v5.15.3 - per-instance orchestrator token
Public hardcoded orchestrator token replaced with per-instance secrets. The orchestrator's full-access blackboard identity used the constant 'system-orchestrator-token', also hardcoded in bin/mcp-server.ts, TaskDecompose
Security
- Public hardcoded orchestrator token replaced with per-instance secrets. The orchestrator's full-access blackboard identity used the constant
'system-orchestrator-token', also hardcoded inbin/mcp-server.ts,TaskDecomposer, andControlMcpTools. EachSwarmOrchestratornow generates a random token; the old string no longer authenticates anywhere. Not remotely exploitable on its own, since MCP transports already require the bearer secret or local stdio. - MCP server-held identity.
network-ai-serverwrites on behalf of admitted callers via the newcreateServerIdentityBlackboard(). Transport authentication is the trust boundary, and eachagent_idis recorded as the entry's source agent.
Fixed
- Over MCP, every normal
agent_idwas rejected with a namespace error; only impersonatingorchestratorwith the public token worked. Anyagent_idnow works as documented.
Migration
- MCP clients: no change needed. Callers still sending
agent_token: "system-orchestrator-token"keep working; the server ignores caller-supplied tokens. - Library code that passed the literal string to
SharedBlackboard.write()must use its ownregisterAgent()token.
Changed
scripts/clawhub-publish.jsreads git provenance withexecFileSync(no shell strings).- Added
.plugin-scanner.tomlfor the HOL plugin-scanner (excludes only test fixtures and docs). Score 95/100, no high or critical findings.
3,679 tests across 41 suites.
Full changelog: https://github.com/Jovancoding/Network-AI/blob/main/CHANGELOG.md