[v4.5.0] - 2026-07-24
Added
- Frontend: Open-source frontend code with open-source environment configuration (5cb33e2, bed369b)
- Agent-Scan: Modularize as standalone CLI with AIG integration support (2a18b88)
- Agent-Scan: Add 4 new detection skills for AI agent security (5f7022f)
- Agent-Scan: Register 4 new detection skills in _DETECTION_SKILLS (9c2c0f8)
- MCP-Scan: Modularize with dual-mode support (CLI + AIG Web) (272c56e)
- MCP-Scan: Add standalone mcp-scan-lite module (d93e69a)
- MCP-Scan: Add 2 MCP security detection rules (#458)
- MCP-Scan: Add ATR-derived MCP detection rules for further attack surfaces (#469)
- Skill-Scan: Add Agent Skill security auditing support (78ddc07)
- Skill-Scan: Repackage as standalone PyPI package aig-skill-scan (545ed4b)
- Skill-Scan: SARIF 2.1.0 output + single-stage optimization (d32a56f)
- Eval: Add agentic-tool-misuse evaluation dataset (#427)
- Data: Add AIG rules [2026-06-29], [2026-07-13], [2026-07-17]
- Data: Add CVE rules for Jan, Open WebUI, crewai, lobehub components
- Data: Add ai component fingerprints (#459)
- Data: Add missing English vuln rules
- Docs: Add aig-skill-scan and SkillTrustBench to README
- Docs: Add Tiane and Binus University to user acknowledgements
Changed
- Frontend: Add open-source environment configuration and UI improvements
- MCP-Scan: Remove redundant aig-mcp-scan-lite module (ff4a6b3)
- Skill-Scan: Simplify to single default LLM, rebrand to aig-skill-scan (982d938)
- Skill-Scan: Stage 2 Code Audit output Markdown report instead of XML (04f48f3)
- Docs: Update CVE count to 1700+ and fix component counts in ai-infra-scan docs
- Docs: Update component/vuln counts after multiple rules updates
- Docs: Sync new "Securing the AI Agent" paper across all README languages
- Docs: Update readme and technical_report
- Docs: Collapse older What's New entries, keep latest 5 visible
- Docs: Fix CVE count 1600+ -> 1900+ in README_DE and README_RU
Fixed
- Version: Bypass GitHub API rate limit via releases/latest redirect (7a08609)
- Task Manager: Classify Skill-Scan and rename MCP label (7be6e7c)
- i18n: Bilingual stage titles for mcp-scan and skill-scan (0823a53, c8969cc)
- Data: Remove duplicate OpenClaw/ directories (EN+CN) (a7d5388)
- Data: Remove 4 CVE rules without matching fingerprints (d89e887)
- Data: Resolve YAML parse errors in 4 vuln rule files (a7af757)
- Data: Correct info.name to match fingerprint names (case-sensitive) (f7de1bc, 9552ebf)
- Data: Fix missing CN translations for multiple CVE rules
- Docs: Fix Python version requirement in skill-scan docs (3.12 -> 3.9) (fff4bb9)
- Docs: Fix EN README CHANGELOG link text from Chinese to English (e21733d)
Chore
- Remove redundant aig-mcp-scan-lite module
- Add yamlcheck to .gitignore
- Bump skill-scan version to 0.2.0
Contributors
Special thanks to @zhuque, @aigsec, @aigdocs[bot], @boyhack, @Elwood Ying, @DevamShah, @adam Lin, @fyoungguo, @AIG-Bot