github nicobailon/pi-mcp-adapter v5.2.0

3 hours ago

This release closes a security hole in the MCP SDK and makes tool calls land on the first try more often. A malicious or compromised MCP server could previously trick the adapter into sending your saved sign-in tokens to an authorization server it chose; the updated SDK binds saved credentials to the server that issued them, and npm audit no longer flags the adapter. When the model lists a server's tools, it now sees each tool's parameter names, so it stops guessing argument names and wasting a turn on the error. The doctor command and local Jev setups also behave the way you'd expect.

Highlights

  • Fixes the MCP SDK security advisory GHSA-6qxp-vccf-f47h, so a malicious MCP server can no longer collect the tokens saved from an earlier sign-in.
  • When the model lists a server's tools, it now sees each tool's parameter names, so fewer calls fail on guessed argument names.
  • pi-mcp-adapter doctor now agrees with Pi about which project servers are trusted.
  • Jev semantic search can use a System One server running on your own machine.

Need to know

With the updated SDK, a server URL that redirects to a different host is no longer followed. If a server stops connecting with "Redirect to X not followed", put the final URL in your config. A redirect from http to https on the same host still works.

Changelog

Highlights

  • Fixes the MCP SDK security advisory GHSA-6qxp-vccf-f47h, so a malicious MCP server can no longer collect the tokens saved from an earlier sign-in.
  • When the model lists a server's tools, it now sees each tool's parameter names, so fewer calls fail on guessed argument names.
  • pi-mcp-adapter doctor now agrees with Pi about which project servers are trusted.
  • Jev semantic search can use a System One server running on your own machine.

Changed

  • mcp({ server }) now lists each tool's parameter names, required ones first, for example get_record(record_id, fields?). Models used to guess names like id for record_id and lose a turn to the validation error. Types and nested fields are still shown only by describe. Thanks to @rakesh-vs for PR #817.

Fixed

  • pi-mcp-adapter doctor no longer reports project servers as blocked by project trust when a Pi session in the same folder would trust the project. When the adapter is installed as a Pi package, the doctor now finds Pi through the pi on your PATH. Like Pi, it trusts a project that has no Pi-specific project files, such as .pi/settings.json. Thanks to @felipe-saavedra for reporting it in #809.
  • Running Pi once with --mcp-config <file>, for example pi -e <adapter> --mcp-config <file> -p ..., no longer adds "-builtin:mcp" to your Pi settings.json. The same goes for a configPath passed to createMcpAdapter(). Pi already leaves its built-in MCP out of those runs. An installed adapter without a config path still turns the built-in off once, as before. Thanks to @deniskern for reporting it in #811.
  • SYSTEMONE_ENDPOINT can point at a System One server on your own machine, such as http://127.0.0.1:8080/v1/systemone. Plain http is accepted only on localhost, 127.0.0.0/8, and [::1]; every other endpoint still needs https. A local server that ignores keys still needs some non-empty SYSTEMONE_API_KEY. Thanks to @amchen2310 for reporting it in #810.

Security

  • The MCP SDK packages move from 2.0.0 to 2.3.1, which fixes GHSA-6qxp-vccf-f47h. With 2.0.0, a malicious or compromised MCP server could point sign-in at its own authorization server and receive the refresh token and client secret saved from an earlier sign-in. npm audit no longer flags the adapter. One side effect: a server URL that redirects to a different host is no longer followed, so put the final URL in your config. A redirect from http to https on the same host still works. Thanks to @cash-flow-king for reporting it in #816 and to @rakesh-vs for PR #819.

Don't miss a new pi-mcp-adapter release

NewReleases is sending notifications on new releases.