May 28, 2026
Android APK research capability and issue-tracker connectors for web-security
← All updates
Android APK research capability and issue-tracker connectors for web-security
7 new 3 improved 9 fixed
New capability bundles for Android APK research and issue-tracker integrations land alongside a full sweep of assistant-led CLI guides across the platform.
New
- Android APK research capability. A new
android-apk-researchcapability bundle ships with a 10-tool MCP server and four skills for static semantic vulnerability research on Android APKs. - Jira connector for web-security. Web-security agents can now export validated findings directly to Jira Cloud as remediation tickets via a new Jira MCP connector.
- GitHub connector for web-security. A new GitHub MCP connector lets web-security agents file findings as GitHub issues and add follow-up comments without leaving the agent workflow.
- Run artifact logging tools. Web-security agents can now attach screenshots, audio, video, and file artifacts directly to a run using four new path-based logging tools:
log_image_output,log_audio_output,log_video_output, andlog_file_artifact. - IDOR/BOLA judge scorer rubric. A new built-in IDOR/BOLA rubric is available for the SDK’s default LLM judge scorer, with graduated pentest-aligned cross-boundary access criteria; the web-security scorer-reference skill documents how to compose it in
task.yamland SDK configs. - Activity feed on the home page. The home page now shows a live activity feed with recent projects, sessions, evaluations, training jobs, and other workspace activity.
- Administrators Can Now Control Which AI Models Members Use. Organization administrators can now grant each member access to a specific set of AI models, with the limits enforced automatically across the web app, API, and CLI.
Improvements
- Assistant-led CLI guides across all surfaces. Every in-product CLI guide (capability, task/environment, dataset, model, evaluation, optimization, world manifest, trajectory, training) is rewritten into a two-tab layout with an ‘Ask an agent’ tab, accurate
dnalias commands, and corrected flags. - CLI guide launcher button labels clarified. Launcher buttons across nine surfaces now use accurate action verbs (Create, Evaluate, Optimize, Train) instead of generic or incorrect labels.
- AIRT and Traces visual language overhaul. The AIRT Traces view and shared TraceViewer now use consistent design-system primitives, unified span-category colors, and a redesigned trace control bar.
Fixes
- Large-trajectory judge staging no longer fails. Outcome-judge staging no longer errors on large eval trajectories; the sandbox now fetches the trajectory directly via session ID instead of having it serialized and shipped by the API.
- Session transcripts no longer truncated. Session transcripts now load all messages via cursor pagination — previously, sessions with more than 2,000 messages were silently truncated, dropping the most recent ones.
dn task validateaccepts compound verification methods.dn task validatenow acceptsflag_and_judgeandscript_and_judge, fixing validation failures across 248 tasks.- TUI Ctrl+C now copies to clipboard. In the agent TUI, Ctrl+C copies selected text to clipboard (with fallback to pbcopy/xclip/xsel/wl-copy); use Ctrl+Q to quit.
- TUI hosted model list no longer shrinks after restart. New platform model deployments now appear in the TUI without manually deleting
~/.dreadnode/proxy-models.json. - TUI /models screen respects admin model ordering. The TUI
/modelsscreen now displays models in the order configured by your admin instead of re-sorting alphabetically. - TUI no longer crashes on mid-load screen navigation. The TUI no longer throws a
NoMatchesexception when navigating away from a screen while a background worker is still loading data. - Image files render correctly in the environment file viewer. Image files in the environment file viewer now render as images instead of garbled binary content.
- Linear MCP credentials now passed correctly.
LINEAR_API_KEY,LINEAR_ACCESS_TOKEN, andLINEAR_API_URLare now correctly forwarded to the Linear MCP server in the web-security capability.