This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+14 more
Summary
AI summaryUpdates Compat / honesty, What got safer, and Route notes across a mixed release.
Full changelog
Kinocut 1.11.1
Thin kinocut_sound S12 public join and post-theme harden. Published surface: 161 MCP tools / 140 CLI commands.
What agents can do now
- Discover and invoke a bounded local-first sound set via MCP, CLI, and Python client:
sound_capabilities,sound_plan_validate,sound_voice_batch,sound_mix_render,sound_qa_loudness,sound_qa_asr(CLI:sound-*/kino sound <action>).
What got safer
- Stream-shorts package fails closed when draft bytes diverge from render content hash (1.10.1 class integrity on this line).
- Sound public results stay privacy-bounded (no absolute host paths in invoke results).
Compat / honesty
pip install -U kinocut→ 1.11.1.mcp-video==1.6.2shim pins matching Kinocut.- Not claimed: full-episode sound completion, protected-timeline kernel, native MCPB public ship.
- G004 remains open: human listening / phone-frame review still required for production stream-shorts claims.
Route notes
- CHANGELOG documents 1.10.1 (integrity + ledger), 1.11.0 (sound join), and 1.11.1 (harden) as the multi-release ladder; this tag ships the tip as 1.11.1.
Security Fixes
- Stream‑shorts package fails closed when draft bytes diverge from render content hash (integrity enforcement).
- Sound public results are privacy‑bounded – invoke responses no longer contain absolute host paths.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About pastorsimon1798/mcp-video
Video editing MCP server with 26 tools for trimming, merging, text overlays, audio sync, filters, color grading, audio normalization, picture-in-picture, split-screen, batch processing, format conversion, subtitles, watermarks, and more. 380 tests, CI on Python 3.11+3.12, progress callbacks, works with Claude Code, Cursor, and any MCP client.
Related context
Related tools
Earlier breaking changes
- v1.7.0 Moves implementation package from `mcp_video` to `kinocut`; new Python integrations must import from `kinocut`.
Beta — feedback welcome: [email protected]