Skip to content

This release adds 2 notable features for engineering teams evaluating rollout.

Published 2mo MCP Developer Tools
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Affected surfaces

auth rbac

Summary

AI summary

Write permission probing distinguishes read‑only from read+write tokens in probe_token_capabilities.

Full changelog

What's New

Write permission probing in probe_token_capabilities — distinguishes read-only tokens from read+write tokens.

Added

  • Probes roll and detach endpoints using real cluster IDs with fake instance IDs (safe dry-run)
  • Detects Spot.io's non-standard permission denials (400 "An unknown error occurred" instead of 403)
  • Response now includes read_access, write_access, write_denied fields
  • Recommendation summary: "full read + write", "read-only", or "partial write"
  • 4 new probe tests (82 total)

Changed

  • CI workflows bumped to actions/checkout@v6 and actions/setup-python@v6 (Node.js 24)

Full Changelog: https://github.com/arnstarn/mcp-server-spotinst/compare/v0.4.1...v0.5.0

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track arnstarn/mcp-server-spotinst

Get notified when new releases ship.

Sign up free

About arnstarn/mcp-server-spotinst

MCP server for Spot.io (Spotinst) API with 23 tools for managing Ocean clusters, VNGs, Elastigroups, costs, right-sizing, and logs across AWS and Azure with multi-account support.

All releases →

Beta — feedback welcome: [email protected]