This release includes 1 breaking change for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+13 more
Affected surfaces
Summary
AI summarypair_ledger_* now mandates per-address device verification and preview_send shows EIP‑1559 fee breakdown.
Full changelog
Highlights
- Pre-sign gate hardening —
prepare_custom_callgains a value-exfil selector classifier (#659);setApprovalForAllon uncurated destinations now selector-decoded instead of opaque (#658);pair_ledger_*mandates per-address device verification in tool instructions (#660). preview_sendenriched — surfaces pinned network fee + EIP-1559 baseFee/priorityFee breakdown so the agent can present total cost before pre-sign checks (#661).- NFT floor-sweep — new
get_nft_listingstool returns ranked floor candidates per collection (#657). - Glama build repair (round 2) —
.npmrc+pnpm.overridesmake Glama's auto-generated pnpm Dockerfile build succeed alongside npm (#663). Companion to v0.14.3's project Dockerfile fix. - Docs — codifies the per-protocol vs
prepare_custom_callcutoff rule in CLAUDE.md (#662).
Included PRs
- #657 feat(nft): add get_nft_listings for ranked floor-sweep candidates
- #658 feat(decode): selector-only partial decode for setApprovalForAll on uncurated destinations
- #659 feat(custom-call): selector classifier for value-exfil patterns
- #660 feat(pair_ledger): mandate per-address device verification in instructions
- #661 feat(preview): surface pinned network fee + EIP-1559 breakdown at preview_send
- #662 docs(CLAUDE.md): codify per-protocol vs. prepare_custom_call cutoff rule
- #663 fix(deps): make Glama's pnpm build succeed alongside npm
- #664 chore(release): 0.14.4
Breaking Changes
- `pair_ledger_*` functions now require per‑address device verification in instructions
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About szhygulin/recon-crypto-mcp
Self-custodial crypto portfolio for AI agents. Reads EVM wallet balances, ENS, token prices, and DeFi positions across Ethereum/Arbitrum/Polygon/Base (Aave V3, Compound V3, Morpho Blue, Uniswap V3 LP, Lido, EigenLayer), surfaces health-factor alerts and protocol risk scores, then prepares unsigned transactions (supply, borrow, repay, withdraw, stake, send, LiFi swap/bridge) signed on Ledger via WalletConnect — private keys never leave the hardware wallet.
Related context
Beta — feedback welcome: [email protected]