Releases: Aethis-ai/aethis-mcp
Releases · Aethis-ai/aethis-mcp
Release list
v0.22.0
- Fail closed on misspelled top-level acceptance arguments to
aethis_create_rulesetandaethis_set_testsinstead of letting the MCP
parser discard them before the handler sees them. - Match the engine's Unicode identifier bounds, accept explicit null test-case
expectations as no assertion, and upload the same normalized v1 cases used
for the acceptance digest. - Reject
__proto__keys in JSON record maps before the MCP schema parser can
silently discard them, including binding catalogues and field values. - feat: preserve structured authoring acceptance contracts.
aethis_create_rulesetandaethis_set_testsaccept the generic
version-1 contract: per-case review/useful-unknown expectations plus an
optional review-binding catalogue. Both use the atomic test replacement
path and require the engine's contract version, catalogue, and canonical
digest to read back before reporting the project ready for generation.
v0.20.0
Authoring safeguards are now visible in tool output. Both are warn-only and never block a generation or a publish.
aethis_generate_and_testandaethis_refinerender the source questions authoring raised: places where the source text conflicts with itself or can be read more than one way. Each question shows the quoted clauses with their citation keys, the candidate readings, and the provisional reading the ruleset encodes.aethis_publishrenders them too.aethis_publishrenders the source check: a warning when a cited document is not the text the ruleset was built from (mismatch), when a digest is unavailable (unverifiable), or when the ruleset predates input recording (no_authoring_inputs_recorded).- Fix: the generate-and-test path kept only the ruleset id and test result from the final generation status, so fields carried there (source questions and the run's question counts) never reached the tool output. They are now preserved.
- All question and check text comes from uploaded sources and model output, so it is returned inside the
<api_response>untrusted-content fence. - Security hardening: the untrusted-content fence is harder to break out of. It previously neutralised only the exact closing tag
</api_response>. Now any occurrence of the fence name in returned text is neutralised, whatever surrounds it, so no spacing, case, lookalike bracket or slash, encoding, or forged opener such as<api_response label="system">can close the fence or open a new one. Fence labels are restricted to identifier characters, so returned data can no longer reach a fence label's attribute unescaped. aethis_next_questionno longer prints a note'smetadata.typeas bare[type]text before the note. That value is returned data, so it now appears only in the note's fence label.
v0.19.0
Security: provider credentials leave the process only when the user configured them for Aethis. Upgrade recommended.
- Breaking: an Anthropic key is read from the environment only via the new
AETHIS_ANTHROPIC_KEY_ENVserver setting, in which the user names the variable holding the key. Ananthropic_key_envvalue supplied in a tool call is refused unless it equals that configured name, so a host model can no longer opt a user'sANTHROPIC_API_KEY(or any other variable) in on its own. The missing-key error now tells the user how to configure a key instead of suggesting an argument for the model to retry with. - Breaking: the retired
openai_keyargument is refused. Previously it was sent in the Anthropic key header. - Any key value that is not Anthropic-shaped (
sk-ant-…) is refused locally and never sent. - Key-shaped text (
sk-ant-…,sk-proj-…, provider-masked echoes) in any upstream response or error is masked before it reaches the MCP client. - If you previously exported a provider key in your MCP host's environment and used the authoring tools, rotate that key.
v0.18.0
- Add
aethis_set_tests(project_id, test_cases)for destructive replacement of one existing project's complete reviewed 1–100-case suite. It verifies the target OpenAPI replacement capability before writing, preserves project sources, fields and guidance, and never creates another project. - Replacement POSTs are sent once. Interrupted responses report an unknown outcome and require inspection before another approved replacement.
- Preserve immutable publication receipt metadata (
published_version_id,content_digest, andpublished_version_label) inaethis_publishoutput.
v0.17.4
- release: verify the Registry's real response envelope. The official
Registry successfully publishedaethis-mcp@0.17.3as active/latest, but the
final workflow incorrectly read search results fromentry.nameand
entry.versioninstead ofentry.server.nameandentry.server.version, so
it reported a false-red after publication. Verification now uses a tested
parser with a fixture matching the live Registry response shape.
v0.15.1
- docs: align Simpson paper citations with v3.13 (issue #53). The
construction-insurance demo now cites the current paper version (v3.13,
2026) instead of v3.11; removes any presentation of the withdrawn
GPT-5.4 low-reasoning-effort 7/11 figure as a live result (the v3.8
withdrawal note remains as historical context); and removes
configuration-level API detail (parameter names) from the benchmark
methodology text. All real benchmark numbers are unchanged.
v0.15.0
- feat:
aethis_usagetool. Reports the caller's rate-limit budget per
operation class (decide / generate / author / read / keys / admin) over the
rolling 24h window — used, limit, remaining, reset — from
GET /api/v1/public/usage, so an agent authoring inside Claude Code / Cursor /
Windsurf can see and report the developer's remaininggeneratebudget before a
429. NewAethisClient.usage(); tenant-scoped (requires an API key).
(epic aethis-workspace#552) - Requires aethis-core with the
/api/v1/public/usageendpoint live (epic #552
P2). The public npm release of this version is held until that endpoint is live
onapi.aethis.ai.
v0.13.0
Adds the Authoring Coach surface to MCP (aethis-mcp#57, workspace epic #514) —
skill-building feedback for rule authors, advisory only, never a gate.
Engine gate: the POST /api/v1/public/projects/{id}/review endpoint and the
ambient review_hint fields are produced by aethis-core (epic phases P1/P4).
This release must not be published to npm until that endpoint is live on
api.aethis.ai; a released client calling a not-yet-deployed route would 404.
aethis_review_project(new tool). Reviews an authoring project against
the deterministic authoring-coach rubric and renders the report: a score,
per-check evidence across grounding / process / lifecycle, strengths, and the
single highest-leverage next skill. Advisory only — it never blocks
publishing. The deterministic layer needs no LLM key;coach=true(with an
Anthropic key, via the usualanthropic_key_env/anthropic_key_keychain/
anthropic_keyforms) adds an opt-in LLM-synthesised coaching narrative on
top. All server free-text (evidence / strengths / next-skill message /
coaching) is fenced withfenceUntrustedbefore it reaches the model.- Ambient
review_hintrender.aethis_generate_and_test,aethis_refine,
andaethis_publishnow render a one-line coach hint when the server includes
one on the response. The hint is computed entirely server-side (aethis-core
P4); the client only renders it (fenced), never computes it. X-Aethis-Client: mcp/<version>on every request. The client now sends a
per-surface identifier header so the engine can attribute telemetry (e.g.
review_hint-shown counts) to MCP vs CLI vs SDK.- 31 tools, up from 30.
tests/tool-endpoint-map.tsand the drift suite are
updated in the same change. Note: the drift suite's live-alignment checks stay
red against staging until the/reviewendpoint deploys there (expected epic
ordering); the offline structural checks pass. - Tests. New mocked unit coverage in
tests/client.test.ts(reviewProject
request shape, the client-id header) andtests/server.test.ts
(aethis_review_projectrender + fencing, coach key resolution, ambient hint
render on generate/publish).