---
summary: "mcp-ts-core ^0.10.6 → ^0.10.9 maintenance — ctx.content media collector, Canvas SQL invalid_sql classification, fresh-scaffold devcheck guards; new dependency-specifier + plugin-manifest packaging checks; skills + scripts re-synced; .codex-plugin longDescription filled"
breaking: false
security: false
---

# 0.1.11 — 2026-06-20

## Changed

- **`@cyanheads/mcp-ts-core` `^0.10.6` → `^0.10.9`** — adopts the 0.10.7–0.10.9 framework line:
  - **`ctx.content`** — new always-present collector on `Context` for non-text content blocks; `ctx.content.image(data, mimeType)` / `.audio(data, mimeType)` push base64 media that rides `content[]` only and never duplicates into `structuredContent`.
  - **Canvas SQL gate** — a `SELECT`/`WITH` statement that parses but fails to prepare (mistyped column, unknown function) now throws `ValidationError` with `data.reason: 'invalid_sql'` and the DuckDB binder detail in `data.binderMessage`, instead of the misleading `non_select_statement`.
  - **`DuckdbProvider.describe({ tableName })`** — qualified the pushed `WHERE` filters with the `t` alias, fixing the ambiguous-column Binder Error on every filtered `describe()`.
  - **Fresh-scaffold devcheck robustness** — changelog-sync and git-dependent checks (TODOs, Tracked Secrets, Framework Antipatterns, Skill Versions) now skip cleanly when run before `git init` rather than failing.
  - **`OTEL_SERVICE_NAME`** — docs corrected: `createApp({ name })` seeds it only when unset (precedence env → `createApp` name → `package.json` name). No behavior change.
- **`devcheck.config.json`** — added `packaging.pluginManifests: true`, enabling the framework's new `lint:packaging` check 10 (validates `.claude-plugin/plugin.json`, `.codex-plugin/plugin.json`, `.codex-plugin/mcp.json` for non-empty descriptions, unscoped display names, and the full scoped `npx -y` install arg).
- **`.codex-plugin/plugin.json`** — filled the empty `interface.longDescription` with the tool-surface summary (datasets, variable search, geography resolution, query, compare).
- **`scripts/` re-synced from the framework** — `check-dependency-specifiers.ts` added (new `Dependency Specifiers` devcheck step: hard-fails on floating `latest`/`*`/dist-tag specifiers in `package.json` and `bun.lock` workspaces); `build-changelog.ts`, `check-framework-antipatterns.ts`, `check-skill-versions.ts`, `devcheck.ts`, and `lint-packaging.ts` picked up the 0.10.7–0.10.9 guard and skip-on-fresh-scaffold changes.
- **14 `skills/` files re-synced** to their upstream `metadata.version` and body updates, mirrored into `.claude/skills/` and `.agents/skills/`.

### Dependency bumps

- `@cyanheads/mcp-ts-core` `^0.10.6` → `^0.10.9`
- `@biomejs/biome` `^2.4.16` → `^2.5.0`
- `@types/node` `^25.9.3` → `^26.0.0`
- `vitest` `^4.1.8` → `^4.1.9`
