·
6 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
🐕 AgentHound Changelog
1.1.1 — Evidence Precision and Reliability
Added
- Instruction findings now preserve bounded matched excerpts, source positions, scope, and file metadata from the scan artifact through the dashboard and copied report.
- A medium-severity
INSTRUCTION_SIGNALfinding separates reviewable standalone or deep-scope signals from high-confidence poisoning in active instruction scope.
Fixed
- Instruction-file classification now requires deterministic override, identity, hidden-content, decoded-payload, or sensitive-outbound semantics instead of promoting ordinary instruction language and documentation examples.
- Concrete credentials discovered in multiple agent configurations now share one
value_hash-based identity with deterministic provenance and authentication hints. - Positional scan targets now reject malformed hostname syntax before any resolver or network work begins.
- The installer now validates before promotion and atomically restores the previous binary when installed-path startup validation fails.
- Legitimate documentation URLs no longer look like Base64 prompt-injection payloads or, by themselves, outbound-network capabilities.
- Active planning avoids redundant credential presentation when the exact MCP resource or A2A card/probe surface has already succeeded anonymously.
- Repeated service collection now keeps protected Open WebUI posture stable across credential attempts and gives each distinct LiteLLM master key a contextual
value_hashidentity.