This release adds 2 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+14 more
Summary
AI summaryEmpty results now display the full check process and a built‑in risky example demo.
Full changelog
回应「都没有检查过程?秒出是不是假的」。
新增
- 空结果也展示「检查过程」:未发现风险时,逐项列出查了什么(境外端点+SDK依赖 38 特征 / 硬编码密钥 / 中文+国际 PII / .env 权限)+ ✓0命中 + 文件数/规则数/耗时——证明确实逐项扫了,不是没查。
- 内置「含风险示例」一键演示:首页点「▶ 看一个含风险的示例报告」或访问
/demo,扫一个故意埋了风险的样例,同样秒出,但满屏发现 + 行号(境外5/密钥6/PII4)——直观证明「快 ≠ 假」。
验证
- 独立 grep 确认 superpowers-zh 真实无风险 → 报 0 正确;往副本植入一个密钥 → 立刻命中
file:line。快是因为是正则匹配文本(同 ripgrep),毫秒级正常。
全套 300 测试通过。
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About jnMetaCode/shellward
AI Agent Security Middleware & MCP Server with 8-layer defense including prompt injection detection, DLP data flow tracking, command blocking, and PII detection. 7 MCP tools, zero dependencies.
Related context
Related tools
Beta — feedback welcome: [email protected]