0.12.3

Security patch: a `__proto__` member in received data no longer picks an object's prototype

A security patch. All six packages move to 0.12.3 together. The spec revision stays 1.0.0-draft.8. Details are in the advisory, GHSA-4pcf-49g3-h325: who is affected, workarounds, and what isn’t covered.

What changed

  • @silverprotocol/core requires zod 4.4.0 or later. With an older zod, AgEvent.parse() could give a received ext.* event a prototype taken from its own __proto__ member. Three side effects:
    • An application that pins an older zod for itself gets a second copy of zod for core.
    • An application that combines core’s exported schemas with its own zod should move its own zod to 4.4.0 or later.
    • overrides or resolutions that force zod below 4.4.0 defeat the requirement. Remove them, or decode with ingestAgEvent().
  • Claude Agent SDK: a model name in the native modelUsage no longer sets the prototype of usage.byModel or of modelUsage in ext.anthropic.result-meta, and a supersedes list is copied like the other carries.
  • Vercel AI SDK: an emitted value never holds a member named __proto__, at any depth, and a step’s stop details in message.metadata no longer take their prototype from one; the members beside it are carried as before.
  • Google ADK: a member named __proto__ in a native is dropped at every depth, and the unparsed-native carry no longer takes its prototype from one.
  • OpenAI Agents SDK: a host error’s usage reaches turn.error copied, without an own __proto__ key; a well-formed usage is unchanged. A host usage that isn’t a valid usage once that key is dropped is no longer put on turn.error; it rides ext.openai.unparsed instead.

What to do

  1. Upgrade every @silverprotocol/* package to 0.12.3, including where another package pins one (check your lockfile).
  2. If your application decodes received events with AgEvent.parse() or ingestAgEvent(), upgrade core now. Versions of core before 0.6.4 are being deprecated on npm.
  3. Review the advisory for what to check in application code that copies values taken from events.