Network-AI
Release

v5.12.4 - SkillSpector triage & Socket.dev scan gap

Published 2026-06-19 | Release notes

A hardening and triage release targeting ClawHub SkillSpector findings from v5.12.3 and a Socket.dev scan gap in the dual CJS+ESM build. No breaking changes; all 3,269 tests across 33 suites pass.

Read the release here or open the original release on GitHub.

v5.12.4 — SkillSpector triage, SKILL.md trigger hardening, Socket.dev scan gap

A hardening and triage release targeting ClawHub SkillSpector findings from v5.12.3 and a Socket.dev scan gap in the dual CJS+ESM build. No breaking changes; all 3,269 tests across 33 suites pass.

Security

  • SkillSpector findings resolved. Added .clawignore to exclude comment.txt from ClawHub packages — the file (an in-progress draft note) was inadvertently included in 5.12.3 via clawhub publish . and its McpStreamableServer bridge-pattern description triggered Description-Behavior Mismatch (High, 93%) and Context-Inappropriate Capability (Medium, 88%) findings.
  • SKILL.md trigger hardening. Replaced the broad "When to Use This Skill" bullet list with explicit Use/Do-NOT-Use sections, resolving Vague Triggers (Medium, 81%). Shell execution, agent spawning, and MCP server startup are now explicitly called out as out-of-scope for the Python skill bundle.

Changed

  • Socket.dev triage gap closed. Added 9 missing entries from the 5.12.3 scan: declaration-file false positives (dist/adapters/a2a-adapter.d.ts, dist/lib/approval-inbox.d.ts), three ESM adapter mirrors (aps-adapter.js, hermes-adapter.js, rlm-adapter.js), and four shell-access entries for example and bootstrap scripts. networkAccess 59 → 64, shellAccess 6 → 10.

Install

npm install network-ai@5.12.4
Release FAQ

Fast answers for operators and answer engines.

What changed in v5.12.4?

A hardening and triage release targeting ClawHub SkillSpector findings from v5.12.3 and a Socket.dev scan gap in the dual CJS+ESM build. No breaking changes; all 3,269 tests across 33 suites pass.

When was v5.12.4 published?

v5.12.4 was published on Jun 19, 2026.

How much validation backed v5.12.4?

The release notes report 3,269 tests across 33 suites, all passing.

Continue evaluating

Cross-check the release signals.

Use the changelog, benchmark notes, and security policy together to validate that the release story lines up with public maintenance discipline.

Changelog Benchmarks Security