github quazardous/nelson-mcp v0.14.3

latest release: v0.14.4
11 days ago

The config API can no longer undo the protections set for an agent, and
with LibreOffice's KDE interface a call right after opening a document no
longer lands on the previous one.

Fixed

  • With LibreOffice's KDE interface, the call right after doc_open or
    doc_create could land on the previous document.
    The window manager can
    hand focus back to the previous window for about 100 ms after the switch,
    and the next call arrives within milliseconds. Nelson now keeps the
    document a tool just made active as the active one for two seconds, unless
    it is closed. Measured with the new KDE smoke mode: the opening checks
    failed about one run in three, and now pass 12 of 12

Security

  • The config API could undo the protections set for an agent.
    POST /api/config wrote any setting. An agent with access could clear the
    access token, change the address, switch off the guard against disabling
    change recording, set the command a launcher runs, or widen the folders its
    tools reach. GET also returned the token and providers' API keys in clear.
    The settings that decide what is exposed, what runs and what can be reached
    are now reserved to Options:

    • http.*, tunnel.*, debug.*, launcher.*;
    • *.instances;
    • core.force_track_changes.

    A request that touches one is refused with 403 and writes nothing, and
    secrets read back as ***. Everything else (read limits, exchange format,
    the name on tracked changes, MCP endpoints) stays open to the agent

Added

  • README: "Let the agent configure Nelson": what the config API is for,
    how to switch it on, and what it cannot change. API.md documents the
    reserved settings, the 403 and masked secrets, and the current /health
    response; the option's help text in Options says what stays reserved

Don't miss a new nelson-mcp release

NewReleases is sending notifications on new releases.