Back to all releases
// October 2, 2026v1.35.2

Platform

Security and Policy

Reveal the evidence behind a finding from an MCP tool call, and risk policies apply only to their audience

A finding raised by an MCP tool call can now be opened to see the content that triggered it, the same as a finding raised in a chat. Reveal used to fail outright on those findings, so an investigation that started in Risk Events or the Watchdog drawer stalled at a masked value with nothing behind it. Risk policies scoped to an MCP server also stop over-reaching: a policy aimed at named users, roles, or agents no longer fires for every other caller of a matching tool. More on this in Risk events and Guardrails.

Features

  • Evidence behind an MCP tool-call finding can be revealed — Reveal a masked match on a finding that came from a tool call and see the content that matched, under the same chat:read check and the same audit entry as a chat finding. Findings recorded before this change read "Evidence not stored" rather than failing with an error. (#6946, @vishalg0wda)

Bug fixes

  • An MCP-scoped risk policy applies only to its audience — A policy targeted at specific users, roles, or agents no longer applies to other callers of a matching MCP tool, so a narrow policy stops producing findings for people it was never aimed at. (#7035, @vishalg0wda)
  • Prompt-based guardrails keep judging when provider credit runs low — The prompt-injection and prompt-policy judges are capped at 8192 completion tokens, so a model provider no longer refuses them outright when the remaining credit on a key sits below the model's full output ceiling. A credit refusal or a truncated completion now reports itself as such instead of a generic error. (#6999, @bradcypert)
Speakeasy Team
Speakeasy Team
View on GitHub