0.12.2

Security patch: Google ADK stops emitting a remote agent's repeat of the forwarded request

A security patch. All six packages move to 0.12.2 together, and only @silverprotocol/google-adk changes. The spec revision stays 1.0.0-draft.8. Details are in the advisory, GHSA-7mgv-vf77-ch53. This is separate from the 0.12.1 patch, which doesn’t stop the repeat described here.

What changed

  • A remote agent’s repeat of the forwarded message is no longer mapped. Some remote A2A agents repeat the forwarded message back in their first reply. ADK-Python’s A2A executor on a2a-sdk 0.3.x sends it back as a new task’s submitted status, in the "user" role, and the relay yields it as the remote agent’s own output: model text on @google/adk, reasoning on ADK-Python’s relay. Before 0.12.2 the normalizer mapped that output like any other content, so the forwarded conversation reached the emitted events. It can hold the user’s text, other agents’ replies, tool-call arguments and tool results, and, on @google/adk before 2.1.0, an adk_request_credential call’s OAuth client secret.
  • 0.12.2 recognizes the repeat in a relayed event whose recorded reply is a submitted status with its message in the "user" role, and maps the event as if the repeated message’s parts were absent. Every other part of the event, including a task’s artifact parts, is mapped as before. In their place it emits one ext.google.relay-echo-omitted event inside the turn the relayed event belongs to. That event carries only the number of parts omitted, and none of their content.
  • A user-role message relayed in any other state, such as a remote workflow’s tool result while it’s working, is mapped as before.

Who is affected

An application on @silverprotocol/google-adk 0.3.0 to 0.12.1 that runs an agent tree containing a RemoteA2AAgent, or feeds the normalizer ADK events serialized from ADK-Python’s relay, when the remote agent repeats the forwarded message. An application that doesn’t relay to a remote A2A agent, or whose remote agents don’t repeat it, isn’t affected.

What to do

  1. Upgrade every @silverprotocol/* package to 0.12.2, including where another package pins one (check your lockfile), and rebuild any image that bundles the normalizer.
  2. Rotate any secret that could have ridden in the repeat, as the advisory lists.
  3. Purge those relay turns’ stored output, as the advisory describes.

Until you can upgrade, the advisory describes a workaround for each relay. What 0.12.2 doesn’t cover is listed there too.