{
  "$schema": "https://verifymcp.io/schemas/changelog.json",
  "server": "spreadzp-agentbadge",
  "component": "agentbadge-mcp",
  "generated_at": "2026-09-29T15:02:17.960Z",
  "tracking_since": "2026-09-24",
  "counts": {
    "critical": 2,
    "security": 5,
    "functional": 0,
    "cosmetic": 0
  },
  "events": [
    {
      "id": "chg_01a0d953-c275-72d9-a30d-9b37fde93ab4",
      "kind": "check.reverified",
      "family": "tool-safety-injection",
      "subject_kind": "check",
      "subject": "tool-safety-injection",
      "subject_child": "",
      "from_code": "toolsafety.sandbox_pending",
      "to_code": "toolsafety.injection_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-25",
      "occurred_at": "2026-09-25 16:08:59.655184+00",
      "observed_since": "2026-09-24",
      "source": "scan",
      "summary": "Injection markers (unverified → pass)",
      "link": "https://verifymcp.io/servers/spreadzp-agentbadge/agentbadge-mcp#chg-chg_01a0d953-c275-72d9-a30d-9b37fde93ab4"
    },
    {
      "id": "chg_01a0d953-c276-70f2-80fa-78c1697733fe",
      "kind": "check.appeared",
      "family": "tool-safety-manipulation",
      "subject_kind": "check",
      "subject": "tool-safety-manipulation",
      "subject_child": "",
      "from_code": null,
      "to_code": "toolsafety.manipulation_clean",
      "from_value": null,
      "to_value": "pass",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "units": "39",
        "judged": "39"
      },
      "occurred_on": "2026-09-25",
      "occurred_at": "2026-09-25 16:08:59.655184+00",
      "observed_since": "2026-09-24",
      "source": "scan",
      "summary": "First check of Judged manipulation (pass)",
      "link": "https://verifymcp.io/servers/spreadzp-agentbadge/agentbadge-mcp#chg-chg_01a0d953-c276-70f2-80fa-78c1697733fe"
    },
    {
      "id": "chg_01a0d953-c27d-7397-b503-e0521309d01f",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_pending",
      "to_code": "stability.insufficient_history",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-25",
      "occurred_at": "2026-09-25 16:08:59.655184+00",
      "observed_since": "2026-09-24",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: not enough scan history yet (needs a 30-day window).)",
      "link": "https://verifymcp.io/servers/spreadzp-agentbadge/agentbadge-mcp#chg-chg_01a0d953-c27d-7397-b503-e0521309d01f"
    },
    {
      "id": "chg_01a0d74f-bb75-7890-ab9d-119156c7ad7a",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.unpatched_critical",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "critical",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "@agentbadge/hedera-core > @hashgraph/sdk > @grpc/grpc-js",
        "refs": "[\"CVE-2026-41242\"]",
        "seen": "257",
        "package": "@grpc/grpc-js",
        "version": "1.12.6",
        "assessed": "254",
        "resolved": "253",
        "severity": "high",
        "transitive": "5",
        "unresolved": "4",
        "vulnerable": "[{\"name\":\"@grpc/grpc-js\",\"version\":\"1.12.6\",\"depth\":3,\"path\":[\"@agentbadge/hedera-core\",\"@hashgraph/sdk\",\"@grpc/grpc-js\"],\"refs\":[\"CVE-2026-48068\",\"CVE-2026-48069\"]},{\"name\":\"elliptic\",\"version\":\"6.6.1\",\"depth\":9,\"path\":[\"@agentbadge/hedera-core\",\"@hashgraph/sdk\",\"@ethersproject/abi\",\"@ethersproject/hash\",\"@ethersproject/abstract-signer\",\"@ethersproject/abstract-provider\",\"@ethersproject/transactions\",\"@ethersproject/signing-key\",\"elliptic\"],\"refs\":[\"CVE-2025-14505\"]},{\"name\":\"protobufjs\",\"version\":\"8.0.0\",",
        "no_fix_refs": "[\"CVE-2025-14505\"]",
        "tree_source": "registry",
        "tree_status": "partial"
      },
      "occurred_on": "2026-09-25",
      "occurred_at": "2026-09-25 06:45:21.682115+00",
      "observed_since": "2026-09-24",
      "source": "scan",
      "summary": "Known CVEs (unverified → fail)",
      "link": "https://verifymcp.io/servers/spreadzp-agentbadge/agentbadge-mcp#chg-chg_01a0d74f-bb75-7890-ab9d-119156c7ad7a"
    },
    {
      "id": "chg_01a0d74f-bb78-74cc-ad17-f4f317968125",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-41242",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.unpatched_critical",
      "from_value": null,
      "to_value": "high",
      "materiality": "critical",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-41242",
        "severity": "high"
      },
      "occurred_on": "2026-09-25",
      "occurred_at": "2026-09-25 06:45:21.682115+00",
      "observed_since": "2026-09-24",
      "source": "scan",
      "summary": "CVE-2026-41242 affects this package (high)",
      "link": "https://verifymcp.io/servers/spreadzp-agentbadge/agentbadge-mcp#chg-chg_01a0d74f-bb78-74cc-ad17-f4f317968125"
    },
    {
      "id": "chg_01a0d74f-bb78-7a79-ae2d-6681c03c2782",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_pending",
      "to_code": "stability.sandbox_failed",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "reason": "not_attempted",
        "status": "unreachable"
      },
      "occurred_on": "2026-09-25",
      "occurred_at": "2026-09-25 06:45:21.682115+00",
      "observed_since": "2026-09-24",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: our sandbox could not run this package, so we have no schema to compare.)",
      "link": "https://verifymcp.io/servers/spreadzp-agentbadge/agentbadge-mcp#chg-chg_01a0d74f-bb78-7a79-ae2d-6681c03c2782"
    },
    {
      "id": "chg_01a0d74f-bb79-71fe-8f3d-e171750d34e8",
      "kind": "check.reason",
      "family": "tool-safety-injection",
      "subject_kind": "check",
      "subject": "tool-safety-injection",
      "subject_child": "",
      "from_code": "toolsafety.sandbox_pending",
      "to_code": "toolsafety.sandbox_failed",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "reason": "not_attempted",
        "status": "unreachable"
      },
      "occurred_on": "2026-09-25",
      "occurred_at": "2026-09-25 06:45:21.682115+00",
      "observed_since": "2026-09-24",
      "source": "scan",
      "summary": "Tool safety (Tool safety not yet verified: our sandbox could not run this package, so we have no tool text to scan.)",
      "link": "https://verifymcp.io/servers/spreadzp-agentbadge/agentbadge-mcp#chg-chg_01a0d74f-bb79-71fe-8f3d-e171750d34e8"
    }
  ],
  "days": [
    {
      "date": "2026-09-28",
      "total": 0,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-25",
      "total": 0,
      "delta": -28,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 20
    },
    {
      "date": "2026-09-24",
      "total": 28,
      "delta": null,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 0
    }
  ]
}