Network-AI
Release

v5.13.3 - ClawHub publish script + SkillSpector YARA fix

Published 2026-06-26 | Release notes

SkillSpector YARA agentskillmcptoolpoisoningmetadata — Reworded the audit-log privacy note in SKILL.md that was triggering the exfiltration sub-rule. No functional change; VirusTotal 64/64 clean.

Read the release here or open the original release on GitHub.

What's changed

Fixed

  • SkillSpector YARA agent_skill_mcp_tool_poisoning_metadata — Reworded the audit-log privacy note in SKILL.md that was triggering the exfiltration sub-rule. No functional change; VirusTotal 64/64 clean.
  • CodeQL js/redundant-operation (alert #178) — Split an &&-chained double-call to RetryBudget.tryConsume() in test-phase15.ts into two explicit assertions.
  • ClawHub display name — Corrected to "Network-AI" (a temp staging directory name leaked as the display name in the first patch publish).

Added

  • npm run clawhub:publish — New publish script (scripts/clawhub-publish.js) that automates the ClawHub staging workaround required since CLI v0.23+. Reads version from skill.json, pulls git provenance automatically, always publishes with --name "Network-AI", and cleans up after itself.
  npm run clawhub:publish
  npm run clawhub:publish -- --changelog "what changed"
  npm run clawhub:publish -- --dry-run

_Patch release — no API or behaviour changes. All 3,373 tests pass._

Release FAQ

Fast answers for operators and answer engines.

What changed in v5.13.3?

SkillSpector YARA agentskillmcptoolpoisoningmetadata — Reworded the audit-log privacy note in SKILL.md that was triggering the exfiltration sub-rule. No functional change; VirusTotal 64/64 clean.

When was v5.13.3 published?

v5.13.3 was published on Jun 26, 2026.

How much validation backed v5.13.3?

The release notes report 3,373 tests, all passing.

Continue evaluating

Cross-check the release signals.

Use the changelog, benchmark notes, and security policy together to validate that the release story lines up with public maintenance discipline.

Changelog Benchmarks Security