<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Ryzek changelog</title>
<link>https://ryzek.dev/changelog</link>
<atom:link href="https://ryzek.dev/changelog.xml" rel="self" type="application/rss+xml"/>
<description>What's changed in Ryzek, release by release, with the CVE for every security fix.</description>
<language>en</language>
<lastBuildDate>Sat, 19 Sep 2026 00:00:00 GMT</lastBuildDate>
<item>
<title>1.3.1 — This month's MCP advisories, and points for what you find</title>
<link>https://ryzek.dev/changelog#v1-3-1</link>
<guid isPermaLink="false">ryzek-1.3.1</guid>
<pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate>
<category>security</category>
<description><![CDATA[<div class="prose">
          <p><strong>Security</strong></p>
          <ul>
            <li><code>mcp-known-vulnerable-version</code> knows three critical advisories published this month: mysql_mcp_server before 0.4.2 (CVE-2026-59971), MCP Context Forge 1.0.0 to 1.0.1 (CVE-2026-53710) and obsidian-web-mcp before 0.2.0 (CVE-2026-54618). A config that pins an affected version is flagged.</li>
          </ul>
          <p><strong>Added</strong></p>
          <ul>
            <li>Leaderboards score what your scans find, by severity, rather than how many scans you run — with a global board and one for each of eight regions. The top 5 of each board get Pro free.</li>
            <li>The site in Hindi, and the trailer in Chinese, dubbed or with English audio and subtitles.</li>
            <li>This changelog as an RSS feed.</li>
          </ul>
          <p><strong>Fixed</strong></p>
          <ul>
            <li>The trailer can be skipped through on iPhone and in Safari.</li>
          </ul>
        </div>]]></description>
</item>
<item>
<title>1.3.0 — The web scanner, accounts, and 54 rules</title>
<link>https://ryzek.dev/changelog#v1-3-0</link>
<guid isPermaLink="false">ryzek-1.3.0</guid>
<pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate>
<category>security</category>
<description><![CDATA[<div class="prose">
          <p>Ryzek now runs at ryzek.dev. Sign in, add your files, and read the results — nothing to install. Scanned files are read in memory and discarded.</p>
          <ul>
            <li><strong>54 rules</strong>, up from 12 — MCP configuration, the agent layer (injection, forged tool results, memory poisoning, deferred triggers), supply chain and credentials — each with a live demo on the rules page, generated by running the scanner.</li>
            <li><strong>Drift detection that follows your account.</strong> Ryzek keeps a fingerprint of each tool you scan and flags changes on your next scan, on any device. Accept a change when it's expected.</li>
            <li><strong>Version-aware dependency checks.</strong> <code>vulnerable-dependency</code> now compares versions against the advisory, so patched releases stay quiet. New advisories: Langflow (CVE-2025-3248), Flowise (CVE-2025-59528) and mcp-remote (CVE-2025-6514).</li>
            <li><strong>package.json and requirements.txt</strong> are read for install hooks and advisory-listed dependencies.</li>
            <li><strong>Shadow MCP servers:</strong> upload a project's MCP config alongside a client config, such as <code>claude_desktop_config.json</code>, to see servers the client can use that the project never declares.</li>
          </ul>
          <p><strong>Fixes</strong></p>
          <ul>
            <li><code>install-script-hook</code> couldn't match a real package.json; it now does, and still ignores hooks that don't reach the network or a shell.</li>
            <li>A hidden Unicode Tag character was reported twice by two rules; it's now reported once.</li>
            <li>Remote MCP servers were flagged for excessive permissions simply for using the network; that false alarm is gone.</li>
            <li>Three rules showed no OWASP category because of mismatched ids; every rule is now mapped.</li>
            <li>DNS-exfiltration, persistence and prompt-extraction checks now match code that's split across lines, as formatters lay it out.</li>
            <li>The MCP Go SDK advisory now reflects its fix in version 1.4.1.</li>
          </ul>
        </div>]]></description>
</item>
<item>
<title>1.2.1 — Licence change and a command-line fix</title>
<link>https://ryzek.dev/changelog#v1-2-1</link>
<guid isPermaLink="false">ryzek-1.2.1</guid>
<description><![CDATA[<p>Moved to the Business Source License 1.1, which restricts commercial resale and competing hosted services. Also fixed a crash in the command-line help.</p>]]></description>
</item>
<item>
<title>1.2.0 — Renamed to Ryzek</title>
<link>https://ryzek.dev/changelog#v1-2-0</link>
<guid isPermaLink="false">ryzek-1.2.0</guid>
<description><![CDATA[<p>Published under the current name, with the website and domain live.</p>]]></description>
</item>
<item>
<title>1.1.0 — Multi-agent discovery</title>
<link>https://ryzek.dev/changelog#v1-1-0</link>
<guid isPermaLink="false">ryzek-1.1.0</guid>
<description><![CDATA[<p>The command-line tool gained a discover command that lists skills installed for Claude Code, Cursor, Gemini and Codex — including ones nobody remembers installing.</p>]]></description>
</item>
<item>
<title>1.0.0 — First release</title>
<link>https://ryzek.dev/changelog#v1-0-0</link>
<guid isPermaLink="false">ryzek-1.0.0</guid>
<description><![CDATA[<p>Twelve detection rules across SKILL.md bundles and JSON tool manifests, each mapped to the OWASP Agentic Skills Top 10, with a confidence score and stated reason on every finding.</p>]]></description>
</item>
</channel>
</rss>
