This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+13 more
Summary
AI summaryListDir now defaults to flat output and adds symlink skipping plus a 10,000‑entry limit for security.
Full changelog
Quick Start
- Download the binary for your OS below
- Run
agent-tool install(oragent-tool install claude) - Restart your IDE
- Done — all tools work immediately, no permission popups
Or just ask your AI agent:
"Download agent-tool from https://github.com/knewstimek/agent-tool/releases/latest and run
agent-tool install"
Any capable AI coding agent (Claude Code, Codex, etc.) can handle the full download → install → restart flow automatically.
Tip: Add this to your CLAUDE.md or AGENTS.md so your agent prefers agent-tool over built-in tools:
Strict mode:
ALWAYS use agent-tool MCP tools (mcp__agent-tool__*) instead of built-in file tools. agent-tool preserves file encoding and respects .editorconfig indentation settings.
Soft mode:
Prefer agent-tool MCP tools (mcp__agent-tool__*) over built-in file tools when available.
What's New in v0.6.2
ListDir flat mode
- New
flatoption (default:true) — outputs one path per line, token-efficient for AI agents - Use
flat=falsefor traditional tree view with visual connectors (├── └──)
Security hardening
- Symlink skip in directory traversal (consistent with delete/rename/mkdir)
- Entry limit (10,000) to prevent memory exhaustion on huge directories
Security Fixes
- Symlink traversal is now skipped in ListDir operations
- Entry limit of 10,000 entries added to prevent memory exhaustion
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About knewstimek/agent-tool
Encoding-aware, indentation-smart file tools for AI coding agents. 20+ tools including read/edit with automatic encoding detection, smart indentation conversion, SSH, SFTP, process management, and system utilities. Preserves file encoding (UTF-8, EUC-KR, Shift_JIS, etc.) and respects .editorconfig settings.
Related context
Beta — feedback welcome: [email protected]