- Initial release
- markdown.new proxy integration for clean web content extraction
- Prompt injection protection with 6 core defense rules
- Safe error handling — no unsafe fallbacks to direct downloads or blind API calls
- Silent injection handling to prevent side-channel exploitation
- Chained fetch protection — agent only fetches user-provided URLs