Skip to content

KryptosAI/mcp-observatory

v1.30.0 Feature

This release adds 3 notable features for engineering teams evaluating rollout.

Published 17d MCP Developer Tools
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

agent-security ai-agent ai-security ai-supply-chain cli code-scanning
+14 more
developer-tools github-action github-code-scanning mcp mcp-ci mcp-security mcp-server mcp-testing model-context-protocol regression-testing sarif schema-drift security supply-chain-security

Summary

AI summary

Adds skill scanning for malicious behaviors and Unicode obfuscation detection.

Full changelog

What's New

  • 🕵️ Skill scanning: detect credential theft, exfiltration, remote execution, prompt injection in agent skill files
  • 🌐 13+ agent auto-discovery: Cursor, Windsurf, VS Code, OpenCode, Codex, Gemini CLI, and more
  • 🔤 Unicode obfuscation detection: zero-width characters, bidi overrides, Unicode tag sequences
  • 🧬 YARA-inspired compound rules: credential-exfiltration, supply-chain-hijack, hidden-execution, social-engineering
  • 📊 572 tests, 59 test files

New Contributors

  • @albatrossflyon-coder made their first contribution in https://github.com/KryptosAI/mcp-observatory/pull/201

Full Changelog: https://github.com/KryptosAI/mcp-observatory/compare/v1.29.2...v1.30.0

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track KryptosAI/mcp-observatory

Get notified when new releases ship.

Sign up free

About KryptosAI/mcp-observatory

Regression testing for MCP servers. Auto-discovers servers from Claude configs, checks capabilities, invokes tools, detects schema drift between versions, and recommends new servers based on your environment. Works as both a CLI and an MCP server.

All releases →

Beta — feedback welcome: [email protected]