Skip to content

ooples/token-optimizer-mcp

v5.1.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 7d MCP Developer Tools
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai cache claude compression gemini-cli-extension llm
+3 more
mcp mcp-server token-optimization

Affected surfaces

rce_ssrf

Summary

AI summary

Updates Bug Fixes, 5.1.0, and CI/CD across a mixed release.

Changes in this release

Security Critical

eliminate os command injection across smart_* tools

eliminate os command injection across smart_* tools

Source: llm_adapter@2026-07-20

Confidence: medium

Feature Medium

auto-record token savings and add get_optimization_report

auto-record token savings and add get_optimization_report

Source: llm_adapter@2026-07-20

Confidence: medium

Feature Medium

implement background optimization with immediate session persistence

implement background optimization with immediate session persistence

Source: llm_adapter@2026-07-20

Confidence: medium

Feature Medium

implement LRU cache and sophisticated token counting

implement LRU cache and sophisticated token counting

Source: llm_adapter@2026-07-20

Confidence: medium

Feature Medium

add claude code plugin and Gemini/Codex/OpenCode/Copilot integrations

add claude code plugin and Gemini/Codex/OpenCode/Copilot integrations

Source: llm_adapter@2026-07-20

Confidence: medium

Bugfix Medium

repair broken PowerShell hooks and 5 MCP tool bugs (15 user-reported issues)

repair broken PowerShell hooks and 5 MCP tool bugs (15 user-reported issues)

Source: llm_adapter@2026-07-20

Confidence: medium

Bugfix Low

add missing items schema to array tool parameters

add missing items schema to array tool parameters

Source: llm_adapter@2026-07-20

Confidence: medium

Bugfix Low

tolerate a directory passed as the cache engine db path

tolerate a directory passed as the cache engine db path

Source: llm_adapter@2026-07-20

Confidence: medium

Bugfix Low

guard zod-v4 error issues and require non‑empty path in smart_read

guard zod-v4 error issues and require non‑empty path in smart_read

Source: llm_adapter@2026-07-20

Confidence: medium

Bugfix Low

exit stdio server on stdin close to prevent Windows orphan‑leak

exit stdio server on stdin close to prevent Windows orphan‑leak

Source: llm_adapter@2026-07-20

Confidence: medium

Full changelog

5.1.0 (2026-07-20)

Features

  • analytics: auto-record token savings + add get_optimization_report (#181) (2b26227)
  • implement background optimization with immediate session persistence (770cf31)
  • implement LRU cache and sophisticated token counting (issues #4 and #5) (#127) (3f069f7)
  • optimization platform — config, tokenizers, LRU cache, sessions, context-delta (#163) (b316152)
  • packaging: claude code plugin + gemini/codex/opencode/copilot integrations (#180) (a694fc1)

Bug Fixes

  • add missing items schema to array tool parameters (#153) (#154) (06b941f)
  • add semantic-release git plugin and sync package.json to v5.0.1 (#119) (31efcf3)
  • cache: tolerate a directory passed as the cache engine db path (#171) (d933821)
  • ci,security: repair release pipeline (Node 22) and stop tracking .mcp.json (#179) (73550bc)
  • hooks,tools: close gap-analysis findings on top of #175 (#176) (99252ae)
  • move background optimization and session fixes to PR (wrongly committed to master) (#128) (1ac3e7b)
  • release: recognize existing vX.Y.Z tags in release-please (#183) (4637590)
  • remove conflicting Start-Process parameters causing silent failures (6e43e7c)
  • repair broken PowerShell hooks and 5 MCP tool bugs (15 user-reported issues) (#175) (ced86aa)
  • resolve powershell parse errors and session file corruption (ceaf8e1)
  • security: eliminate os command injection across smart_* tools (#169) (b4ee96d)
  • server: exit stdio server on stdin close to prevent Windows orphan-leak (#177) (0408bee)
  • smart_read: guard zod-v4 error issues and require non-empty path (#167) (4ae7c35)

CI/CD

  • release: harden release pipeline + version-info notifications (#170) (9e5a06c)
  • release: migrate to release-please with oidc npm publishing (#182) (22462c7)

Security Fixes

  • Eliminate os command injection across smart_* tools

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track ooples/token-optimizer-mcp

Get notified when new releases ship.

Sign up free

About ooples/token-optimizer-mcp

Intelligent token optimization achieving 95%+ reduction through caching, compression, and 80+ smart tools for API optimization, code analysis, and real-time monitoring.

All releases →

Beta — feedback welcome: [email protected]