This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+14 more
Summary
AI summaryAdds skill scanning for malicious behaviors and Unicode obfuscation detection.
Full changelog
What's New
- 🕵️ Skill scanning: detect credential theft, exfiltration, remote execution, prompt injection in agent skill files
- 🌐 13+ agent auto-discovery: Cursor, Windsurf, VS Code, OpenCode, Codex, Gemini CLI, and more
- 🔤 Unicode obfuscation detection: zero-width characters, bidi overrides, Unicode tag sequences
- 🧬 YARA-inspired compound rules: credential-exfiltration, supply-chain-hijack, hidden-execution, social-engineering
- 📊 572 tests, 59 test files
New Contributors
- @albatrossflyon-coder made their first contribution in https://github.com/KryptosAI/mcp-observatory/pull/201
Full Changelog: https://github.com/KryptosAI/mcp-observatory/compare/v1.29.2...v1.30.0
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About KryptosAI/mcp-observatory
Regression testing for MCP servers. Auto-discovers servers from Claude configs, checks capabilities, invokes tools, detects schema drift between versions, and recommends new servers based on your environment. Works as both a CLI and an MCP server.
Related context
Beta — feedback welcome: [email protected]