This release closes a set of integration gaps where shell commands and file paths reached hosts without being analyzed, and makes installation and doctor report each host's real state instead of trusting its config file.
Highlights
- Shell commands run through Claude Code's
Monitor, Grok Build'smonitor, and Pi'spowershelltools are now analyzed for destructive commands. Previously those tools were routed as non-command tools, so a command such asgit reset --hardwas allowed through. (#163) - Tool inputs that name files in a
pathsarray, a downloaddestination, or a bare patch string are now inspected, so a Copilot CLI search or patch and an Amp thread download can no longer read or write protected paths unchecked. (#164, #166)
Added
- Added OpenCode v1's global
~/.config/opencode/config.jsonto the protected OpenCode configuration paths. (#173)
Changed
- Changed OpenCode v2 detection so
doctorand the policy GUI ask the host for activation state withopencode api plugin.listand report a plugin OpenCode marked failed as not configured, instead of reporting it as configured from the config file alone. These commands may start OpenCode's persistent background service. (#171, #173) - Changed the OpenCode v2 installer to run
opencode plugin addfirst, runopencode plugin updateonly when the plugin was already configured, wait for the host to list the plugin, and then confirm an active copy. The install now fails with OpenCode's own error when the plugin failed, and fails when the host lists no active copy. (#169, #173) - Changed the Codex entry in
doctorto state that Codex runs only trusted hooks and thatdoctorcannot check trust, alongside the/hookstrust step. (#171) - Documented two analysis limits in
SECURITY.mdand the README: Codex'sexec_commandpayload omits the call'sworkdir, and OpenClaw'sbefore_tool_callcontext exposes no session directory, so on those hosts a command can be analyzed against a different directory than the one it runs in. (#172)
Fixed
- Fixed Copilot CLI hook input handling so an object
toolArgsis used as received, anapply_patchpayload that arrives as raw*** Begin Patchtext is analyzed as a patch, and Copilot'sBashtool is analyzed with shell auto-detection. (#166) - Fixed Copilot CLI detection to read repository-level
enabledPlugins, to count hook entries that omittypeor useexecandargs, and to keep a standalone hook reported as configured when a repository switches the plugin off. (#171) - Fixed Gemini CLI analysis to use the directory named by
run_shell_command'sdir_pathrather than the session directory. (#168) - Fixed Hermes so file-tool calls are analyzed in the directory Hermes resolves their relative paths against, and so installation targets the profile named in
active_profile. (#167) - Fixed host-configuration discovery to follow
CLAUDE_CONFIG_DIR,PI_CODING_AGENT_DIR, andOPENCLAW_HOMEinstead of assuming~/.claude,~/.pi/agent, and the OS home directory. (#170, #171) - Fixed OpenCode v2 first installation, which failed because
opencode plugin updateran against a plugin that was not configured yet. (#169) - Fixed OpenCode v1 plugin discovery when
OPENCODE_CONFIG_DIRis set: detection and uninstall now also scan the XDG configuration directory that v1 loads. (#169) - Fixed a
~working directory on OpenCode v2 so it resolves to the home directory, matching the host, instead of a literal~directory inside the project. (#169) - Fixed an OpenClaw reinstall after an uninstall, which left the plugin disabled. Installation now enables it and accepts an enable the Gateway saved before a newer configuration reload superseded it. (#170, #173)