Skip to content

Security remediation: encrypt CLI keystore and harden MCP launch - #4

Draft
coinsecuritiescompany wants to merge 19 commits into
mainfrom
security/audit-2026-08-06-remediation
Draft

Security remediation: encrypt CLI keystore and harden MCP launch#4
coinsecuritiescompany wants to merge 19 commits into
mainfrom
security/audit-2026-08-06-remediation

Conversation

@coinsecuritiescompany

@coinsecuritiescompany coinsecuritiescompany commented Aug 7, 2026

Copy link
Copy Markdown

Release-candidate scope

  • AES-256-GCM keystore, atomic writes and strict permissions;
  • no private-key argv import; legacy plaintext migration;
  • verified release checksums and hardened MCP launch;
  • quote-split --include-creator forwards the optional creator-fee choice;
  • README no longer claims live multi-chain settlement.

Evidence

Candidate SHA: 7a87ad8294bc3e06054e7364c8e3bf23f67dde54

GitHub CI run 31280971995 — success.

Release boundary

No package publication or deployment is included. Final MCP version pin and release artifact publication remain a coordinated release step after SDK review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant