Skip to content

Proposal: AffixIOGuardPlugin for host-side tool action proof #184

Description

@AffixIO

What

Community plugin: AffixIOGuardPlugin that gates sensitive tool calls via AffixIO on the host, same shelf as AgentGovernancePlugin / HITL samples.

Why AffixIO here

AffixIO proves a host-side ACTION completed (signed yes/no). PII stays on the host. Not person/age/KYC.

Sit: before an ADK agent runs a sensitive tool (spend, DB admin, destructive API), AffixIO can gate/prove the action on the host using before_tool_callback on BasePlugin.

Install

npm i affixio
npm i @affixio/[email protected]

MCP is local stdio.

Sketch

# google.adk_community.plugins.affixio_guard_plugin
class AffixIOGuardPlugin(BasePlugin):
    async def before_tool_callback(self, *, tool, tool_args, tool_context):
        # For allowlisted sensitive tools: require AffixIO host proof
        # Deny / short-circuit if unsigned or rejected
        ...

Would live under src/google/adk_community/plugins/ plus a small sample next to contributing/samples/agent_governance and hitl_approval.

Links

Offer

Happy to open a focused PR if maintainers want this shape. Prefer confirm fit first so we do not dump a heavy wrap.

Context

Kris / AffixIO. Looking for a light community integration, not a core ADK change (core already has BasePlugin tool callbacks).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions