Changelog
- 67e2ed3 ci: bump the ci-actions group with 4 updates (#287)
- c609b0b deps: bump modernc.org/sqlite from 1.46.1 to 1.47.0 (#282)
- e87d8c2 feat: JetBrains/Junie MCP proxy integration (#260)
- b7145d2 feat: adaptive enforcement exempt_domains for DLP scoring (#268)
- d8f1ef4 feat: add --sandbox and --workspace flags to jetbrains install (#269)
- 33330fb feat: add redirect policy action for MCP tool call routing (#271)
- 65b936b feat: built-in attack simulation command (#277)
- f98bf70 feat: config security scoring and tool policy overpermission audit (#273)
- d735d3e feat: full-schema tool poisoning + state/control response patterns (#270)
- f5a1fa6 feat: generic HTTP reverse proxy with body scanning (#278)
- 62094cb feat: macOS sandbox via sandbox-exec (seatbelt) (#275)
- 6624862 feat: per-agent sandbox profiles, strict mode, diagnostics, redirect handler (#272)
- cfec5f8 feat: sandbox --best-effort for container environments (#289)
- ce39f12 feat: unprivileged process sandbox (Landlock + seccomp + netns) (#267)
- 2332fb1 fix: harden reverse proxy scanning and kill switch preemption (#281)