Skip to main content

gfg-adr-detection

A packaged, importable build of ADR Detection from uber/ADR, maintained by Global Fashion Group for internal use and published so it can be installed with pip rather than cloned.

Not affiliated with or endorsed by Uber. This is a modified redistribution under the Apache License 2.0; the original copyright and LICENSE are retained. For the upstream project, its paper and its benchmark, go to github.com/uber/ADR.

⚠️ Not a general-purpose library

ADR Detection is a research artifact that parses hostile input and, in its high-precision tier, spawns a nested agent with permission checks off. Run it in a container, VM or dedicated host — not alongside your application.

Since 0.5.0 the default install is just the detector: four direct dependencies (mcp, openai, PyYAML, numpy) and a closure of roughly 38 packages. The research stack is opt-in, and the CVE-bearing pins upstream documents and accepts under an isolated threat model now live only in those extras:

Extra What it adds Why it is not default
baseline Meta's LlamaFirewall comparison: llamafirewall, torch, transformers and the NVIDIA CUDA wheels Several GB. guardrail imports llamafirewall under try/except, so the detector runs without it.
benchmark The frozen AgentDojo harness and the paper figures: the LangChain stack, nemoguardrails, matplotlib Holds the exact == pins retained for reproducibility. These carry the known CVEs.
corpus Dependencies of the ~200 deliberately vulnerable benchmark MCP servers Fixtures only; the corpus is not shipped in the wheel.

If you install [benchmark] or [baseline], the old advice applies in full: the == pins will conflict with most other packages, so give it a dedicated virtualenv.

0.8.0

Clears every high and critical advisory in the research extras.

  • [baseline] now requires transformers >= 5.10.0 (was 4.57.6). Three advisories against transformers have no fix on the 4.x line. Verified: llamafirewall's scanners initialise on transformers 5.17.0 + torch 2.14.0.
  • [benchmark] moves nemoguardrails 0.14.0 -> 0.24.1. Its old fastembed cap was holding pillow below 12 (13 advisories) and huggingface-hub below 1.0 (blocking the transformers fix). It also drops annoy, so no C++ toolchain is needed to install.
  • [corpus] no longer depends on standalone fastmcp, which was stuck on 1.0 with five advisories including a critical. The corpus servers now import FastMCP from mcp.server.fastmcp -- the copy bundled with mcp, already a runtime dependency -- which is what 47 of them already did.
  • google-cloud-aiplatform 1.71.1 -> 1.165.1.

The default install is unchanged in shape: same four runtime dependencies, same 38-package closure, and that closure now carries no known advisories at any severity.

0.7.0

Security bumps inside the research extras: langchain-core 0.3.28 -> 0.3.86 clears a critical serialization-injection advisory, plus aiohttp, tornado, langsmith, langchain, langchain-community, deepdiff and others. The default install is unchanged -- same four runtime dependencies, same closure.

Breaking in 0.6.0

The import package is guardrail again, not adr_guardrail. 0.4.0 and 0.5.0 shipped adr_guardrail; update imports:

from guardrail.adr_agent.adr_baseline import ADRBaseline   # 0.6.0+

Note that PyPI's unrelated guardrail distribution also ships a top-level guardrail package. Install this alongside it and one will shadow the other with no error, so give this package a dedicated virtualenv.

Breaking in 0.5.0

pip install gfg-adr-detection no longer installs torch, transformers, the LangChain stack, flask, spacy, nltk, opencv-python or ~90 other packages that nothing in the detector imports. Specifically:

  • LlamaFirewallBaseline now needs gfg-adr-detection[baseline]. Without it, is_available() returns False and main_detector.py --detector llamafirewall exits with a message. Note that constructing the class directly only logs a warning, so check is_available().
  • Reproducing the benchmark from a checkout needs uv sync --extra benchmark.
  • Running the corpus MCP servers needs --extra corpus.

What this package changes

Upstream resolves its runtime data relative to __file__, three directories up — which is the source tree in a checkout, and site-packages once installed. The practical effect was that an installed copy discovered zero MCP context providers and silently degraded from two detection tiers to one, with no error. This build fixes that and the related path assumptions:

  • context providers resolve from inside the package (ADR_CONTEXT_PROVIDERS_DIR overrides; the original layout is still honoured for source checkouts)
  • the reasoning workspace is relocatable via ADR_WORKSPACE_ROOT, instead of being created inside site-packages
  • MCP servers launch with sys.executable rather than uv run, which resolved an unrelated environment when installed as a wheel
  • the dependency axios is dropped — it is a JavaScript library, and the PyPI project of that name is unrelated to it and to ADR
  • the 16 MB benchmark corpus is not shipped, so the source-code context provider is disabled by default (enable_source_code: false)
  • the dependency set is split: the detector's own runtime closure is the default install, and the benchmark harness, the LlamaFirewall baseline and the corpus fixtures are extras. Upstream declared all three as hard requirements, so installing the detector pulled ~199 packages to run code that imports four. About 35 of those declarations are imported nowhere in the tree at all.

Install

python -m venv .venv && .venv/bin/pip install gfg-adr-detection

Requires Python 3.10–3.12. For the research extras:

pip install "gfg-adr-detection[benchmark]"   # AgentDojo harness + paper figures
pip install "gfg-adr-detection[baseline]"    # LlamaFirewall comparison (torch)

Use

from guardrail.adr_agent.adr_baseline import ADRBaseline

detector = ADRBaseline(config_data=config, benchmark_type="adr_bench")
verdict = detector.analyze_conversation(messages).to_dict()

config is the parsed config_detector.yaml structure documented upstream. The high-precision tier shells out to the Claude CLI, which refuses to run as root — so give the container an unprivileged user.

Licence

Apache-2.0, as the original. See LICENSE.

Release files for gfg-adr-detection 0.8.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for gfg-adr-detection 0.8.0
File Size Uploaded
gfg_adr_detection-0.8.0.tar.gz 73.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for gfg-adr-detection 0.8.0
File Interpreter ABI Platform
gfg_adr_detection-0.8.0-py3-none-any.whl Python 3 none any Details

Total release size: 159.4 kB

Release files / gfg_adr_detection-0.8.0.tar.gz

Download URL gfg_adr_detection-0.8.0.tar.gz
Size 73.6 kB
Tags Source
SHA-256 checksum
How to use checksums
c9d6b08db1e2822184e84a374502c7b4b4c28d4ff8fc798e9ae5b3cd2b4f15cc
BLAKE2b-256 checksum
How to use checksums
16883bd25978c30fcdb29632b0368e378869412b551386b5d62d2dce3e09812e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.32 {"installer":{"name":"uv","version":"0.11.32","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Amazon Linux","version":"2023","id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release files / gfg_adr_detection-0.8.0-py3-none-any.whl

Download URL gfg_adr_detection-0.8.0-py3-none-any.whl
Size 85.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
0ce4b1fd38d464ae692f3841ac949bebdcb6d45fa07d683159be9925cc641598
BLAKE2b-256 checksum
How to use checksums
f3d0149e14d94b310f620aa4b2d2ce7920d04442809f6de1996c0a096c5ac421
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.32 {"installer":{"name":"uv","version":"0.11.32","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Amazon Linux","version":"2023","id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release history Release notifications | RSS feed

0.8.1

2 release files

This release

0.8.0 This release

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page