Commit 3a50250
committed
utcp-http 1.1.3
Ships the OpenAPI converter defense-in-depth from e356ea7: a remote
spec can no longer declare a loopback ``servers[0].url`` to redirect
tool invocation at the agent's loopback interface. The runtime check
already shipped in 1.1.2; this just refuses the malicious tools at
conversion time so they never enter the registry.1 parent e356ea7 commit 3a50250
1 file changed
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
7 | | - | |
| 7 | + | |
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
| |||
0 commit comments