Jonathan Singer
439169d101
keep the mcp tests from reading your shell's STRIX_MCP_* vars
2026-08-24 08:59:35 -04:00
Jonathan Singer
267fe6f1ed
Merge remote-tracking branch 'origin/main' into mcp-support
...
# Conflicts:
# strix/interface/viewer/frontend/src/components/live/tool-renderers/index.ts
# strix/interface/viewer/static/assets/index-Bi_X6kI3.js
# strix/interface/viewer/static/assets/index-DBJ-RJqo.js
# strix/interface/viewer/static/assets/index-gEZK6bjO.js
# strix/interface/viewer/static/index.html
2026-08-24 08:59:31 -04:00
Jonathan Singer
fb4c3df9b5
Correct the notes docstring to match how notes reach the agent
2026-08-24 08:12:17 -04:00
devin-ai-integration[bot] and Ahmed Allam
391d81bea7
feat(agents): evidence discipline, and coverage as a first-class artifact ( #961 )
...
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com >
2026-08-24 03:34:09 -07:00
Jonathan Singer
c5eac30bf0
Say what MCP servers are worth connecting for
2026-08-21 17:38:05 -04:00
devin-ai-integration[bot] and Ahmed Allam
1c499c5b2d
perf: bootstrap Caido concurrently with the scan start ( #1143 )
...
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com >
2026-08-21 12:09:59 -07:00
Jonathan Singer
01ea94920d
Show MCP tool calls distinctly in the terminal and the run viewer
2026-08-21 13:09:24 -04:00
Jonathan Singer
afda373f55
Sanitize namespaced tool names so model APIs accept them
2026-08-21 11:08:23 -04:00
devin-ai-integration[bot] and Ahmed Allam
1ce43d1b94
perf: take heavy imports off the startup path and pre-warm them in the background ( #1141 )
...
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com >
2026-08-20 20:24:08 -07:00
Alex Schapiro
2cc8167814
docs(skills): correct gRPC guidance, a .proto is not a spec target
2026-08-20 19:27:04 -04:00
Alex Schapiro
d6a3ca7e58
docs(skills): document --workspace-file for supporting files
2026-08-20 19:27:04 -04:00
Alex Schapiro
9099710cef
docs(skills): fix nonexistent --mount flag, document real targeting flags, add application-security-testing skill
...
- Remove --mount from two skills: the flag does not exist in the CLI. Local
paths are mounted writable when passed with -t.
- Document --target-list, --scope-mode, --diff-base, and OpenAPI/Postman
targets, so agents stop putting spec URLs in --instruction prose.
- Add the application-security-testing skill as the entry point for
whole-product AppSec requests, routing each asset to the right workflow.
- Drop contractions and Latin abbreviations across the skill prose.
2026-08-20 19:27:04 -04:00
Alex Schapiro
634cb98241
docs(skills): use current OWASP editions (Top 10:2025, API Top 10 2023)
2026-08-20 19:27:04 -04:00
Alex Schapiro
1b36343eea
fix(skills): avoid unquoted colon in api-security-testing description
2026-08-20 19:27:04 -04:00
Alex Schapiro
b5ef93e744
feat(skills): add target-specific security testing skills (web app, API, OWASP Top 10, code review)
2026-08-20 19:27:04 -04:00
Jonathan Singer
305cb13998
Show errored MCP tool calls as failed in the TUI
2026-08-20 18:19:01 -04:00
RAJVARDHAN PATIL
e152c4c7c0
fix(report): raise RuntimeError on non-object run.json ( fixes #1109 ) ( #1116 )
2026-08-20 13:41:04 -07:00
OpenPay
fe758af4fc
fix(tui): use single space after ordered-list marker ( #1043 )
2026-08-20 13:40:12 -07:00
oyasumi and oyasumi
deb2057e20
fix(tui): preserve cost when state is truncated ( #1086 )
...
Co-authored-by: oyasumi <oyasumi@kantilabs.xyz >
2026-08-20 13:36:01 -07:00
Jonathan Singer
b30ed45ed1
Add MCP connection notes and per-run selection; clean up on cancel and dedupe names
2026-08-20 16:31:58 -04:00
Alex Schapiro
d6f2218756
Drop strict tool schemas on Claude routes
2026-08-20 23:12:23 +03:00
Jonathan Singer
8fb83f52b1
Add MCP docs and CLI polish: docs page, startup connect summary, --mcp-config flag, compact tool output
2026-08-20 15:39:50 -04:00
Jonathan Singer
209584e7fd
add a generic MCP client and a config for connecting MCP servers
2026-08-20 01:44:01 -04:00
oyasumi
6f88b7d7d5
Require viewer session for run data
2026-08-19 15:25:57 -04:00
oyasumi
8d3693df8c
Expose viewer host option
2026-08-19 15:25:57 -04:00
bearsyankees
9cd81e5c76
Add semantic browser and Electron security skills
2026-08-19 12:05:47 -04:00
bearsyankees
e8272c6a21
Add HTTP differential testing tools
2026-08-19 12:04:43 -04:00
bearsyankees
aa5867f5df
Add ecosystem supply-chain security skills
2026-08-19 12:03:45 -04:00
bearsyankees
7b8f9cb160
Add argument injection security skill
2026-08-19 12:02:45 -04:00
bearsyankees
2d944a9bcc
Add Azure and Entra security skill
2026-08-19 12:01:21 -04:00
alex s
0478a69ab0
feat(skills): cover OWASP LLM Top 10 2026 ( #1115 )
2026-08-18 18:40:27 -04:00
alex s
8ede419dcc
handle resume tokens gracefully ( #1097 )
...
* Fix telemetry deltas for resumed runs
* Fix resumed telemetry duration
2026-08-17 16:55:27 -04:00
Ahmed Allam
a46a60cf6a
feat(reporting): require contextual CVSS and usage evidence on dependency reports
2026-08-17 14:35:21 +03:00
Ahmed Allam
918442dbc8
cli: render contextual CVSS vector, advisory score, and reasoning for dependency findings
2026-08-17 13:03:41 +03:00
Ahmed Allam
e442db9c93
Contextual CVSS as a full 8-metric breakdown, computed like a normal finding
2026-08-17 13:03:41 +03:00
Ahmed Allam
9c0d30a0d0
reporting: require the source-to-sink trace in reachability evidence, not just CVSS reasoning
2026-08-17 13:03:41 +03:00
Ahmed Allam
55e6e66030
reporting: surface contextual CVSS in the markdown report; require reasoning only for surviving metrics
2026-08-17 13:03:41 +03:00
Ahmed Allam
99e2d5d826
reporting: drop per-metric contextual CVSS reasoning, keep the summary
2026-08-17 13:03:41 +03:00
Ahmed Allam
310f310e28
feat(reporting): contextual CVSS environmental metrics on dependency reports
2026-08-17 13:03:41 +03:00
yoni-at-strix
8551339130
feat: place caller-provided files into the sandbox workspace (extra_files, --workspace-file) ( #1085 )
...
* add extra-files plumbing so orchestrators can drop single files into the sandbox workspace
* reject extra-file paths that collide with a local source tree
* add --workspace-file so CLI users can place files in the sandbox workspace
* reject repeated and control-character workspace paths
* revalidate persisted workspace files when resuming a run
* drop the workspace-file size limit
2026-08-14 16:43:08 -04:00
Alex Schapiro
8ca0c4a9b8
Fix LiteLLM cost model resolution
2026-08-12 17:26:00 +03:00
Ahmed Allam
7cc9fa9faa
chore: release v1.5.3
v1.5.3
2026-08-10 21:28:52 +03:00
devin-ai-integration[bot]
174c16fa26
fix(llm): send OpenRouter app attribution on the request itself ( #1045 )
2026-08-10 11:24:02 -07:00
Ahmed Allam
94a2586aaa
fix(container): write the browser profile as root
2026-08-10 10:08:17 +03:00
Ahmed Allam
372e27fa17
chore(container): drop explanatory comment
2026-08-10 09:54:49 +03:00
Ahmed Allam
ad727edd66
fix(container): keep the browser env alive where image ENV is dropped
2026-08-10 09:54:49 +03:00
devin-ai-integration[bot] and Ahmed Allam
7b3c8f9b74
fix(container): reclaim abandoned browser sessions ( #1034 )
...
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com >
2026-08-09 16:57:51 -07:00
Ahmed Allam
ae07af6159
chore: drop explanatory comment
2026-08-09 15:44:16 +03:00
Ahmed Allam
649a2e2140
fix(llm): omit parallel_tool_calls on tool-less requests
2026-08-09 15:44:16 +03:00
Ahmed Allam
597aae6715
chore: release v1.5.2
v1.5.2
2026-08-09 04:29:34 +03:00