Skip to content

[suggestion] semble install should set exact versions for uvx commands #186

@VanTanev

Description

@VanTanev

Currently, semble install will set the mcp as uvx --from 'semble[mcp]' semble, and will suggest uvx fallbacks in AGENTS.md and subagents.

This, however, leaves users vulnerable to supply chain attacks. If someone takes over the package, agents will install and execute the compromised package.

Semble install should pin to its own version.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions