Changelog

What's changed.

Every release, newest first: what was added, changed and fixed, with the CVE for every security fix.

Follow by RSS — paste the address into any feed reader to hear about every release, security fixes included.

  1. · 1.3.1

    This month's MCP advisories, and points for what you find

    Security

    • mcp-known-vulnerable-version knows three critical advisories published this month: mysql_mcp_server before 0.4.2 (CVE-2026-59971), MCP Context Forge 1.0.0 to 1.0.1 (CVE-2026-53710) and obsidian-web-mcp before 0.2.0 (CVE-2026-54618). A config that pins an affected version is flagged.

    Added

    • Leaderboards score what your scans find, by severity, rather than how many scans you run — with a global board and one for each of eight regions. The top 5 of each board get Pro free.
    • The site in Hindi, and the trailer in Chinese, dubbed or with English audio and subtitles.
    • This changelog as an RSS feed.

    Fixed

    • The trailer can be skipped through on iPhone and in Safari.
  2. · 1.3.0

    The web scanner, accounts, and 54 rules

    Ryzek now runs at ryzek.dev. Sign in, add your files, and read the results — nothing to install. Scanned files are read in memory and discarded.

    • 54 rules, up from 12 — MCP configuration, the agent layer (injection, forged tool results, memory poisoning, deferred triggers), supply chain and credentials — each with a live demo on the rules page, generated by running the scanner.
    • Drift detection that follows your account. Ryzek keeps a fingerprint of each tool you scan and flags changes on your next scan, on any device. Accept a change when it's expected.
    • Version-aware dependency checks. vulnerable-dependency now compares versions against the advisory, so patched releases stay quiet. New advisories: Langflow (CVE-2025-3248), Flowise (CVE-2025-59528) and mcp-remote (CVE-2025-6514).
    • package.json and requirements.txt are read for install hooks and advisory-listed dependencies.
    • Shadow MCP servers: upload a project's MCP config alongside a client config, such as claude_desktop_config.json, to see servers the client can use that the project never declares.

    Fixes

    • install-script-hook couldn't match a real package.json; it now does, and still ignores hooks that don't reach the network or a shell.
    • A hidden Unicode Tag character was reported twice by two rules; it's now reported once.
    • Remote MCP servers were flagged for excessive permissions simply for using the network; that false alarm is gone.
    • Three rules showed no OWASP category because of mismatched ids; every rule is now mapped.
    • DNS-exfiltration, persistence and prompt-extraction checks now match code that's split across lines, as formatters lay it out.
    • The MCP Go SDK advisory now reflects its fix in version 1.4.1.
  3. 1.2.1

    Licence change and a command-line fix

    Moved to the Business Source License 1.1, which restricts commercial resale and competing hosted services. Also fixed a crash in the command-line help.

  4. 1.2.0

    Renamed to Ryzek

    Published under the current name, with the website and domain live.

  5. 1.1.0

    Multi-agent discovery

    The command-line tool gained a discover command that lists skills installed for Claude Code, Cursor, Gemini and Codex — including ones nobody remembers installing.

  6. 1.0.0

    First release

    Twelve detection rules across SKILL.md bundles and JSON tool manifests, each mapped to the OWASP Agentic Skills Top 10, with a confidence score and stated reason on every finding.