Port of the upstream "Secure and harden FileArtifactService against tampered metadata and partial writes". Four defects, all in the file service: The payload location was taken from `canonicalUri` in the on-disk metadata document whenever the payload file itself was absent. That document lives inside the artifact tree, so anything able to write there, or to win the race between a delete and a load, could redirect a read to any file the process could open. The payload location is now derived only from the storage layout, and the `canonical_uri` returned to callers is recomputed from that layout rather than read back from the document. Saving an artifact named `metadata.json` destroyed it. The payload is stored under the artifact directory's own name, so it was written first and then overwritten by the metadata document, leaving a version directory holding only metadata. Filenames are model-supplied, so this needed no attacker. The name is now rejected at save time, caselessly, because a case-insensitive filesystem resolves `Metadata.json` to the same file. The rejection is on the save path only, so an artifact already stored under that name stays readable and deletable. A save that failed partway left the version directory behind, and a version with a payload but no metadata reads as valid. Serializing `custom_metadata` is caller-driven and can fail, which was enough to produce one. The whole version directory is now removed if any step fails. The metadata document was written in place with `write_text`, so a reader could see a truncated document. It is now written to a temporary file in the same directory and renamed over the destination. `tempfile.mkstemp` hardcodes mode 0600 and `os.replace` carries that mode across, so the mode a normally created file would get from the umask is restored first; otherwise the metadata document and the payload beside it end up readable by different principals. Behaviour changes an existing 1.x user would notice: - Saving an artifact named `metadata.json` in any casing now raises InputValidationError. It previously succeeded and silently destroyed the artifact it had just written. - A save that fails partway now leaves nothing behind, where it previously left a version directory that `list_versions` reported. - A metadata document naming a `canonicalUri` outside the artifact tree is ignored rather than followed, so an artifact whose payload is missing now loads as None. `_umask_derived_file_mode()` calls `os.umask` twice at import time, which is a process-global mutation. It is momentary, and sampling per write would race against concurrent writers instead. The upstream commit also threads `inline_data.display_name` through the save and load paths and guards `inline_data.data is None`. Neither is ported: both come from separate upstream changes that are not on this branch.
Agent Development Kit (ADK)
<html>An open-source, code-first Python framework for building, evaluating, and deploying sophisticated AI agents with flexibility and control.
Important Links: Docs, Samples, Java ADK, Go ADK & ADK Web.
</html>Agent Development Kit (ADK) is a flexible and modular framework that applies software development principles to AI agent creation. It is designed to simplify building, deploying, and orchestrating agent workflows, from simple tasks to complex systems. While optimized for Gemini, ADK is model-agnostic, deployment-agnostic, and compatible with other frameworks.
🔥 What's new
-
Custom Service Registration: Add a service registry to provide a generic way to register custom service implementations to be used in FastAPI server. See short instruction. (391628f)
-
Rewind: Add the ability to rewind a session to before a previous invocation (9dce06f).
-
New CodeExecutor: Introduces a new AgentEngineSandboxCodeExecutor class that supports executing agent-generated code using the Vertex AI Code Execution Sandbox API (ee39a89)
✨ Key Features
-
Rich Tool Ecosystem: Utilize pre-built tools, custom functions, OpenAPI specs, MCP tools or integrate existing tools to give agents diverse capabilities, all for tight integration with the Google ecosystem.
-
Code-First Development: Define agent logic, tools, and orchestration directly in Python for ultimate flexibility, testability, and versioning.
-
Agent Config: Build agents without code. Check out the Agent Config feature.
-
Tool Confirmation: A tool confirmation flow(HITL) that can guard tool execution with explicit confirmation and custom input.
-
Modular Multi-Agent Systems: Design scalable applications by composing multiple specialized agents into flexible hierarchies.
-
Deploy Anywhere: Easily containerize and deploy agents on Cloud Run or scale seamlessly with Vertex AI Agent Engine.
🚀 Installation
Stable Release (Recommended)
You can install the latest stable version of ADK using pip:
pip install google-adk
To install optional integrations, you can use the following command:
pip install "google-adk[extensions]"
The release cadence is roughly bi-weekly.
This version is recommended for most users as it represents the most recent official release.
Development Version
Bug fixes and new features are merged into the main branch on GitHub first. If you need access to changes that haven't been included in an official PyPI release yet, you can install directly from the main branch:
pip install git+https://github.com/google/adk-python.git@main
Note: The development version is built directly from the latest code commits. While it includes the newest fixes and features, it may also contain experimental changes or bugs not present in the stable release. Use it primarily for testing upcoming changes or accessing critical fixes before they are officially released.
🤖 Agent2Agent (A2A) Protocol and ADK Integration
For remote agent-to-agent communication, ADK integrates with the A2A protocol. See this example for how they can work together.
📚 Documentation
Explore the full documentation for detailed guides on building, evaluating, and deploying agents:
🏁 Feature Highlight
Define a single agent:
from google.adk.agents import Agent
from google.adk.tools import google_search
root_agent = Agent(
name="search_assistant",
model="gemini-2.5-flash", # Or your preferred Gemini model
instruction="You are a helpful assistant. Answer user questions using Google Search when needed.",
description="An assistant that can search the web.",
tools=[google_search]
)
Define a multi-agent system:
Define a multi-agent system with coordinator agent, greeter agent, and task execution agent. Then ADK engine and the model will guide the agents to work together to accomplish the task.
from google.adk.agents import LlmAgent, BaseAgent
# Define individual agents
greeter = LlmAgent(name="greeter", model="gemini-2.5-flash", ...)
task_executor = LlmAgent(name="task_executor", model="gemini-2.5-flash", ...)
# Create parent agent and assign children via sub_agents
coordinator = LlmAgent(
name="Coordinator",
model="gemini-2.5-flash",
description="I coordinate greetings and tasks.",
sub_agents=[ # Assign sub_agents here
greeter,
task_executor
]
)
Development UI
A built-in development UI to help you test, evaluate, debug, and showcase your agent(s).
Evaluate Agents
adk eval \
samples_for_testing/hello_world \
samples_for_testing/hello_world/hello_world_eval_set_001.evalset.json
🤝 Contributing
We welcome contributions from the community! Whether it's bug reports, feature requests, documentation improvements, or code contributions, please see our
- General contribution guideline and flow.
- Then if you want to contribute code, please read Code Contributing Guidelines to get started.
Community Repo
We have adk-python-community repo that is home to a growing ecosystem of community-contributed tools, third-party service integrations, and deployment scripts that extend the core capabilities of the ADK.
Vibe Coding
If you want to develop agent via vibe coding the llms.txt and the llms-full.txt can be used as context to LLM. While the former one is a summarized one and the later one has the full information in case your LLM has big enough context window.
Community Events
- [Completed] ADK's 1st community meeting on Wednesday, October 15, 2025. Remember to join our group to get access to the recording, and deck.
📄 License
This project is licensed under the Apache 2.0 License - see the LICENSE file for details.
Happy Agent Building!
