Agent Frameworks & Harnesses 2026-10-05

Framework Watch: Google ADK 2.11 and OpenAI's Agents SDK 0.23 Both Ship on October 1 -- With Cancellation, Approvals and Redaction

ADK 2.11.0 adds graceful run cancellation, tool confirmation inside workflows, a budget-capped tool for consulting a second model, SQLite memory and an MCP SDK 2.x path. OpenAI Agents SDK 0.23.0 scopes tool approvals to the agent that owns the tool and redacts tool-failure details by default.

Two of the main agent frameworks shipped releases dated October 1, 2026. Read together, they show the same priority: making runs that can be stopped, paused for a human, and audited without leaking data.

Google ADK for Python 2.11.0

  • Execution cancellation. Pass an abort_signal to Runner, Workflow and nodes to stop a run gracefully; /run_sse now cancels the run when the client disconnects, and ADK synthesizes an abort event and function response so the history stays consistent. A related fix cancels an in-flight tool call when its caller is cancelled.
  • Tool confirmation in workflows. Tool nodes now pause for user approval via RequestInput, as an LlmAgent already does, "instead of passing an error downstream."
  • ModelConsultTool. An agent can consult another model mid-task, capped by per-turn and per-session budgets; the consulted "advisor" model is invoked without tools.
  • Memory and MCP. A built-in SQLite memory service (sqlite://), and an opt-in path to connect to MCP servers through MCP SDK 2.x. An optional ToolCallIntegrityPlugin is also added, and credential-request events are kept out of the compaction prompt.
  • Breaking change: the dev UI's runtime-config.json is now served per request instead of written into the installed package; set the logo with --logo-text and --logo-image-url.

OpenAI Agents SDK (Python) 0.23.0

  • Approvals scoped to their owner. "Scope function tool approvals to their owning agent" -- an approval granted for one agent's tool no longer carries over to another agent's tool of the same name.
  • Less leakage by default. Default tool-failure details and streaming task exception tracebacks are now redacted, and sensitive-trace settings are respected for model metadata.
  • Sandbox and sessions. Opt-in protection against removing Docker sandboxes, configurable memory-consolidation turns, and an opt-in budget for scanning encrypted session history. MCP listing page limits are now configurable.
  • Correctness. Many fixes isolate nested agent-tool state across runs and reject silently discarded tool arguments. Version 0.23.1 followed on October 2.

Who should act. ADK users who run long workflows behind a web front end get real cancellation for the first time and should wire the abort signal through; anyone who edited the installed runtime-config.json must switch to the new flags. Agents SDK users with multi-agent setups where tools share names should upgrade, because approval scope was broader than it looked.

Analysis: both releases treat a human approval as something that must attach to a specific agent and a specific action, and both make it easier to stop work cleanly. That is the same lesson the Claude Code permission fixes of the past week taught from the other direction: controls that match on names or text drift from what actually runs. ADK's budget-capped ModelConsultTool is also notable -- consulting a stronger model only at decision points is becoming a standard harness pattern, and putting a hard budget on it is the right default.

Google ADK 2.11.0 and OpenAI Agents SDK 0.23.0, both released October 1, add graceful cancellation, workflow-level tool confirmation, per-agent approval scope and default redaction -- frameworks are converging on approvals that bind to a specific agent and action, and runs that can be stopped cleanly.