google / google/adk-python

GCPSkillRegistry rejects every Google-published skill: dotted ids (cloud.google.com-*) fail name validation in get_skill and search_skills

Open
#7,136 1 comment 0 reactions 1 assignee Claimed by @llalitkumarrr View on GitHub
tools
Dominant language
Python
Stars
21.5k
Forks
4k
Avg merge
1d 14h
Merged PRs (30d)
37

Description

Follow-up to #6838 / #6839: that fix stopped `search_skills` from crashing on these ids, but the ids themselves are still rejected everywhere, so Google-published skills remain unusable from ADK.

## 🔴 Required Information

**Describe the Bug:**
Skills published by Google into Agent Registry have resource ids of the form `cloud.google.com-` (also `discoveryengine.googleapis.com-`). ADK cannot use any of them:

- `GCPSkillRegistry.get_skill(name="cloud.google.com-google-cloud-networking-observability")` raises `ValueError: Invalid skill name ...` because the name check added in 11101acc only accepts kebab/snake case (no dots).
- `GCPSkillRegistry.search_skills()` feeds each id into `Frontmatter(name=...)`, whose validator also rejects dots, so since 3c977bc2 (#6838) every Google-published hit is dropped with a "Skipping search result" warning. `tests/unittests/integrations/skill_registry/test_gcp_skill_registry.py` even uses `cloud.google.com-agent-platform-eval-flywheel` as the example of a "bad" name.

In a real project catalog (location `global`) this rejects 113 of 117 skills; the only 4 that pass are ones we created ourselves with plain kebab ids. With the validation bypassed locally, downloading the Google skill works (SKILL.md with 7184 chars, 8 resources; the frontmatter name inside the archive equals the displayName and is valid kebab-case), so the archives themselves are fine. It is only the registry *id* that fails the SKILL.md naming rule.

**Steps to Reproduce:**
1. `google-adk` main (ac0133a4) or 2.9.1, project with Agent Registry enabled (Google-published skills are visible in the Console).
2. `registry = GCPSkillRegistry(project_id=..., location="global")`
3. `await registry.search_skills(query="networking")` -> only self-created skills are returned; one warning per Google skill.
4. `await registry.get_skill(name="cloud.google.com-google-cloud-networking-observability")` -> `ValueError`.

**Expected Behavior:**
Google-published skills are searchable and loadable. The security intent of 11101acc (single path segment, no traversal) can be kept by validating the id as a safe path segment (e.g. `^[A-Za-z0-9._-]+$`, and not `.`/`..`) instead of applying the SKILL.md frontmatter naming rule to a registry resource id. `search_skills` should not validate registry ids with the frontmatter rule either; that rule belongs to the SKILL.md inside the archive, which does pass.

**Observed Behavior:**
`ValueError` from `get_skill`, and silent exclusion from `search_skills`.

**Environment Details:**
- ADK Library Version: main @ ac0133a4, also 2.9.1
- Reproduced locally (macOS, Python 3.14) against a real Agent Registry catalog

**Model Information:**
- Are you using LiteLLM: No
- Which model is being used: N/A (registry client only)

## Additional Context

- #6838 reported this exact catalog entry (`cloud.google.com-agent-platform-eval-flywheel`) but asked only for the crash to be fixed; #6839 implemented "skip and log", and its description states this matches `get_skill()` already rejecting those names. So the current behaviour is deliberate at the symptom level, but it means every Google-published skill (113/117 in our catalog) is unreachable from ADK, which I don't think was the intent. This issue is about accepting those ids, not about the crash.
- Related: #6908 / #6824 (redirect on media download; needed for the download to succeed at all), #7130 / #7135 (pinning registry skills). Note that registry id and frontmatter name differ for 117/117 skills in the catalog, which is why #7135 needs to key the pinned skill by both names.
- Happy to send a PR.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.