v0.2.2
Security and reliability
- Redact configured Brave/Tavily credentials and common authorization tokens from every MCP result, provider error, and fallback diagnostic.
- Bound provider diagnostics so oversized upstream failures cannot flood tool output.
- Reject non-HTTP(S) extract inputs and filter unsafe provider-returned citation URLs.
- Keep deterministic bundled output and the same native DeepSeek Harness component identity.
TaroCub v0.1.281 adds the corresponding managed-host validation and safe fallback when a Harness profile has a missing, altered, or mismatched plugin patch.
Verification
- 28 plugin tests passed
- TypeScript typecheck passed
- deterministic bundle check passed
- npm pack dry-run passed
- npm audit --omit=dev: 0 vulnerabilities
- repository and history secret scans passed