Skip to content

[Feature Request]: Add Creduent zero-trust agent identity verification plugin for ADK #6551

Description

@cyberfascinate

** Please make sure you read the contribution guide and file the issues in the right place. **
Contribution guide.

🔴 Required Information

Is your feature request related to a specific problem?

When ADK workflows delegate tasks to sub-agents, agents lack a standard mechanism to verify if a target agent URI (agent://<namespace>/<name>) is cryptographically signed before executing tasks. This allows untrusted agent calls and unverified prompt injections to compromise multi-agent execution loops.

Describe the Solution You'd Like

Introduce CreduentGoogleADKPlugin — a local Ed25519 + JCS RFC 8785 cryptographic verification plugin for agent URIs in under 5ms, with no network calls required.

Impact on your work

Critical for securing enterprise multi-agent delegation chains. Implementation and test suite are ready to submit as a Pull Request.

Willingness to contribute

Yes


🟡 Recommended Information

Describe Alternatives You've Considered

  1. Manual HTTP verification before sub-agent calls — adds latency.
  2. Custom wrapper functions — no standard schema validation across frameworks.

Proposed API / Implementation

from creduent.integrations.google_adk import CreduentGoogleADKPlugin

plugin = CreduentGoogleADKPlugin(
    agent_uri="agent://assistant.dev/agent",
    timeout=10
)

Additional Context

Metadata

Metadata

Assignees

Labels

agent config[Component] This issue is related to the Agent Config interface and implementationneeds review[Status] The PR/issue is awaiting review from the maintainer

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions