v2.6.1 — Overlay Application and Enhanced Linting
This release introduces powerful new features, including OpenAPI Overlay document support and agent-readiness linting, making it easier for developers to manage and improve their OpenAPI specifications.
✨ Highlights
Apply OpenAPI Overlay documents at load time to seamlessly integrate curated changes without altering the original spec.
import { applyOverlay } from 'mcp-from-openapi';
applyOverlay(specDocument, overlayDocument);Agent-readiness linting provides a detailed analysis of spec quality to improve tool selection accuracy.
import { lintDocument } from 'mcp-from-openapi';
const lintResults = await lintDocument(apiDocument);🔒 Security
- Resolves CodeQL alerts on polynomial trims, backslash escaping, and merge sanitizer recognition.
🛠 Also in this release
- Added detection of pagination parameters and unbounded-array responses for better metadata hints.
- Introduced trimming options including
maxProperties,maxDescriptionLength, andstripExamples. - Added token estimation and budget reports for tool-set usage.
- Enhanced description strategies with compact response summaries.
⚠️ Upgrading
| Change | Impact |
|---|---|
| Eager overlay application | Requires overlays specified in the options to be handled at load time. |
Full change list
Features
- feat: detect pagination params and unbounded-array responses as metadata hints
- feat: add description strategies and compact response summaries
- feat: add agent-readiness lint with severity-ranked findings and fix hints
- feat: apply OpenAPI Overlay documents at load time with a JSONPath subset supporting filters and recursive descent
- feat: add maxProperties, maxDescriptionLength, and stripExamples trimming options
- feat: add token estimation and tool-set budget reports with context warnings
Fixes
- fix: exclude open brace from path template regex to avoid polynomial backtracking
- fix: resolve CodeQL alerts on polynomial trims, digest backslash escaping, and merge sanitizer recognition
- fix: address review findings on prototype-safe overlays, cycle-safe trimming, shared-node lint measurement, and OverlayError identity
- fix: apply review findings on overlay match dedup and removal order, trim safety for mapper params, lint cycle safety, and eager overlays
Security
- Security improvements with CodeQL alert resolutions
Installation
npm install mcp-from-openapi@2.6.1- OpenAPI Overlay Support – Seamless integration of curated changes to existing specs.
Release line: 2.6.x · Branch: release/2.6.x · Type: stable