Changelog
What's changed.
Every release, newest first: what was added, changed and fixed, with the CVE for every security fix.
Follow by RSS — paste the address into any feed reader to hear about every release, security fixes included.
-
· 1.3.1
This month's MCP advisories, and points for what you find
Security
mcp-known-vulnerable-versionknows three critical advisories published this month: mysql_mcp_server before 0.4.2 (CVE-2026-59971), MCP Context Forge 1.0.0 to 1.0.1 (CVE-2026-53710) and obsidian-web-mcp before 0.2.0 (CVE-2026-54618). A config that pins an affected version is flagged.
Added
- Leaderboards score what your scans find, by severity, rather than how many scans you run — with a global board and one for each of eight regions. The top 5 of each board get Pro free.
- The site in Hindi, and the trailer in Chinese, dubbed or with English audio and subtitles.
- This changelog as an RSS feed.
Fixed
- The trailer can be skipped through on iPhone and in Safari.
-
· 1.3.0
The web scanner, accounts, and 54 rules
Ryzek now runs at ryzek.dev. Sign in, add your files, and read the results — nothing to install. Scanned files are read in memory and discarded.
- 54 rules, up from 12 — MCP configuration, the agent layer (injection, forged tool results, memory poisoning, deferred triggers), supply chain and credentials — each with a live demo on the rules page, generated by running the scanner.
- Drift detection that follows your account. Ryzek keeps a fingerprint of each tool you scan and flags changes on your next scan, on any device. Accept a change when it's expected.
- Version-aware dependency checks.
vulnerable-dependencynow compares versions against the advisory, so patched releases stay quiet. New advisories: Langflow (CVE-2025-3248), Flowise (CVE-2025-59528) and mcp-remote (CVE-2025-6514). - package.json and requirements.txt are read for install hooks and advisory-listed dependencies.
- Shadow MCP servers: upload a project's MCP config alongside a client config, such as
claude_desktop_config.json, to see servers the client can use that the project never declares.
Fixes
install-script-hookcouldn't match a real package.json; it now does, and still ignores hooks that don't reach the network or a shell.- A hidden Unicode Tag character was reported twice by two rules; it's now reported once.
- Remote MCP servers were flagged for excessive permissions simply for using the network; that false alarm is gone.
- Three rules showed no OWASP category because of mismatched ids; every rule is now mapped.
- DNS-exfiltration, persistence and prompt-extraction checks now match code that's split across lines, as formatters lay it out.
- The MCP Go SDK advisory now reflects its fix in version 1.4.1.
-
1.2.1
Licence change and a command-line fix
Moved to the Business Source License 1.1, which restricts commercial resale and competing hosted services. Also fixed a crash in the command-line help.
-
1.2.0
Renamed to Ryzek
Published under the current name, with the website and domain live.
-
1.1.0
Multi-agent discovery
The command-line tool gained a discover command that lists skills installed for Claude Code, Cursor, Gemini and Codex — including ones nobody remembers installing.
-
1.0.0
First release
Twelve detection rules across SKILL.md bundles and JSON tool manifests, each mapped to the OWASP Agentic Skills Top 10, with a confidence score and stated reason on every finding.