This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
Summary
AI summaryAdds shellward web for public URL scanning and a local GUI mode that scans private code without uploading.
Full changelog
让「贴链接就能测」和「客户端体验」都成立——而且守住数据不出境的根基。
新增
shellward web(公网):网页贴公开仓库 URL,或用/scan?repo=URL分享链接 → 在线体检。公开仓库代码本就公开,不涉数据出境。附Dockerfile一键部署。shellward web --local(客户端):浏览器 GUI 填本地路径扫描,私有代码不上传、不出本机,无需命令行——零 Electron 的客户端体验。- 安全:域名白名单、严格 URL 正则(拒凭据/注入)、浅克隆 + 30s 超时、临时目录用完即删、并发上限、公网模式禁止扫本地路径、绝不执行仓库代码。
私有/敏感代码请始终用本地:npx shellward scan(不上传)。
全套 273 测试通过。
Security Fixes
- Enforces domain whitelist, strict URL regex, shallow clone, 30‑second timeout, temporary directory cleanup, concurrency limits, and prohibits local path scans in public mode to prevent credential injection or execution of repository code
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About jnMetaCode/shellward
AI Agent Security Middleware & MCP Server with 8-layer defense including prompt injection detection, DLP data flow tracking, command blocking, and PII detection. 7 MCP tools, zero dependencies.
Related context
Related tools
Beta — feedback welcome: [email protected]