This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+6 more
Affected surfaces
ReleasePort's take
Light signalThe MCP CLI now includes a guidelines list subcommand for easier reference. The agent has integrated an untrusted‑content fence to harden output handling.
Why it matters: Security severity 90 triggers mandatory review of agent output processing; developers gain direct access to guidelines via the new CLI command.
Summary
AI summaryUpdates 5.5.0, Bug Fixes, and 2026-06-11 across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Wire untrusted-content fence into agent‑facing output for security hardening Wire untrusted-content fence into agent‑facing output for security hardening Source: llm_adapter@2026-06-11 Confidence: high |
— |
| Feature | Medium |
Adds guidelines list subcommand to MCP tool Adds guidelines list subcommand to MCP tool Source: llm_adapter@2026-06-11 Confidence: high |
— |
| Bugfix | Medium |
Retries Gist initialization after transient failure instead of latching done Retries Gist initialization after transient failure instead of latching done Source: llm_adapter@2026-06-11 Confidence: high |
— |
Security Fixes
- Untrusted-content fence integrated to prevent exposure of untrusted data in agent‑facing output
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About costajohnt/oss-autopilot
Open source contribution manager with PR tracking across repos, issue discovery, CI failure diagnosis, and maintainer response drafting. Available as CLI, MCP server, and Claude Code plugin.
Related context
Related tools
Beta — feedback welcome: [email protected]