v0.6.0
Security hardening drawn from a competitive analysis of the MCP security field. Five new defenses, all deterministic (no model in the decision path) and opt-in via config. No change to existing enforcement behavior.
New
- Tool integrity (
tool_integrity:). Fingerprints every upstream tool on first sight (trust on first use) and flags any later change to its description or schema (rug pull); scans descriptions for hidden instructions (tool poisoning). Alert or block. - Rate limiting (
rate_limit:). A per-user fixed-window ceiling on tool calls, shared across replicas via Redis. Denial-of-wallet and abuse control. - Inbound secret scanning (
scan_inbound:). Scans tool arguments for credential-shaped strings and blocks or masks them before they reach an upstream. - Policy linter (
aggrete-lint). Static checks oncoc.yamlfor fail-open and dead rules: a high-severity rule that only alerts, an expired embargo wall, a missing enforce field, or (with--config) a rule whose domains no tool maps to. Exits non-zero on errors, for CI. - SIEM audit forwarding (
audit_forward:). Ships each audit row to Splunk/Elastic/Datadog over HTTP, or to syslog, as it is written, best-effort and off the hot path. The local hash-chained log stays the system of record.
Notes
All five default off unless configured. See the updated README and ROADMAP (the matching roadmap items moved to Shipped).