This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+3 more
Affected surfaces
Summary
AI summaryUpdates Bug Fixes, 5.1.0, and CI/CD across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
eliminate os command injection across smart_* tools eliminate os command injection across smart_* tools Source: llm_adapter@2026-07-20 Confidence: medium |
— |
| Feature | Medium |
auto-record token savings and add get_optimization_report auto-record token savings and add get_optimization_report Source: llm_adapter@2026-07-20 Confidence: medium |
— |
| Feature | Medium |
implement background optimization with immediate session persistence implement background optimization with immediate session persistence Source: llm_adapter@2026-07-20 Confidence: medium |
— |
| Feature | Medium |
implement LRU cache and sophisticated token counting implement LRU cache and sophisticated token counting Source: llm_adapter@2026-07-20 Confidence: medium |
— |
| Feature | Medium |
add claude code plugin and Gemini/Codex/OpenCode/Copilot integrations add claude code plugin and Gemini/Codex/OpenCode/Copilot integrations Source: llm_adapter@2026-07-20 Confidence: medium |
— |
| Bugfix | Medium |
repair broken PowerShell hooks and 5 MCP tool bugs (15 user-reported issues) repair broken PowerShell hooks and 5 MCP tool bugs (15 user-reported issues) Source: llm_adapter@2026-07-20 Confidence: medium |
— |
| Bugfix | Low |
add missing items schema to array tool parameters add missing items schema to array tool parameters Source: llm_adapter@2026-07-20 Confidence: medium |
— |
| Bugfix | Low |
tolerate a directory passed as the cache engine db path tolerate a directory passed as the cache engine db path Source: llm_adapter@2026-07-20 Confidence: medium |
— |
| Bugfix | Low |
guard zod-v4 error issues and require non‑empty path in smart_read guard zod-v4 error issues and require non‑empty path in smart_read Source: llm_adapter@2026-07-20 Confidence: medium |
— |
| Bugfix | Low |
exit stdio server on stdin close to prevent Windows orphan‑leak exit stdio server on stdin close to prevent Windows orphan‑leak Source: llm_adapter@2026-07-20 Confidence: medium |
— |
Full changelog
5.1.0 (2026-07-20)
Features
- analytics: auto-record token savings + add get_optimization_report (#181) (2b26227)
- implement background optimization with immediate session persistence (770cf31)
- implement LRU cache and sophisticated token counting (issues #4 and #5) (#127) (3f069f7)
- optimization platform — config, tokenizers, LRU cache, sessions, context-delta (#163) (b316152)
- packaging: claude code plugin + gemini/codex/opencode/copilot integrations (#180) (a694fc1)
Bug Fixes
- add missing items schema to array tool parameters (#153) (#154) (06b941f)
- add semantic-release git plugin and sync package.json to v5.0.1 (#119) (31efcf3)
- cache: tolerate a directory passed as the cache engine db path (#171) (d933821)
- ci,security: repair release pipeline (Node 22) and stop tracking .mcp.json (#179) (73550bc)
- hooks,tools: close gap-analysis findings on top of #175 (#176) (99252ae)
- move background optimization and session fixes to PR (wrongly committed to master) (#128) (1ac3e7b)
- release: recognize existing vX.Y.Z tags in release-please (#183) (4637590)
- remove conflicting Start-Process parameters causing silent failures (6e43e7c)
- repair broken PowerShell hooks and 5 MCP tool bugs (15 user-reported issues) (#175) (ced86aa)
- resolve powershell parse errors and session file corruption (ceaf8e1)
- security: eliminate os command injection across smart_* tools (#169) (b4ee96d)
- server: exit stdio server on stdin close to prevent Windows orphan-leak (#177) (0408bee)
- smart_read: guard zod-v4 error issues and require non-empty path (#167) (4ae7c35)
CI/CD
Security Fixes
- Eliminate os command injection across smart_* tools
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About ooples/token-optimizer-mcp
Intelligent token optimization achieving 95%+ reduction through caching, compression, and 80+ smart tools for API optimization, code analysis, and real-time monitoring.
Related context
Beta — feedback welcome: [email protected]