Skip to content
This repository was archived by the owner on Jul 4, 2026. It is now read-only.

v0.7.0

Choose a tag to compare

@github-actions github-actions released this 26 Mar 03:40

What's Changed

  • feat(release): add keyless signing/attestation + v0.5 specs by @kurtpayne in #85
  • feat(rules): add OBF-003 Unicode PUA near dynamic execution sinks by @kurtpayne in #84
  • chore(validation): add local validation wrapper and guardrail updates by @kurtpayne in #86
  • chore(rules): add malware pattern updates 2026-03-16 by @kurtpayne in #87
  • feat(rules): additive metadata enrichment for all existing rules by @kurtpayne in #88
  • feat(cli): add rule metadata query command and docs by @kurtpayne in #89
  • docs+test: metadata naming guidance and guard test by @kurtpayne in #90
  • feat(ci): add reusable GitHub Actions workflow for SARIF scanning by @kurtpayne in #91
  • chore(rules): add 10 rules for MCP attacks, social engineering chains, and container escape by @kurtpayne in #92
  • ci: consolidate test and coverage workflows into single CI workflow by @kurtpayne in #93
  • feat(integrations): add GitHub Pages deployment workflow for skillscan.sh by @kurtpayne in #94
  • feat(ml): offline HuggingFace prompt-injection detector (--ml-detect) by @kurtpayne in #96
  • feat(corpus): corpus management + delta-based model update trigger by @kurtpayne in #97
  • feat(rules): MAL-029 Solana RPC C2 resolution + IOC/vuln updates (2026-03-17) by @kurtpayne in #95
  • feat(signatures): signature-as-data architecture + corpus growth (57 injection examples) by @kurtpayne in #98
  • chore(rules): MAL-030..032, PINJ-002 — CursorJack, Deno BYOR, GlassWorm Wave 6, MEDIA injection by @kurtpayne in #99
  • feat(rules): [MAL-033, EXF-017] BlokTrooper VSX extension downloader, ClawHavoc agent memory harvesting (2026-03-18) by @kurtpayne in #100
  • v0.3.2: SE detection, intel seeding, AI assist removal, docs cleanup by @kurtpayne in #101
  • chore: docs cleanup pass — consolidate redundant files, fix stale references by @kurtpayne in #102
  • feat(rules): [MAL-034, MAL-035] Click-Fix WebDAV exec, Electron app.asar C2 injection (2026-03-19) by @kurtpayne in #104
  • chore: pattern update 2026-03-19 — GlassWorm Chrome RAT, OpenClaw gatewayUrl RCE by @kurtpayne in #103
  • chore: pattern update 2026-03-20 — AI-gated malware C2, npm env exfil, prompt control persistence by @kurtpayne in #105
  • chore: pattern update 2026-03-20 batch 2 — GhostClaw, LotAI, CVE-2026-33060 by @kurtpayne in #106
  • chore: pattern update 2026-03-21 — SUP-011, SUP-012, MAL-039 by @kurtpayne in #107
  • docs: add Milestone 21 — Skill Fuzzer to roadmap by @kurtpayne in #108
  • docs: reorder roadmap — Skill Fuzzer to M19, Corpus to M20/M21 by @kurtpayne in #109
  • chore: pattern update 2026-03-21 batch 2 — CanisterWorm, MCP Server CmdInj, Claudy Day by @kurtpayne in #110
  • feat(rules): [MAL-042] CanisterWorm K8s wiper, [EXEC-041] API traffic hijacking (2026-03-22) by @kurtpayne in #112
  • feat(rules): add MAL-043, PINJ-005, SUP-014 for 2026-03-23 threat batch by @kurtpayne in #113
  • chore: pattern update 2026-03-23 — SQLBot RCE, RAG Poisoning, Actions Tag Repointing by @kurtpayne in #114
  • chore: pattern update 2026-03-24 — StoatWaffle malware, MCP server CVEs by @kurtpayne in #115
  • feat: add MAL-046, MAL-047, PINJ-007 — CursorJack deeplink, Claude hooks RCE, MCP sampling exfil by @kurtpayne in #116
  • chore: pattern update 2026-03-24 batch 2 — Langflow RCE, Checkmarx Actions compromise by @kurtpayne in #117
  • chore: pattern update 2026-03-22 — MAL-042, PINJ-005, 2 IOCs by @kurtpayne in #118
  • chore(rules): add MAL-049, SUP-019 — LiteLLM TeamPCP supply chain compromise by @kurtpayne in #119
  • chore: pattern update 2026-03-25 — ClawHavoc typosquats & prompt poaching by @kurtpayne in #120

Full Changelog: v0.3.1...v0.7.0