Skip to content

v5.15.3 - per-instance orchestrator token

Choose a tag to compare

@Jovancoding Jovancoding released this 27 Sep 21:56
· 6 commits to main since this release

Security

  • Public hardcoded orchestrator token replaced with per-instance secrets. The orchestrator's full-access blackboard identity used the constant 'system-orchestrator-token', also hardcoded in bin/mcp-server.ts, TaskDecomposer, and ControlMcpTools. Each SwarmOrchestrator now generates a random token; the old string no longer authenticates anywhere. Not remotely exploitable on its own, since MCP transports already require the bearer secret or local stdio.
  • MCP server-held identity. network-ai-server writes on behalf of admitted callers via the new createServerIdentityBlackboard(). Transport authentication is the trust boundary, and each agent_id is recorded as the entry's source agent.

Fixed

  • Over MCP, every normal agent_id was rejected with a namespace error; only impersonating orchestrator with the public token worked. Any agent_id now works as documented.

Migration

  • MCP clients: no change needed. Callers still sending agent_token: "system-orchestrator-token" keep working; the server ignores caller-supplied tokens.
  • Library code that passed the literal string to SharedBlackboard.write() must use its own registerAgent() token.

Changed

  • scripts/clawhub-publish.js reads git provenance with execFileSync (no shell strings).
  • Added .plugin-scanner.toml for the HOL plugin-scanner (excludes only test fixtures and docs). Score 95/100, no high or critical findings.

3,679 tests across 41 suites.


Full changelog: https://github.com/Jovancoding/Network-AI/blob/main/CHANGELOG.md