gfg-adr-detection
A packaged, importable build of ADR Detection from
uber/ADR, maintained by Global Fashion Group for
internal use and published so it can be installed with pip rather than cloned.
Not affiliated with or endorsed by Uber. This is a modified redistribution
under the Apache License 2.0; the original copyright and LICENSE are retained.
For the upstream project, its paper and its benchmark, go to
github.com/uber/ADR.
⚠️ Not a general-purpose library
ADR Detection is a research artifact that parses hostile input and, in its high-precision tier, spawns a nested agent with permission checks off. Run it in a container, VM or dedicated host — not alongside your application.
Since 0.5.0 the default install is just the detector: four direct
dependencies (mcp, openai, PyYAML, numpy) and a closure of roughly 38
packages. The research stack is opt-in, and the CVE-bearing pins upstream
documents and accepts under an isolated threat model now live only in those
extras:
| Extra | What it adds | Why it is not default |
|---|---|---|
baseline |
Meta's LlamaFirewall comparison: llamafirewall, torch, transformers and the NVIDIA CUDA wheels |
Several GB. guardrail imports llamafirewall under try/except, so the detector runs without it. |
benchmark |
The frozen AgentDojo harness and the paper figures: the LangChain stack, nemoguardrails, matplotlib |
Holds the exact == pins retained for reproducibility. These carry the known CVEs. |
corpus |
Dependencies of the ~200 deliberately vulnerable benchmark MCP servers | Fixtures only; the corpus is not shipped in the wheel. |
If you install [benchmark] or [baseline], the old advice applies in full:
the == pins will conflict with most other packages, so give it a dedicated
virtualenv.
Breaking in 0.6.0
The import package is guardrail again, not adr_guardrail. 0.4.0 and 0.5.0
shipped adr_guardrail; update imports:
from guardrail.adr_agent.adr_baseline import ADRBaseline # 0.6.0+
Note that PyPI's unrelated guardrail distribution also ships a top-level
guardrail package. Install this alongside it and one will shadow the other
with no error, so give this package a dedicated virtualenv.
Breaking in 0.5.0
pip install gfg-adr-detection no longer installs torch, transformers, the
LangChain stack, flask, spacy, nltk, opencv-python or ~90 other packages
that nothing in the detector imports. Specifically:
LlamaFirewallBaselinenow needsgfg-adr-detection[baseline]. Without it,is_available()returnsFalseandmain_detector.py --detector llamafirewallexits with a message. Note that constructing the class directly only logs a warning, so checkis_available().- Reproducing the benchmark from a checkout needs
uv sync --extra benchmark. - Running the corpus MCP servers needs
--extra corpus.
What this package changes
Upstream resolves its runtime data relative to __file__, three directories up —
which is the source tree in a checkout, and site-packages once installed. The
practical effect was that an installed copy discovered zero MCP context
providers and silently degraded from two detection tiers to one, with no error.
This build fixes that and the related path assumptions:
- context providers resolve from inside the package (
ADR_CONTEXT_PROVIDERS_DIRoverrides; the original layout is still honoured for source checkouts) - the reasoning workspace is relocatable via
ADR_WORKSPACE_ROOT, instead of being created insidesite-packages - MCP servers launch with
sys.executablerather thanuv run, which resolved an unrelated environment when installed as a wheel - the dependency
axiosis dropped — it is a JavaScript library, and the PyPI project of that name is unrelated to it and to ADR - the 16 MB benchmark corpus is not shipped, so the source-code context provider
is disabled by default (
enable_source_code: false) - the dependency set is split: the detector's own runtime closure is the default install, and the benchmark harness, the LlamaFirewall baseline and the corpus fixtures are extras. Upstream declared all three as hard requirements, so installing the detector pulled ~199 packages to run code that imports four. About 35 of those declarations are imported nowhere in the tree at all.
Install
python -m venv .venv && .venv/bin/pip install gfg-adr-detection
Requires Python 3.10–3.12. For the research extras:
pip install "gfg-adr-detection[benchmark]" # AgentDojo harness + paper figures
pip install "gfg-adr-detection[baseline]" # LlamaFirewall comparison (torch)
Use
from guardrail.adr_agent.adr_baseline import ADRBaseline
detector = ADRBaseline(config_data=config, benchmark_type="adr_bench")
verdict = detector.analyze_conversation(messages).to_dict()
config is the parsed config_detector.yaml structure documented upstream. The
high-precision tier shells out to the Claude CLI, which refuses to run as root —
so give the container an unprivileged user.
Licence
Apache-2.0, as the original. See LICENSE.
Release files for gfg-adr-detection 0.6.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| gfg_adr_detection-0.6.0.tar.gz | 72.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| gfg_adr_detection-0.6.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 157.8 kB
Release files / gfg_adr_detection-0.6.0.tar.gz
| Download URL | gfg_adr_detection-0.6.0.tar.gz |
|---|---|
| Size | 72.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
116f96e5165f6480b9d43bf0b916f4cb0a7370388124924c8c4c316c30c6582d
|
|
BLAKE2b-256 checksum How to use checksums |
9d13ea424971e3d15d81c4fb97a9388ec80b6b51cbd858be5244236242416f9a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.32 {"installer":{"name":"uv","version":"0.11.32","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Amazon Linux","version":"2023","id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|
Release files / gfg_adr_detection-0.6.0-py3-none-any.whl
| Download URL | gfg_adr_detection-0.6.0-py3-none-any.whl |
|---|---|
| Size | 85.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
8d9f89b14a6aa12e43b76212aac8d6a1bd4ddd06ec2a47a8d38c87d5e389bc26
|
|
BLAKE2b-256 checksum How to use checksums |
4762944a627e6fe17885b18640c0a910c5c899092026fd3fc99db8a086248a1f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.32 {"installer":{"name":"uv","version":"0.11.32","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Amazon Linux","version":"2023","id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|