Fetching from the wire…
Public story · 2026-08-31 · high
The change closes a hole where shared-scope knowledge bases exposed any server-readable file to every attached agent.
Why now: Agno released 3.0.4 on August 30.
Agno turned off automatic file ingestion in its knowledge-base tools with its 3.0.4 release, published August 30.
The default mattered because of how shared knowledge bases behave. Under scope="shared", anything one agent ingests becomes readable by every other agent on that knowledge base. A single wide-open path, an env file or a credentials directory, got redistributed to the whole group automatically. That risk hit any team pooling multiple agents on one knowledge base. Every member inherited whatever got ingested, regardless of which agent pulled it in.
Version 3.0.4 replaces the 2.x enable_ingest and enable_remove flags with per-tool flags. Ingestion is now something you turn on per tool, not something left on by default.
The release also moves agno.tools.knowledge_management to agno.tools.knowledge, with no compatibility shim. Code built against 3.0.3 breaks on import until it's updated.
The fix only changes what happens next. Knowledge bases that already ingested a broad path under 2.x's on-by-default setting still have that content synced to every agent that shares the base. The version bump doesn't retroactively narrow what's already there.
Each link below shares sources, entities, or timing with this story.
Agno supports MCP / Shared entities / Same source domain / Earlier coverage
Linked by a graph relationship (Agno supports MCP); both cover Agno, Released August; reported by the same outlet (github.com).
Agno supports MCP / Shared entity: Agno / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Agno supports MCP); both cover Agno; reported by the same outlet (github.com).
Agno uses IPython / Shared entity: Agno / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Agno uses IPython); both cover Agno; reported by the same outlet (github.com).
Agno supports MCP / Shared entity: Agno / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Agno supports MCP); both cover Agno; reported by the same outlet (github.com).
Agno uses IPython / Shared entity: Agno / Same source domain / Earlier coverage
Linked by a graph relationship (Agno uses IPython); both cover Agno; reported by the same outlet (github.com).
Agno supports AtomicMail / Shared entity: Agno / Same source domain / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (Agno supports AtomicMail); both cover Agno; reported by the same outlet (github.com).
Agno supports MCP / Shared entity: Released August / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Agno supports MCP); both cover Released August; reported by the same outlet (github.com).
Agno supports AtomicMail / Shared entity: Agno / Same source domain / Shared topic / Earlier coverage
Linked by a graph relationship (Agno supports AtomicMail); both cover Agno; reported by the same outlet (github.com).