This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+14 more
ReleasePort's take
Moderate signalRelease v0.6.0 lowers the default injectionThreshold from 60 to 40 after benchmark calibration and fixes two catastrophic ReDoS vulnerabilities causing self‑DoS.
Why it matters: The change reduces false positives by setting injectionThreshold to 40; critical because it also patches two severe ReDoS flaws that can cause service denial.
Summary
AI summaryDefault injectionThreshold lowered from 60 to 40 based on benchmark calibration.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes two catastrophic ReDoS vulnerabilities causing self‑DoS Fixes two catastrophic ReDoS vulnerabilities causing self‑DoS Source: llm_adapter@2026-06-05 Confidence: high |
— |
| Feature | Medium |
Adds MCP tool-poisoning scanner with rug‑pull detection via /scan-mcp (stdio and remote HTTP) Adds MCP tool-poisoning scanner with rug‑pull detection via /scan-mcp (stdio and remote HTTP) Source: llm_adapter@2026-06-05 Confidence: high |
— |
| Feature | Medium |
Adds support for custom rules (`customRules`) to extend detection without forking Adds support for custom rules (`customRules`) to extend detection without forking Source: llm_adapter@2026-06-05 Confidence: high |
— |
| Feature | Low |
Adds detection benchmark command `npm run bench` with 100% precision/recall on labeled corpus Adds detection benchmark command `npm run bench` with 100% precision/recall on labeled corpus Source: llm_adapter@2026-06-05 Confidence: high |
— |
| Bugfix | Medium |
Reduces default injectionThreshold from 60 to 40 based on benchmark calibration (revertible via config) Reduces default injectionThreshold from 60 to 40 based on benchmark calibration (revertible via config) Source: llm_adapter@2026-06-05 Confidence: high |
— |
| Bugfix | Low |
Fixes PII false‑positive issues for carrier‑validated mobile numbers and UnionPay‑only bank cards Fixes PII false‑positive issues for carrier‑validated mobile numbers and UnionPay‑only bank cards Source: llm_adapter@2026-06-05 Confidence: high |
— |
Full changelog
Highlights
- MCP tool-poisoning scanner + rug-pull detection +
/scan-mcp(stdio + remote HTTP) - Custom rules (
customRules) for extending detection without forking - Detection benchmark (
npm run bench) — 100% precision/recall on labeled corpus, CI-gated - ReDoS audit — fixed 2 catastrophic-backtracking self-DoS vulns
- Default
injectionThreshold60→40 (benchmark-calibrated; revertible via config) - PII false-positive fixes (carrier-validated mobile, UnionPay-only bank card)
See CHANGELOG. Published to npm: [email protected].
Note: npm provenance via CI activates once the repo NPM_TOKEN secret is set; 0.6.0 was published from the maintainer's authenticated local environment.
Security Fixes
- Fixed two catastrophic backtracking ReDoS vulnerabilities causing self‑DoS
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About jnMetaCode/shellward
AI Agent Security Middleware & MCP Server with 8-layer defense including prompt injection detection, DLP data flow tracking, command blocking, and PII detection. 7 MCP tools, zero dependencies.
Related context
Related tools
Beta — feedback welcome: [email protected]