Skip to content

integrations: add Attenu Guard plugin (per-agent permissions on tool calls and transfers) - #2176

Open
rafaelasor wants to merge 4 commits into
google:mainfrom
rafaelasor:integration-attenu-guard
Open

integrations: add Attenu Guard plugin (per-agent permissions on tool calls and transfers)#2176
rafaelasor wants to merge 4 commits into
google:mainfrom
rafaelasor:integration-attenu-guard

Conversation

@rafaelasor

Copy link
Copy Markdown

Adds docs/integrations/attenu-guard.md (+ catalog icon) for the Attenu Guard ADK plugin (Apache-2.0, PyPI attenu-guard, extra attenu-guard[google-adk]).

The plugin is one BasePlugin (attenu_guard.adapters.google_adk): before_agent_callback computes each sub-agent's permission set as the meet of the parent's and the declared child set when control reaches it (covers transfer_to_agent, AgentTool and task-mode sub-agents), and before_tool_callback checks each tool call before the tool body runs. Decisions land in a hash-chained audit log verified offline. Tested against google-adk 2.7.1; the repo ships a scripted-model example (no API key) and a live smoke test.

Follows the plugin-page conventions (frontmatter, language tag, Use cases, Prerequisites, Installation, Use with agent, Resources). Disclosure: I maintain attenu-guard. I have signed / will sign the Google CLA on this PR.

@google-cla

google-cla Bot commented Aug 26, 2026

Copy link
Copy Markdown

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

@rafaelasor

Copy link
Copy Markdown
Author

@googlebot I signed it!

Shorten catalog_description to fit the card (was 143 chars, now 55)
and drop stray em dashes in prose per the integration-review style
guide, picked up while rebasing onto a base that had moved 15
commits ahead.
@rafaelasor
rafaelasor force-pushed the integration-attenu-guard branch from 293869a to 123a0a9 Compare September 1, 2026 05:44
@rafaelasor

Copy link
Copy Markdown
Author

Rebased onto main on 09-01 and re-checked the entry against the integration-review checklist. CLA is signed and checks are green. Is there anything else you need from me before a review?

@rafaelasor

Copy link
Copy Markdown
Author

@joefernandez Could you triage this one? It has had no label since it opened on 2026-08-26. It adds one page under docs/integrations/ plus its screenshot, for an ADK plugin that narrows what a sub-agent may do at each transfer and checks every tool call before the body runs. integration looks like the right label.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant