Skip to main content

gfg-adr-detection

A packaged, importable build of ADR Detection from uber/ADR, maintained by Global Fashion Group for internal use and published so it can be installed with pip rather than cloned.

Not affiliated with or endorsed by Uber. This is a modified redistribution under the Apache License 2.0; the original copyright and LICENSE are retained. For the upstream project, its paper and its benchmark, go to github.com/uber/ADR.

⚠️ Not a general-purpose library

ADR Detection is a research artifact that parses hostile input and, in its high-precision tier, spawns a nested agent with permission checks off. Run it in a container, VM or dedicated host — not alongside your application.

Since 0.5.0 the default install is just the detector: four direct dependencies (mcp, openai, PyYAML, numpy) and a closure of roughly 38 packages. The research stack is opt-in, and the CVE-bearing pins upstream documents and accepts under an isolated threat model now live only in those extras:

Extra What it adds Why it is not default
baseline Meta's LlamaFirewall comparison: llamafirewall, torch, transformers and the NVIDIA CUDA wheels Several GB. guardrail imports llamafirewall under try/except, so the detector runs without it.
benchmark The frozen AgentDojo harness and the paper figures: the LangChain stack, nemoguardrails, matplotlib Holds the exact == pins retained for reproducibility. These carry the known CVEs.
corpus Dependencies of the ~200 deliberately vulnerable benchmark MCP servers Fixtures only; the corpus is not shipped in the wheel.

If you install [benchmark] or [baseline], the old advice applies in full: the == pins will conflict with most other packages, so give it a dedicated virtualenv.

Breaking in 0.6.0

The import package is guardrail again, not adr_guardrail. 0.4.0 and 0.5.0 shipped adr_guardrail; update imports:

from guardrail.adr_agent.adr_baseline import ADRBaseline   # 0.6.0+

Note that PyPI's unrelated guardrail distribution also ships a top-level guardrail package. Install this alongside it and one will shadow the other with no error, so give this package a dedicated virtualenv.

Breaking in 0.5.0

pip install gfg-adr-detection no longer installs torch, transformers, the LangChain stack, flask, spacy, nltk, opencv-python or ~90 other packages that nothing in the detector imports. Specifically:

  • LlamaFirewallBaseline now needs gfg-adr-detection[baseline]. Without it, is_available() returns False and main_detector.py --detector llamafirewall exits with a message. Note that constructing the class directly only logs a warning, so check is_available().
  • Reproducing the benchmark from a checkout needs uv sync --extra benchmark.
  • Running the corpus MCP servers needs --extra corpus.

What this package changes

Upstream resolves its runtime data relative to __file__, three directories up — which is the source tree in a checkout, and site-packages once installed. The practical effect was that an installed copy discovered zero MCP context providers and silently degraded from two detection tiers to one, with no error. This build fixes that and the related path assumptions:

  • context providers resolve from inside the package (ADR_CONTEXT_PROVIDERS_DIR overrides; the original layout is still honoured for source checkouts)
  • the reasoning workspace is relocatable via ADR_WORKSPACE_ROOT, instead of being created inside site-packages
  • MCP servers launch with sys.executable rather than uv run, which resolved an unrelated environment when installed as a wheel
  • the dependency axios is dropped — it is a JavaScript library, and the PyPI project of that name is unrelated to it and to ADR
  • the 16 MB benchmark corpus is not shipped, so the source-code context provider is disabled by default (enable_source_code: false)
  • the dependency set is split: the detector's own runtime closure is the default install, and the benchmark harness, the LlamaFirewall baseline and the corpus fixtures are extras. Upstream declared all three as hard requirements, so installing the detector pulled ~199 packages to run code that imports four. About 35 of those declarations are imported nowhere in the tree at all.

Install

python -m venv .venv && .venv/bin/pip install gfg-adr-detection

Requires Python 3.10–3.12. For the research extras:

pip install "gfg-adr-detection[benchmark]"   # AgentDojo harness + paper figures
pip install "gfg-adr-detection[baseline]"    # LlamaFirewall comparison (torch)

Use

from guardrail.adr_agent.adr_baseline import ADRBaseline

detector = ADRBaseline(config_data=config, benchmark_type="adr_bench")
verdict = detector.analyze_conversation(messages).to_dict()

config is the parsed config_detector.yaml structure documented upstream. The high-precision tier shells out to the Claude CLI, which refuses to run as root — so give the container an unprivileged user.

Licence

Apache-2.0, as the original. See LICENSE.

Release files for gfg-adr-detection 0.6.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for gfg-adr-detection 0.6.0
File Size Uploaded
gfg_adr_detection-0.6.0.tar.gz 72.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for gfg-adr-detection 0.6.0
File Interpreter ABI Platform
gfg_adr_detection-0.6.0-py3-none-any.whl Python 3 none any Details

Total release size: 157.8 kB

Release files / gfg_adr_detection-0.6.0.tar.gz

Download URL gfg_adr_detection-0.6.0.tar.gz
Size 72.5 kB
Tags Source
SHA-256 checksum
How to use checksums
116f96e5165f6480b9d43bf0b916f4cb0a7370388124924c8c4c316c30c6582d
BLAKE2b-256 checksum
How to use checksums
9d13ea424971e3d15d81c4fb97a9388ec80b6b51cbd858be5244236242416f9a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.32 {"installer":{"name":"uv","version":"0.11.32","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Amazon Linux","version":"2023","id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release files / gfg_adr_detection-0.6.0-py3-none-any.whl

Download URL gfg_adr_detection-0.6.0-py3-none-any.whl
Size 85.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
8d9f89b14a6aa12e43b76212aac8d6a1bd4ddd06ec2a47a8d38c87d5e389bc26
BLAKE2b-256 checksum
How to use checksums
4762944a627e6fe17885b18640c0a910c5c899092026fd3fc99db8a086248a1f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.32 {"installer":{"name":"uv","version":"0.11.32","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Amazon Linux","version":"2023","id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release history Release notifications | RSS feed

0.8.1

2 release files

0.8.0

2 release files

0.7.0

2 release files

This release

0.6.0 This release

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page