk-python-community repo that is home to a growing ecosystem of community-contributed tools, third-party service integrations, and deployment scripts that extend the core capabilities of the ADK.

Vibe Coding

If you want to develop agent via vibe coding the llms.txt and the llms-full.txt can be used as context to LLM. While the former one is a summarized one and the later one has the full information in case your LLM has big enough context window.

Community Events

  • [Completed] ADK's 1st community meeting on Wednesday, October 15, 2025. Remember to join our group to get access to the recording, and deck.

📄 License

This project is licensed under the Apache 2.0 License - see the LICENSE file for details.


Happy Agent Building!

S
Description
An open-source, code-first Python toolkit for building, evaluating, and deploying sophisticated AI agents with flexibility and control.|GitHub 镜像 21.3k · 🍴 3.9k
https://github.com/google/adk-python Readme Apache-2.0 79 MiB
Languages
Python 77.5%
JavaScript 20.7%
Jupyter Notebook 1.3%
HTML 0.3%