This release closes a security hole in the MCP SDK and makes tool calls land on the first try more often. A malicious or compromised MCP server could previously trick the adapter into sending your saved sign-in tokens to an authorization server it chose; the updated SDK binds saved credentials to the server that issued them, and npm audit no longer flags the adapter. When the model lists a server's tools, it now sees each tool's parameter names, so it stops guessing argument names and wasting a turn on the error. The doctor command and local Jev setups also behave the way you'd expect.
Highlights
- Fixes the MCP SDK security advisory GHSA-6qxp-vccf-f47h, so a malicious MCP server can no longer collect the tokens saved from an earlier sign-in.
- When the model lists a server's tools, it now sees each tool's parameter names, so fewer calls fail on guessed argument names.
pi-mcp-adapter doctornow agrees with Pi about which project servers are trusted.- Jev semantic search can use a System One server running on your own machine.
Need to know
With the updated SDK, a server URL that redirects to a different host is no longer followed. If a server stops connecting with "Redirect to X not followed", put the final URL in your config. A redirect from http to https on the same host still works.
Changelog
Highlights
- Fixes the MCP SDK security advisory GHSA-6qxp-vccf-f47h, so a malicious MCP server can no longer collect the tokens saved from an earlier sign-in.
- When the model lists a server's tools, it now sees each tool's parameter names, so fewer calls fail on guessed argument names.
pi-mcp-adapter doctornow agrees with Pi about which project servers are trusted.- Jev semantic search can use a System One server running on your own machine.
Changed
mcp({ server })now lists each tool's parameter names, required ones first, for exampleget_record(record_id, fields?). Models used to guess names likeidforrecord_idand lose a turn to the validation error. Types and nested fields are still shown only bydescribe. Thanks to @rakesh-vs for PR #817.
Fixed
pi-mcp-adapter doctorno longer reports project servers as blocked by project trust when a Pi session in the same folder would trust the project. When the adapter is installed as a Pi package, the doctor now finds Pi through thepion your PATH. Like Pi, it trusts a project that has no Pi-specific project files, such as.pi/settings.json. Thanks to @felipe-saavedra for reporting it in #809.- Running Pi once with
--mcp-config <file>, for examplepi -e <adapter> --mcp-config <file> -p ..., no longer adds"-builtin:mcp"to your Pisettings.json. The same goes for aconfigPathpassed tocreateMcpAdapter(). Pi already leaves its built-in MCP out of those runs. An installed adapter without a config path still turns the built-in off once, as before. Thanks to @deniskern for reporting it in #811. SYSTEMONE_ENDPOINTcan point at a System One server on your own machine, such ashttp://127.0.0.1:8080/v1/systemone. Plainhttpis accepted only onlocalhost,127.0.0.0/8, and[::1]; every other endpoint still needshttps. A local server that ignores keys still needs some non-emptySYSTEMONE_API_KEY. Thanks to @amchen2310 for reporting it in #810.
Security
- The MCP SDK packages move from 2.0.0 to 2.3.1, which fixes GHSA-6qxp-vccf-f47h. With 2.0.0, a malicious or compromised MCP server could point sign-in at its own authorization server and receive the refresh token and client secret saved from an earlier sign-in.
npm auditno longer flags the adapter. One side effect: a server URL that redirects to a different host is no longer followed, so put the final URL in your config. A redirect fromhttptohttpson the same host still works. Thanks to @cash-flow-king for reporting it in #816 and to @rakesh-vs for PR #819.