This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+14 more
ReleasePort's take
Moderate signalIn v0.6.1 public engine methods now coerce hostile or garbage input without crashing.
Why it matters: With severity 90, this change prevents crashes from malformed inputs across the public API, directly improving reliability for developers and SREs monitoring service stability.
Summary
AI summaryPublic engine methods now coerce hostile or garbage input without crashing.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Public engine methods now coerce hostile/garbage input instead of throwing. Public engine methods now coerce hostile/garbage input instead of throwing. Source: llm_adapter@2026-06-05 Confidence: high |
— |
Full changelog
Patch: every public engine method now coerces hostile/garbage input (null, non-string, objects) instead of throwing — a security check must never crash on the input it inspects. Found by an adversarial QA pass; locked in with regression tests.
npm: [email protected] · 186 tests + benchmark + ReDoS audit green.
Security Fixes
- Public engine methods coerce null, non-string, and object inputs to prevent crashes during security checks.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About jnMetaCode/shellward
AI Agent Security Middleware & MCP Server with 8-layer defense including prompt injection detection, DLP data flow tracking, command blocking, and PII detection. 7 MCP tools, zero dependencies.
Related context
Related tools
Beta — feedback welcome: [email protected]