feat(plugins): add TealTiger governance plugin - #7013
Conversation
|
Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). View this failed invocation of the CLA check for more information. For the most up to date status, view the checks section at the bottom of the pull request. |
Wrap TealTigerCallback so PII, allowlist, cost, and freeze policies run as an App-level plugin before and after tool calls.
f33a7c6 to
674fc41
Compare
|
Thanks @amanishimwe! I don't think we can take it into TealTiger already ships |
Summary
TealTigerPlugin, an App-level wrapper aroundtealtiger.integrations.google_adk.TealTigerCallback, so PII, allowlist, secret, cost, and freeze policies run on every agent under anApp.pip install tealtiger. Construction without the SDK (or an injectedcallback) raisesImportError.Description of Change
Problem:
TealTiger ships ADK tool hooks as
TealTigerCallback.before_tool/after_tool, meant to be attached per agent. ADK plugins run for every agent in anAppand use a different callback signature, so those hooks need an adapter.Solution:
Add
TealTigerPlugin(BasePlugin)that forwards plugin tool callbacks toTealTigerCallbackby name, passes deny dicts through so ADK skips the tool, and fails closed if evaluation throws.Testing Plan
Unit Tests:
pytest tests/unittests/plugins/test_tealtiger_plugin.py— 10 passedE2E:
tealtigerpackage. Live check:pip install tealtiger, putTealTigerPlugin(..., mode="ENFORCE")on anApp, call a tool with PII in args, confirm[GOVERNANCE DENIED].