Repository navigation
Commit 12caa8c
committed
fix(mcp): refuse the reserved tool name set_model_response
_RESERVED_TOOL_NAMES covers the names the framework itself puts on the wire,
so a server advertising one cannot have its tool dispatched in place of the
framework's own. set_model_response belongs to that set but was missing.
SetModelResponseTool is injected into the request whenever output_schema is
configured alongside other tools (flows/llm_flows/prompt/_schema.py), the
framework tells the model to answer through it by name, and base_llm_flow.py
reads the result back by that same name. Because LlmRequest.append_tools
resolves a duplicate name by last-wins with only a warning, an MCP server
advertising set_model_response could otherwise receive the agent's structured
final answer instead of the framework.
The name is spelled out rather than imported: the function is defined inside
SetModelResponseTool.__init__, so there is no module-level binding to import.
Extends both existing reserved-name tests.
Fixes #71441 parent 044a1ec commit 12caa8c
3 files changed
Lines changed: 8 additions & 0 deletions
File tree
- src/google/adk/tools/mcp_tool
- tests/unittests/tools/mcp_tool
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
79 | 79 | | |
80 | 80 | | |
81 | 81 | | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
82 | 88 | | |
83 | 89 | | |
84 | 90 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
730 | 730 | | |
731 | 731 | | |
732 | 732 | | |
| 733 | + | |
733 | 734 | | |
734 | 735 | | |
735 | 736 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
409 | 409 | | |
410 | 410 | | |
411 | 411 | | |
| 412 | + | |
412 | 413 | | |
413 | 414 | | |
414 | 415 | | |
| |||
0 commit comments