Skip to content

feat/harden_tools - #31

Merged
RahmeKarim merged 5 commits into
mainfrom
dev
Sep 28, 2026
Merged

RahmeKarim merged 5 commits into
mainfrom
dev

Conversation

@RahmeKarim

@RahmeKarim RahmeKarim commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Note

Medium Risk
Generated client renames and response-shape changes can break callers; Autogen may omit tools with invalid MCP names; capping mcp<2 affects installs on future major releases.

Overview
Releases Metorial Python SDK 2.4.1 and documents a security-focused change to the Autogen integration: create_autogen_tools() now builds tool callables with explicit inspect.Signature (no dynamic source compilation), validates tool/parameter names, and skips invalid tools with a warning.

The bulk of the diff is a regenerated Magnetar client aligned with the API. Organization webhooks gain event delivery and delivery attempt resources (list/get, plus delivery retry), and event destinations gain ping, optional retry settings on create/update, and richer list filters. Several surfaces rename chat_integration_id → chat_connection_id and extend chat/callback/event listing (e.g. channel has_access, integration enable_callback_tools, auth-config adapter filter, optional provider_version_id / user_managed_callbacks on dashboard provider triggers). List responses for callback/chat events are slimmer (e.g. no details on callback event list items). mcp is pinned to <2 in core dependencies.

Reviewed by Cursor Bugbot for commit 8bb6b96. Bugbot is set up for automated code reviews on this repo. Configure here.

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedpypi/​mcp@​1.30.099100100100100

View full report

@RahmeKarim
RahmeKarim merged commit 0afda8f into main Sep 28, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant