| Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search |
| Name: skillspector-mcp | Distribution: openSUSE Tumbleweed |
| Version: 2.9.6 | Vendor: openSUSE |
| Release: 1.1 | Build date: Thu Aug 20 20:46:27 2026 |
| Group: Unspecified | Build host: reproducible |
| Size: 0 | Source RPM: skillspector-2.9.6-1.1.src.rpm |
| Packager: https://bugs.opensuse.org | |
| Url: https://github.com/NVIDIA/skillspector | |
| Summary: MCP server mode for SkillSpector | |
This subpackage enables the Model Context Protocol (MCP) server mode of SkillSpector, exposed through the "skillspector mcp" subcommand. It pulls in the optional MCP runtime dependency so the FastMCP-based server can be started for local CLI agents or over HTTP.
Apache-2.0
* Thu Aug 20 2026 Martin Pluskal <mpluskal@suse.com>
- Update to version 2.9.6:
* MCP registry posture scanning
* Ollama, Azure OpenAI, and generic OpenAI-compatible providers
* Opt-in discovery of an author-shipped baseline
(.skillspector-baseline.yaml)
* Detect insecure deserialization (AST10, TT6, DS1-DS4)
* Detect whitespace-padding prompt injection (P9)
* HIGH SC8 when a skill ships __pycache__ or .pyc
* Bound URL, zip and git ingest to limit resource exhaustion
* SC4 reports only verified OSV hits; use lockfile versions
* HTTP MCP rejects local filesystem targets and local YARA dirs
* Reject symlink traversal in skill content; disable git
symlinks on clone
* PE3 no longer flags ordinary OAuth "access token"
documentation
* LLM analyzers retry or isolate malformed responses and
connection failures; incomplete analysis is recorded as
skipped
* Reduce false positives (instructional prose, Markdown
tables, JS RegExp.exec, negated safety constraints, OMS
signatures)
* Map YARA matches via byte offsets; scope the locality guard
to the built-in rule namespace
- Switch source to the official GitHub release tarball
- Drop _service, skillspector-2.5.1.obscpio and
skillspector.obsinfo
- Add packaging >= 24.0 (requirement parsing for OSV lookups)
* Tue Aug 04 2026 Martin Pluskal <mpluskal@suse.com>
- Update to version 2.5.1 (first tagged releases; switches the package
from a pinned git snapshot to the upstream release tags):
* Canonical inspection-ledger reporting: JSON and SARIF reports now
carry execution-completeness and analyzer status, so a consumer
can distinguish a clean zero-finding scan from one that did not
execute reliably
* SKILLSPECTOR_MAX_LLM_CONCURRENCY serializes or bounds asynchronous
LLM analyzer batches for rate-limited providers
* Read exact versions from Python lockfiles for OSV lookups
* Exclude valid OMS signatures from content analysis
- Ship the wheel metadata under the release version again: upstream's
pyproject version now matches the tag, so the dist-info glob follows
the package version
* Fri Jul 03 2026 Martin Pluskal <mpluskal@suse.com>
- Relax over-strict dependency floors set by upstream at initial
release (pin-inflation, not API requirements; the code only uses
long-stable APIs of all three):
* pydantic >= 2.12.0 -> 2.11.7
* rich >= 14.3.0 -> 14.0.0
* typer >= 0.23.0 -> 0.16.0
- Verified against Leap 16.0's shipped versions (pydantic 2.11.7,
rich 14.0.0, typer 0.16.0, click 8.2.1, Python 3.13): full
offline unit suite passes (1249 passed, 12 skipped, 6 xfailed)
and the CLI entry point works.
* Wed Jul 01 2026 Martin Pluskal <mpluskal@suse.com>
- Switch source acquisition to an obs_scm git snapshot of upstream
main: NVIDIA/skillspector publishes no git tags, no GitHub releases
and nothing on PyPI, so no downloadable release tarball exists
- Version changed from 2.3.10 (a locally-built sdist that exists
nowhere upstream) to the snapshot 2.3.9~git20260701.326a2b48
(upstream main HEAD, commit 326a2b48)
- Add _service; drop the hand-built skillspector-2.3.10.tar.gz
* Mon Jun 29 2026 Martin Pluskal <mpluskal@suse.com>
- Use %{primary_python} instead of a hardwired python flavor
* Sun Jun 28 2026 Martin Pluskal <mpluskal@suse.com>
- Initial package skillspector 2.3.10 (CLI scanner; -mcp subpackage
for the MCP server)
- Enable the pytest test suite now that the full langchain/langgraph
runtime stack is packaged; the offline unit tests run at build time
(integration/provider markers and four SSRF allowed-host tests that
require live DNS are deselected)
Generated by rpm2html 1.8.1
Fabrice Bellet, Sun Aug 23 00:03:09 2026