Is your feature request related to a specific problem?
ADK has a global BasePlugin.before_tool_callback that can skip a tool by returning a result dictionary. Users integrating an external deterministic policy need a concrete pattern for binding that decision to the current tool name, arguments, and trusted ToolContext, then returning an understandable denial without invoking the tool.
Describe the Solution You'd Like
Add an opt-in sample plugin using Semaprax as the policy evaluator. It should show one allowed and one denied function-tool call, use None only for the allow path, and return a structured denial for the blocked path. The example should explain how to obtain a trusted caller identity from the ADK application rather than reading one from model-supplied arguments. It should state the coverage of ordinary and live runs; #4704 tracks a separate live plugin-callback gap.
Impact on your work
A developer could express argument-sensitive permission rules in checked code while ADK continues to own agent/tool execution. No deadline or production deployment is claimed.
Willingness to contribute
I can provide a detailed adapter specification and test cases; I am not claiming an implementation exists yet.
Alternatives considered
An agent-level prompt or after-tool callback cannot prevent the tool effect. The existing before-tool plugin API is the intended integration point.
ADK plugin callback: https://github.com/google/adk-python/blob/main/src/google/adk/plugins/base_plugin.py
Semaprax: https://github.com/wavect/semaprax
Is your feature request related to a specific problem?
ADK has a global
BasePlugin.before_tool_callbackthat can skip a tool by returning a result dictionary. Users integrating an external deterministic policy need a concrete pattern for binding that decision to the current tool name, arguments, and trustedToolContext, then returning an understandable denial without invoking the tool.Describe the Solution You'd Like
Add an opt-in sample plugin using Semaprax as the policy evaluator. It should show one allowed and one denied function-tool call, use
Noneonly for the allow path, and return a structured denial for the blocked path. The example should explain how to obtain a trusted caller identity from the ADK application rather than reading one from model-supplied arguments. It should state the coverage of ordinary and live runs; #4704 tracks a separate live plugin-callback gap.Impact on your work
A developer could express argument-sensitive permission rules in checked code while ADK continues to own agent/tool execution. No deadline or production deployment is claimed.
Willingness to contribute
I can provide a detailed adapter specification and test cases; I am not claiming an implementation exists yet.
Alternatives considered
An agent-level prompt or after-tool callback cannot prevent the tool effect. The existing before-tool plugin API is the intended integration point.
ADK plugin callback: https://github.com/google/adk-python/blob/main/src/google/adk/plugins/base_plugin.py
Semaprax: https://github.com/wavect/semaprax