New: trustmcp check <reference> scans an MCP server from npm/PyPI/GitHub/server.json
before you install it — never executes anything from the downloaded package.
Also: three new detection rules (tool-description injection, JWT/credential secrets,
runtime description mutation) raising DVMCP canonical detection from 3/10 to 6/10.
Full Changelog: v0.1.2...v0.2.0