This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+13 more
Affected surfaces
Summary
AI summary2-stage security scan now merges static rules with user LLM judgment and Antigravity engine resolution works in any project.
Full changelog
What's new
- 2-stage security scan (BYOK LLM judgment) —
hephaestus security scannow merges static-rule findings with the user's own LLM judgment (.agentlas/security-llm-judgment.json). Combined verdict = max severity of both stages.--strictblocks BLOCK (exit 1) and now also gates WARN (exit 2) unless--acknowledge-warn. - Antigravity
/hephaestusengine resolution — the workflow now resolves the engine root from the Claude/Codex plugin cache when the workspace has no local package, so/hephaestusworks in any project (previously it only looked at workspace-local files and kept saying "install first"). Also installs into both~/.gemini/antigravity/and~/.gemini/antigravity-ide/data dirs. - Version sync —
marketplace.jsonwas stale at 0.2.9; all manifests unified to 0.2.11.
Updating
Plugin updates are pull-based (no auto-update):
```
claude plugin marketplace update agentlas-core-engine
claude plugin install hephaestus@agentlas-core-engine --force
```
or re-run the one-touch installer.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Hephaestus
Open Agent OS for Claude Code, Codex, and Cursor with a meta-agent builder, A2A Hub routing, local ontology, and memory/security gates. Apache-2.0.
Related context
Related tools
Beta — feedback welcome: [email protected]