Agent Frameworks & Harnesses 2026-09-30

Framework Watch: Google ADK 2.10 Lets Agents Unload Skills, and Codex Lets You Interrupt a Running Turn

ADK 2.10.0 (September 24) adds experimental skill lifecycles, cost and latency metrics in evals, and first-class OpenAI reasoning-model support. Codex CLI 0.159.0 (September 29) adds opt-in instant interrupts and protects .aws directories by default.

Two agent-framework releases in the past week target the same practical problem: long-running agents accumulate context and keep going after the human has changed their mind.

Google Agent Development Kit (Python) 2.10.0, released on September 24, 2026, highlights:

  • Skill lifecycles (experimental, enabled with ADK_ENABLE_SKILL_LIFECYCLE=1): an ephemeral lifecycle that lasts one turn, an opt-in unload_skill tool, a cap on active skills, and dropping an unloaded skill's instructions from later requests. A new SkillDiscoveryMode controls how the skill catalog is disclosed to the model.
  • Evaluation efficiency metrics: duration, token consumption and model-call counts alongside quality scores.
  • OpenAI models move to google.adk.integrations.openai with per-model reasoning effort, reasoning-token reporting and streaming usage.
  • A MongoDB toolset with vector and hybrid search, and an optional context_builder on RemoteA2aAgent.

It also changes some behaviour. BigQuery's protected write mode now rejects statements whose dry run gives no destination in the session's anonymous dataset, such as multi-statement scripts, CALL and EXPORT DATA. AgentEvaluator.evaluate raises an error when no eval cases actually run instead of silently passing. Instruction templating now leaves ${var} and escaped placeholders as written, and legacy live-audio modules warn on import, which breaks test suites run with warnings as errors.

OpenAI Codex CLI 0.159.0, released on September 29, adds an opt-in instant_interrupt that lets new user input steer Codex during a model response or a long-running code-mode call, rather than waiting for the turn to end. On the safety side, approved commands now keep explicit filesystem denials, and .aws directories are protected by default under writable roots. It also removes automatic follow-up prompt suggestions and the bundled plugin-creator skill.

The common thread: skills and tools are cheap to add but expensive to carry, because every loaded skill consumes context and widens what the agent may do. ADK's lifecycles treat a skill like a scoped resource that can be released, and its new eval metrics make the cost visible. Codex's interrupt treats the human as able to redirect mid-turn instead of only before and after. Teams upgrading ADK should rerun evals first, since the silent-pass fix may turn green suites red, and check any BigQuery write scripts against the stricter protected mode.

ADK 2.10 makes skills unloadable and evals cost-aware, while Codex 0.159 lets a human steer mid-turn and hardens credential directories; ADK's stricter eval and BigQuery behaviour can break existing pipelines on upgrade, so test before bumping.