v0.3.0 — opt-in local stdio introspection, multi-server config materialization, and read-only config secret audit.
--allow-start: opt-in, timeout-bounded, byte-bounded, stdlib-only local stdio introspection for command-discovered MCP servers — lists tools via MCPtools/listwithout becoming a proxy, gateway, service, browser UI, org scanner, or hosted dashboard.config-apply --allow-start --materialize-tools-list: materialize a previouslynot_patchablecommand-discovered server to a localtoolsListPathsidecar, then enforce it on later static scans.config-audit/config-audit-demo: read-only MCP config secret hygiene — reports carry path/class/length/fingerprint metadata only and never print literal secret values.config-multiserver-demo: explicit multi-server{servers:[...]}external-catalog patching with fail-closed malformed-shape reporting.- Local-first preserved: the core package stays dependency-free.