Skip to content

v0.3.0 — Security doctrine, esbuild bundling, installer fixes

Latest

Choose a tag to compare

@thefactremains thefactremains released this 08 Apr 21:37
· 4 commits to main since this release

What's new

Security Doctrine

  • Credentials never leak to Claude servers. The SKILL.md now includes explicit rules: credentials stay in .env files, never passed as tool arguments, never logged, never sent to remote APIs through Claude. The generated .env.example documents what's needed without exposing real values.

Node.js esbuild bundling

  • All Node.js templates now include esbuild for production bundling. npm run build creates a single dist/mcp-server.js file. npm run dev runs from source for development.

New project type: data-connector

  • Connect to databases or data warehouses and expose query capabilities as MCP tools.

Installer improvements

  • Fixed stdin handling when piped from curl | bash (re-exec with /dev/tty)
  • Correct Claude Desktop config paths for all platforms (macOS, Linux, Windows)
  • Correct Claude Code config paths (~/.claude/settings.json and ~/.claude.json)
  • Reverted aggressive reinstall behavior — existing installs update cleanly

Skill improvements

  • Common pitfalls guide with credential safety rules
  • Better Claude Desktop / Claude Code configuration instructions
  • uv availability check before running CLI

Install

Claude Code plugin:

Install this plugin: https://github.com/Percona-Lab/CAIRN

CLI:

curl -fsSL -o /tmp/cairn.whl https://github.com/Percona-Lab/CAIRN/releases/latest/download/cairn_mcp-0.3.0-py3-none-any.whl
uvx --from /tmp/cairn.whl cairn init