Skip to content

[Feature Request]: Add Creduent zero-trust agent identity verification plugin for ADK #6551

Description

@cyberfascinate

** Please make sure you read the contribution guide and file the issues in the right place. **
Contribution guide.

🔴 Required Information

Is your feature request related to a specific problem?

When ADK workflows delegate tasks to sub-agents, agents lack a standard mechanism to verify if a target agent URI (agent://<namespace>/<name>) is cryptographically signed before executing tasks. This allows untrusted agent calls and unverified prompt injections to compromise multi-agent execution loops.

Describe the Solution You'd Like

Introduce CreduentGoogleADKPlugin — a local Ed25519 + JCS RFC 8785 cryptographic verification plugin for agent URIs in under 5ms, with no network calls required.

Impact on your work

Critical for securing enterprise multi-agent delegation chains. Implementation and test suite are ready to submit as a Pull Request.

Willingness to contribute

Yes


🟡 Recommended Information

Describe Alternatives You've Considered

  1. Manual HTTP verification before sub-agent calls — adds latency.
  2. Custom wrapper functions — no standard schema validation across frameworks.

Proposed API / Implementation

from creduent.integrations.google_adk import CreduentGoogleADKPlugin

plugin = CreduentGoogleADKPlugin(
    agent_uri="agent://assistant.dev/agent",
    timeout=10
)

Additional Context

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions