This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+14 more
Summary
AI summaryRenamed "信我能检" to "看数字" and added benchmark script with perfect baseline metrics.
Full changelog
把「信我能检」变成「看数字」。
新增
npm run bench:scan:用 31 个标注样例(17 真实风险 + 14 硬负例:境内端点 / 占位符 / 文档示例 / lock 文件 / 无效校验位)跑真实 scanProject 管线,算精确率 / 召回率 / F1- 基线:精确率 100% · 召回率 100% · F1 100%,CI 门禁(低于 90% 构建失败)
- 自建语料,诚实标注——建基准的过程本身就验证并暴露了检测边界(如占位符过滤器对含 abcdef/123456 的密钥的取舍)
一个安全工具该用数字证明自己检得准,而不是"你信我"。
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About jnMetaCode/shellward
AI Agent Security Middleware & MCP Server with 8-layer defense including prompt injection detection, DLP data flow tracking, command blocking, and PII detection. 7 MCP tools, zero dependencies.
Related context
Related tools
Beta — feedback welcome: [email protected]