This release adds 2 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+14 more
Summary
AI summaryScans now report incomplete compliance with explicit unverified control items and correctly scan markdown files.
Full changelog
回应反馈「上传就出结果、太假了」——这版让结果更真、更诚实。
修正
- 不再报"优秀/A"式合规结论:静态扫描以「项目实测风险」为主指标,明确标注「N 项合规控制项未验证、非完整合规结论」。
- 真正扫
.md/.mdx/.ipynb:此前完全跳过 markdown(prompt/skill 项目等于没扫正文)。现纳入扫描。 - markdown 文档只检境外端点、跳过密钥/PII:避免 README「检测示例」里的演示值误报。
- Web URL 扫描健壮性:克隆超时 60s、并发 4、大仓库友好提示(引导本地客户端)、表单防重复点击。
全套 282 测试通过。
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About jnMetaCode/shellward
AI Agent Security Middleware & MCP Server with 8-layer defense including prompt injection detection, DLP data flow tracking, command blocking, and PII detection. 7 MCP tools, zero dependencies.
Related context
Related tools
Beta — feedback welcome: [email protected]