Changelog
Features
- 0cfb2dc feat(detection): resolve MCP server/tool on the OTel path, so MCP exfil rules stop being blind on Claude Code
- 5f99b3a feat(detection): resolve MCP server/tool on the OTel path, so MCP exf… (#336)
- ae319bf feat(harness): pin
clineas Cline's canonical harness name
Bug Fixes
- cf6baa9 fix(ci): make the static-link check fail closed, and plainer wording in the profile
- 7bd2ccf fix(docs): restore the star history chart
- 0a89e08 fix(docs): restore the star history chart (#337)
- 5e8c5be fix(endpoint): stop rollback disabling a collector it found already running
- 24fa177 fix(endpoint): stop the service before rollback restores its state file
- ac848c2 fix(endpoint): three high-severity lifecycle defects, and sandbox probes that catch them
- 04bfe2b fix(endpoint): three high-severity lifecycle defects, and sandbox probes that catch them (#335)
- 135bf3a fix(opencode): split shell commands before matching delete paths
- e87cbaa fix(opencode): split shell commands before matching delete paths (#345)
- 79d4817 fix(opencode): use [ \t]* instead of split to fix quoted paths with separators
- 9e2ffa6 fix(sandbox): make the rollback probe able to see the process it exists to find
- 39523c9 fix(selfupdate): reject any '..' sequence in archive entry names
- f9adaf9 fix(selfupdate): reject any '..' sequence in archive entry names (#344)
- 89f3d7d fix: bump go.opentelemetry.io/otel to v1.44.0 to remediate GHSA-5wrp-cwcj-q835
Other
- 0f3a369 Add Cline to supported runtimes documentation (#368)
- 79381ff Add Pi runtime identity and discovery
- 1af34bd Add Pi runtime to supported runtimes table (#359)
- 832efa0 Add binary-path GitHub Actions reference workflow (#301)
- a8ca801 Add binary-path GitHub Actions reference workflow.
- 4521c44 Add dual S3 and GCS upload GitHub Actions reference workflow (#300)
- fea421e Add dual S3 and GCS upload GitHub Actions reference workflow.
- 7905c79 Cline support 1/8: pin
clineas the canonical harness name (#356) - 958554a Fix leading whitespace deletes missed in shellMutationPaths regex
- 80a1b69 Merge main into examples/binary-path-ci-workflow
- fff80c9 Merge main into examples/s3-gcs-upload-ci-workflow
- 015541e Merge remote-tracking branch 'origin/main' into claude/dependabot-security-issues-79ios5-exporter-otel
- 60a36b3 Pi support 1/7: runtime identity and discovery (#347)
- 0d73826 chore(deps): bump github.com/google/cel-go to v0.30.0
- 8d5fef0 chore(deps): bump github.com/google/cel-go to v0.30.0 (#340)
- ba1cabd chore(deps): bump go.opentelemetry.io/otel to v1.43.0 in beaconjsonexporter
- cdff4ca chore(deps): bump go.opentelemetry.io/otel to v1.44.0 in beaconjsonexporter (#342)
- 614dd4d chore(deps): bump golang.org/x/text, x/net, and x/sys to patched versions
- ed94edd chore(deps): bump golang.org/x/text, x/net, and x/sys to patched versions (#346)
- f67f849 chore(deps): bump google.golang.org/grpc to v1.82.1 in beacon-sandbox
- 844402d chore(deps): bump google.golang.org/grpc to v1.82.1 in beacon-sandbox (#343)
- e69f8a7 chore(deps): bump google.golang.org/grpc to v1.82.1 in beaconjsonexporter
- 3f2736f chore(deps): bump google.golang.org/grpc to v1.82.1 in beaconjsonexporter (#341)
- 283cc5d chore(deps): bump nanoid to 3.3.18 in asymptote-sdk-js lockfile
- 14a033e chore(deps): bump nanoid to 3.3.18 in asymptote-sdk-js lockfile (#338)
- df75407 chore(deps): bump postcss to 8.5.26 in asymptote-sdk-js lockfile
- 2b53c05 chore(deps): bump postcss to 8.5.26 in asymptote-sdk-js lockfile (#339)
- a3daaf3 docs(linux): add a deployment profile, and make its central claim enforceable
- e82fb94 docs(linux): add a deployment profile, and make its central claim enforceable (#334)
- e3d1249 docs(readme): list Cline as a supported local coding agent harness
- af7e8f1 docs(readme): list Pi as a supported local coding agent harness
- f99ab1e test(sandbox): prove rollback by making an install fail, instead of reasoning about it
Installation
Homebrew (macOS/Linux)
brew tap asymptote-labs/tap
brew install beaconManual Download
Download the appropriate archive for your platform from the assets below, extract it, and add the binary to your PATH.
Quick Start
beacon endpoint install
beacon endpoint status
beacon endpoint wazuh print-configThreat detection rules
beacon ships with a small built-in baseline. Install the full threat-rule
pack (attached as threat-rules.tar.gz below) and scan your local telemetry:
beacon rules pull https://github.com/asymptote-labs/agent-beacon/releases/download/v1.2.2/threat-rules.tar.gz
beacon rules list
beacon scan