This repository was archived by the owner on Jul 4, 2026. It is now read-only.
v0.7.0
What's Changed
- feat(release): add keyless signing/attestation + v0.5 specs by @kurtpayne in #85
- feat(rules): add OBF-003 Unicode PUA near dynamic execution sinks by @kurtpayne in #84
- chore(validation): add local validation wrapper and guardrail updates by @kurtpayne in #86
- chore(rules): add malware pattern updates 2026-03-16 by @kurtpayne in #87
- feat(rules): additive metadata enrichment for all existing rules by @kurtpayne in #88
- feat(cli): add rule metadata query command and docs by @kurtpayne in #89
- docs+test: metadata naming guidance and guard test by @kurtpayne in #90
- feat(ci): add reusable GitHub Actions workflow for SARIF scanning by @kurtpayne in #91
- chore(rules): add 10 rules for MCP attacks, social engineering chains, and container escape by @kurtpayne in #92
- ci: consolidate test and coverage workflows into single CI workflow by @kurtpayne in #93
- feat(integrations): add GitHub Pages deployment workflow for skillscan.sh by @kurtpayne in #94
- feat(ml): offline HuggingFace prompt-injection detector (--ml-detect) by @kurtpayne in #96
- feat(corpus): corpus management + delta-based model update trigger by @kurtpayne in #97
- feat(rules): MAL-029 Solana RPC C2 resolution + IOC/vuln updates (2026-03-17) by @kurtpayne in #95
- feat(signatures): signature-as-data architecture + corpus growth (57 injection examples) by @kurtpayne in #98
- chore(rules): MAL-030..032, PINJ-002 — CursorJack, Deno BYOR, GlassWorm Wave 6, MEDIA injection by @kurtpayne in #99
- feat(rules): [MAL-033, EXF-017] BlokTrooper VSX extension downloader, ClawHavoc agent memory harvesting (2026-03-18) by @kurtpayne in #100
- v0.3.2: SE detection, intel seeding, AI assist removal, docs cleanup by @kurtpayne in #101
- chore: docs cleanup pass — consolidate redundant files, fix stale references by @kurtpayne in #102
- feat(rules): [MAL-034, MAL-035] Click-Fix WebDAV exec, Electron app.asar C2 injection (2026-03-19) by @kurtpayne in #104
- chore: pattern update 2026-03-19 — GlassWorm Chrome RAT, OpenClaw gatewayUrl RCE by @kurtpayne in #103
- chore: pattern update 2026-03-20 — AI-gated malware C2, npm env exfil, prompt control persistence by @kurtpayne in #105
- chore: pattern update 2026-03-20 batch 2 — GhostClaw, LotAI, CVE-2026-33060 by @kurtpayne in #106
- chore: pattern update 2026-03-21 — SUP-011, SUP-012, MAL-039 by @kurtpayne in #107
- docs: add Milestone 21 — Skill Fuzzer to roadmap by @kurtpayne in #108
- docs: reorder roadmap — Skill Fuzzer to M19, Corpus to M20/M21 by @kurtpayne in #109
- chore: pattern update 2026-03-21 batch 2 — CanisterWorm, MCP Server CmdInj, Claudy Day by @kurtpayne in #110
- feat(rules): [MAL-042] CanisterWorm K8s wiper, [EXEC-041] API traffic hijacking (2026-03-22) by @kurtpayne in #112
- feat(rules): add MAL-043, PINJ-005, SUP-014 for 2026-03-23 threat batch by @kurtpayne in #113
- chore: pattern update 2026-03-23 — SQLBot RCE, RAG Poisoning, Actions Tag Repointing by @kurtpayne in #114
- chore: pattern update 2026-03-24 — StoatWaffle malware, MCP server CVEs by @kurtpayne in #115
- feat: add MAL-046, MAL-047, PINJ-007 — CursorJack deeplink, Claude hooks RCE, MCP sampling exfil by @kurtpayne in #116
- chore: pattern update 2026-03-24 batch 2 — Langflow RCE, Checkmarx Actions compromise by @kurtpayne in #117
- chore: pattern update 2026-03-22 — MAL-042, PINJ-005, 2 IOCs by @kurtpayne in #118
- chore(rules): add MAL-049, SUP-019 — LiteLLM TeamPCP supply chain compromise by @kurtpayne in #119
- chore: pattern update 2026-03-25 — ClawHavoc typosquats & prompt poaching by @kurtpayne in #120
Full Changelog: v0.3.1...v0.7.0