---
summary: "Adopts mcp-ts-core 0.13.6: argument rejections return InvalidParams with a recovery hint, sessionMode is declared in src/, and the skill tree moves to framework-skills/ so installing the plugin no longer leaks development skills. Carries the SSRF, ReDoS, and rate-limit-key security fixes; raises the Bun floor to >=1.4.0."
breaking: true
security: true
---

# 0.1.9 — 2026-09-20

## Changed

- **`@cyanheads/mcp-ts-core` `^0.12.3` → `^0.13.6`** — an argument rejection now returns `-32602` (`InvalidParams`) instead of `-32007` (`ValidationError`), carrying `structuredContent.error`, `data.reason: "invalid_arguments"`, and a schema-derived `Recovery:` hint naming the keys the tool accepts. A tool error's rendered text closes with `(reason <reason>)`, extended to `(reason <reason> · not retryable)` when the error also declares `retryable`. An undeclared argument key whose case-folded form names exactly one declared key is rewritten onto it.
- **`createApp({ sessionMode: 'stateless' })` declared in `src/index.ts`** — pins the HTTP session posture in code rather than leaving it to `MCP_SESSION_MODE` alone; `/.well-known/mcp.json` now publishes the resolved mode under `_meta`.
- **`thrownBy: 'service'` on each tool's `upstream_error`/`auth_failed` error-contract entries** — lint-only metadata marking reasons the service layer throws, so `error-contract-unthrown` no longer needs the handler's own literal `ctx.fail` calls to cover them.
- **Skill tree moved `skills/` → `framework-skills/`** — Claude Code and Codex auto-load a plugin's root `skills/`, so shipping `.claude-plugin/`/`.codex-plugin/` alongside it handed development skills to every installing agent.
- **Plugin manifests wire `OPENCHARGEMAP_API_KEY` through `user_config`/`env_vars`** — the Claude plugin declares it under `userConfig` and references `${user_config.OPENCHARGEMAP_API_KEY}`; the Codex plugin forwards it via `env_vars` instead of an inlined `${…}` placeholder.
- A caller disconnect or cancelled request classifies `RequestCancelled` (`-32011`) instead of `InternalError`. Upstream `500`/`501` classify as `ServiceUnavailable` (a `500` now retries) and a `3xx` maps to `InvalidRequest`.

## Security

- Carries `@cyanheads/mcp-ts-core`'s SSRF DNS-resolver guard fix (queries both `node:dns` resolvers, closing a Bun 1.4 Linux bypass), five polynomial-time ReDoS replacements, an empty rate-limit-key eviction fix, and the removal of the upstream request URL from client-facing error data by default.
- **`engines.bun` floor raised to `>=1.4.0`** (was `>=1.3.0`) — required by the framework's mirror driver fix; a consumer on an older Bun must upgrade.

## Dependencies

- `@cyanheads/mcp-ts-core` ^0.12.3 → ^0.13.6
- `zod` ^4.4.3 → ^4.6.5
- `@biomejs/biome` ^2.5.10 → ^2.5.14 (dev)
- `@types/node` ^26.2.0 → ^26.6.1 (dev)
- `@vitest/coverage-istanbul` 4.1.11 → 5.0.1 (dev)
- `vitest` ^4.1.11 → ^5.0.1 (dev)
- `fast-check` ^4.9.0 → ^4.10.1 (dev)
- `ignore` ^7.0.6 → ^7.0.9 (dev)
- `tsc-alias` ^1.9.2 → ^1.9.5 (dev)
