GcpSkillRegistry.get_skill() always fails with 302: Agent Registry media download redirect to GCS signed URL is not followed
- Dominant language
- Python
- Stars
- 21.5k
- Forks
- 4k
- Avg merge
- 1d 14h
- Merged PRs (30d)
- 37
Description
## 🔴 Required Information
**Describe the Bug:**
`GcpSkillRegistry.get_skill()` always fails when downloading the skill archive. The Agent Registry API serves the revision media download (`?alt=media`) as a `302` redirect to a short-lived GCS signed URL. The `httpx.AsyncClient` created in `_create_httpx_client` does not follow redirects (httpx default), and httpx's `response.raise_for_status()` raises on 3xx responses, so `_make_request` surfaces the redirect as an error and the skill archive can never be downloaded:
```
RuntimeError: API request failed with status 302: ...
```
This makes skill loading from the GCP Agent Registry (e.g. via `SkillToolset.load_skill`) unusable against the real API.
**Steps to Reproduce:**
1. Install `google-adk==2.7.1`.
2. Point `GcpSkillRegistry` at an Agent Registry project/location containing any skill.
3. `await registry.get_skill(name="")`.
4. The metadata request succeeds, then the `?alt=media` media download fails with the `RuntimeError` above.
**Expected Behavior:**
The client follows the 302 redirect to the GCS signed URL and downloads the skill archive. (This is safe: httpx removes the `Authorization` header when following a cross-origin redirect, so the OAuth bearer token is not forwarded to the signed-URL host.)
**Observed Behavior:**
`RuntimeError: API request failed with status 302: ...` raised from `_make_request` for every skill download.
**Environment Details:**
- ADK Library Version (pip show google-adk): 2.7.1
- Reproduced both locally and with an agent deployed on Agent Engine runtime. Also independently confirmed by another user on 2.7.1 (Linux / Python 3.12), who has been working around it with a client-side monkey-patch since 2.6.2 — see https://github.com/google/adk-python/pull/6824#issuecomment (PR comment thread).
**Model Information:**
- Are you using LiteLLM: No
- Which model is being used: N/A (client-side registry download; no model involved)
## Fix
PR #6824 is open with the fix: pass `follow_redirects=True` to both `httpx.AsyncClient` constructions in `_create_httpx_client` (plain and mTLS/ssl-context branches). It includes unit tests and has been verified end-to-end against a real Agent Registry catalog (the identical change applied as a monkey-patch on Agent Engine runtime restores skill downloads).
Contributor guide
Assessment
This issue has not been assessed yet.