Skip to content

v0.6.0

Choose a tag to compare

@cjohannsen81 cjohannsen81 released this 05 Sep 18:58
· 35 commits to main since this release

Security hardening drawn from a competitive analysis of the MCP security field. Five new defenses, all deterministic (no model in the decision path) and opt-in via config. No change to existing enforcement behavior.

New

  • Tool integrity (tool_integrity:). Fingerprints every upstream tool on first sight (trust on first use) and flags any later change to its description or schema (rug pull); scans descriptions for hidden instructions (tool poisoning). Alert or block.
  • Rate limiting (rate_limit:). A per-user fixed-window ceiling on tool calls, shared across replicas via Redis. Denial-of-wallet and abuse control.
  • Inbound secret scanning (scan_inbound:). Scans tool arguments for credential-shaped strings and blocks or masks them before they reach an upstream.
  • Policy linter (aggrete-lint). Static checks on coc.yaml for fail-open and dead rules: a high-severity rule that only alerts, an expired embargo wall, a missing enforce field, or (with --config) a rule whose domains no tool maps to. Exits non-zero on errors, for CI.
  • SIEM audit forwarding (audit_forward:). Ships each audit row to Splunk/Elastic/Datadog over HTTP, or to syslog, as it is written, best-effort and off the hot path. The local hash-chained log stays the system of record.

Notes

All five default off unless configured. See the updated README and ROADMAP (the matching roadmap items moved to Shipped).