Network-AI
Release

v5.15.4 - ClawHub skill context-store hardening + HOL scanner CI

Published 2026-09-29 | Release notes

ClawHub skill: project-context memory poisoning fixed (scripts/contextmanager.py, A.I.G T02). init/update now validate and reject unsafe values before writing, with per-section type checks. Every field and key is scanned

Read the release here or open the original release on GitHub.

Security

  • ClawHub skill: project-context memory poisoning fixed (scripts/context_manager.py, A.I.G T02). init/update now validate and reject unsafe values before writing, with per-section type checks. Every field and key is scanned for injection and role/prompt-delimiter patterns, with length, depth, count, and size caps. inject blocks on any warning and emits single-line values inside a <project_context type="reference-data"> block that marks them as data, not instructions.

Changed

  • scripts/check_permission.py: docstring and --help describe an advisory local scorer that holds no credentials; --confirm-high-risk help lists PAYMENTS, DATABASE, and FILE_EXPORT.
  • SKILL.md: allowed-tools limits the skill to its six bundled scripts plus Read. Capabilities declare only NETWORK_AI_ENV, no shell, no ports, and no autonomous actions. Unpinned npx commands removed. New Bundled Script Inventory.
  • .clawhubignore excludes Python bytecode caches.

CI

  • New HOL plugin-scanner workflow on every push and PR, using the same gate as the awesome-ai-plugins listing (score >= 80, fail on high, repository policy not trusted). Read-only permissions, SHA-pinned actions.

Tests

  • 3,679 tests across 41 suites; tsc --noEmit clean. Local HOL scan: 95/100, no high findings.

Full changelog: https://github.com/Jovancoding/Network-AI/compare/v5.15.3...v5.15.4

Release FAQ

Fast answers for operators and answer engines.

What changed in v5.15.4?

ClawHub skill: project-context memory poisoning fixed (scripts/contextmanager.py, A.I.G T02). init/update now validate and reject unsafe values before writing, with per-section type checks. Every field and key is scanned

When was v5.15.4 published?

v5.15.4 was published on Sep 29, 2026.

How much validation backed v5.15.4?

The release notes report 3,679 tests across 41 suites, all passing.

Continue evaluating

Cross-check the release signals.

Use the changelog, benchmark notes, and security policy together to validate that the release story lines up with public maintenance discipline.

Changelog Benchmarks Security