Repository navigation
ShadowGit MCP Server v1.1.2
Enhanced security and session management for AI-powered code history access
What's New Since v1.0.0
🔐 Critical Security Enhancements
- Hardened against repository escape attacks by blocking --git-dir, --work-tree, and -C flags
- Removed potentially destructive commands (branch, tag, reflog)
- Switched to array-based command execution, eliminating command injection risks
- Enhanced repository validation with .shadowgit.git verification
🎯 Session Management
- AI can now start/end coding sessions to control auto-commits
- Added checkpoint command for creating AI-authored commits
- Integrated with ShadowGit Session API for smarter history tracking
⚡ Improved Developer Experience
- Better error reporting with stderr/stdout details
- Optional workflow hints (disable with SHADOWGIT_HINTS=0)
- Comprehensive test coverage (175 tests passing)
- Fixed compatibility issues with TypeScript imports
Key Features
- 🔍 Git-native queries - AI runs git log, diff, show on shadow repos
- 🔒 Fort Knox security - Read-only access with multiple protection layers
- ⚡ Zero configuration - Auto-finds .shadowgit/ repositories
- 📝 Session aware - AI can manage its own coding sessions
Installation
npm install -g shadowgit-mcp-server@latest
This release focuses on security hardening and adds intelligent session management, making AI interactions safer and more context-aware.