Google ADK turns a model's Python block into an execution request. This adapter sends that request to plimsolld, checks the returned run record, and gives ADK its native execution result. Every block gets a fresh sandbox.
Google ADK: Google's Agent Development Kit, a Python framework for agents that can execute Python blocks through a replaceable code executor. Google ADK (EXTERNAL · official docs ↗)
The Professor (a fictional narrator)
Python gets to answer the question. It does not get to negotiate the locks.
Real quote
Gary O'Reilly: “They can write their own code. What's stopping them replicating themselves with code?”
Replay a recorded scenario. The diagram lights each hop the call passes; a refused call stops where it is refused.
These buttons send no execution requests. Each answer's source states how it was recorded, including any fixture used.
Exception panels show what reached the application, rather than an invented code result.
The model asks for
ADK result, or exception returned to the application
The Professor (a fictional narrator)
Each step of the call
Model: The model writes a Python code block. It does not choose credentials, the image, or the floor.
ADK: ADK finds the code block and calls the executor in a thread. The model receives ADK's native text result, not all of plimsoll's metadata.
Adapter: The adapter decodes ADK's text input files, fixes the language to Python and delegates to CodeExecutor. Invalid paths are refused here.
Checked client: The client checks daemon capabilities and the floor, sends one project request, and checks the returned run record. It never retries execution.
plimsolld: The daemon enforces the request's isolation floor and deadline, and runs in the configured image. Packages are built into that image.
Fresh Python: Python executes in a fresh sandbox. A normal code exception becomes a failed result. Named output artifacts retain their bytes.
How thick should the walls be?
The executor carries a floor; the daemon states its
isolation tier. This picker is a teaching simulation:
change either to see whether the tier meets the floor. It sends no request and does not check other capabilities.
The Professor (a fictional narrator)
The executor's floor defaults to kernel: docker under runc is the container tier and refuses every call until it runs gVisor, or the executor is built with an explicit container floor, which is for development on your own code only. Use the spelling shown in this page's wiring example.
Surprises and limits
Python blocks, not a new JavaScript modeADK's normal code-block path is Python. This adapter implements that path. plimsoll's other clients and tools can execute JavaScript, but this adapter does not change ADK's language convention. Use print to show a value; a bare expression is not implicitly printed.
CSV optimization requires persistent variablesThis fresh executor refuses optimize_data_file=True. ADK's automatic CSV exploration creates dataframe variables that later blocks expect to reuse, but each block here has a new interpreter. Installing pandas cannot make those variables persist. Applications can supply CSV text as explicit input files for each block and have that block read it; automatic Runner attachment preprocessing is unsupported.
Let the model correct a failed blockADK 2.11 checks error_retry_attempts before execution. Zero disables code and is refused. The adapter defaults to ADK's own two attempts, so the model can correct a failed block; any positive integer is accepted. Every block still runs fresh. Infrastructure exceptions propagate; without a not_dispatched mark, the code may have run.
Cancellation and deadlines differADK awaits a synchronous executor running in a thread. Cancelling that wait does not stop an already dispatched call. The daemon's deadline bounds execution; the default 30 seconds gives interactive calculations a budget below its five-minute maximum.
The model sees ADK's result, the application can inspect moreresult.execution preserves raw stdout and stderr bytes, checked records, isolation and truncation flags. ADK receives its native text result and saved-artifact names. Any stderr text, including warnings with exit zero, makes ADK report failure. A checked record establishes consistency, not independent proof of a remote host. Truncation keeps its flags in execution and adds no stderr diagnostic, so cutting otherwise successful output does not make ADK report a failure.
These buttons replay evidenceThe scenario buttons replay recorded local Docker/gVisor calls. They make no model or sandbox requests. The isolation picker is a teaching simulation. Framework tests separately drive the real ADK Runner with a scripted model and an RPC fixture; that checks wiring, not reasoning skill or isolation.