This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+5 more
Summary
AI summaryBenchmark truth corrected to report 20% job completion accuracy and added governed‑voice overlay for brand transfer measurement.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Sanitized extracted color names at all agent‑facing compile sinks to prevent taint propagation. Sanitized extracted color names at all agent‑facing compile sinks to prevent taint propagation. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Low |
Added governed-voice overlay to benchmark fixtures for brand transfer measurement. Added governed-voice overlay to benchmark fixtures for brand transfer measurement. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Low |
Committed machine‑readable receipts for every published LLM run in eval/receipts/ directory. Committed machine‑readable receipts for every published LLM run in eval/receipts/ directory. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Corrected benchmark result from 100% to 20% accurate completion rate. Corrected benchmark result from 100% to 20% accurate completion rate. Source: llm_adapter@2026-07-18 Confidence: high |
— |
Full changelog
Repair release from adversarial review — the eval suite's instrument audited itself.
Benchmark truth
- Job completion redefined honestly: output contract + brand_check + compliance + non-vacuous rules. Corrected second-agent result: 20% (1/5), down from the previously published 5/5 (which counted empty-checker acceptance as completion). Correction published in eval/RESULTS.md with the original claim annotated, not erased.
- Benchmark fixture gains a governed-voice overlay (never-say, anchors, tone) so text tasks measure brand transfer, not checker emptiness.
Taint closure
- Hostile extracted color names sanitized at every agent-facing compile sink (runtime unknown-role keys, design-synthesis signals, brand_write briefs); raw names stay quarantined in evidence. Adversarial test proves the runtime-key path.
Auditability
- Committed machine-readable receipts (eval/receipts/) for every published LLM run: commit, package, model, per-task contract status, rule coverage, verdicts, tokens.
Full changelog: https://github.com/Brandcode-Studio/brandsystem-mcp/blob/main/CHANGELOG.md
Security Fixes
- Sanitized extracted color names at all agent‑facing compile sinks; hostile runtime keys now quarantined in evidence.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Brand-System/brandsystem-mcp
Make your brand machine-readable. Extract brand identity (colors, fonts, logo, voice, visual rules) from any website via static CSS + rendered-page extraction, compile into DTCG tokens, brand runtime contracts, and interaction policies. 34 tools across 4 progressive sessions. Subscribable `brand://runtime` and `brand://policy` MCP resources. Content compliance scoring (0-100), pass/fail gate, and HTML/CSS preflight. Brandcode Studio connector for hosted brand sync.
Beta — feedback welcome: [email protected]