Highlights
Auth Bypass: 1 prior fix. Scrutinize any change in this area.
src/partners/tools.ts: most-fixed (1 issue). Treat as high-risk during review.
1 high-severity fix in this history; regressions here are high-impact.
Recurring patterns
The bug types that recur here, drawn from past fixes, not open vulnerabilities.
Path Traversal: Dynamic route parameters resolved in the Predexon agent tool runner could allow directory traversal, enabling attackers to escape the safe folder boundaries if inputs are not canonicalized and checked against allowed prefixes.
Auth Bypass: During proxy startup, EADDRINUSE errors could lead to silent reuse of an existing port without verifying that its underlying payment chain matches the requested chain, allowing bypass of payment requirements.
Information Disclosure: Error messages formatted from URLs inside the viem dependency could expose raw usernames and passwords if they are not explicitly stripped before formatting or logging.