Skip to content
Proposals/Audit security updates in SDK v0.0.67
proposalteamP5Worth a lookCline

Audit security updates in SDK v0.0.67

Reasoning controls (effort, budget, on/off) are now driven by the models.dev catalog and normalized once before provider encoding, so requests match what each provider actually advertises; · Anthropic's mandatory and impossible thinking modes are handled explicitly, and out-of-ra

Why this loop

Release: SDK v0.0.67 Detail: Reasoning controls (effort, budget, on/off) are now driven by the models.dev catalog and normalized once before provider encoding, so requests match what each provider actually advertises; · Anthropic's mandatory and impossible thinking modes are handled explicitly, and out-of-range budgets are clamped · OpenRouter now defaults to anthropic/claude-sonnet-5 · +14 more changes Themes: mcp, model, security Config surfaces changed: MCP server config Developer angle: Try in a throwaway repo before changing daily workflow. Team angle: Pilot / sandbox / policy review before org rollout. Source: https://github.com/cline/cline/releases/tag/sdk/sdk/v0.0.67

Proposed actions

  1. Review the MCP server config config for Cline to verify the changes don't break your workflow.
  2. Read the release notes for Cline sdk/sdk/v0.0.67 to understand the full scope of the update.

Agent prompt

Paste into your agent or query via MCP (get_agent_prompt) — free, no extra AI cost

Cline / .clinerules task

DevAgentRadar → Cline

You are helping me adopt a real coding-assistant change. Work only from the facts below. Do not invent features.

Context

Assistant: Cline Proposal: Audit security updates in SDK v0.0.67 Summary: Reasoning controls (effort, budget, on/off) are now driven by the models.dev catalog and normalized once before provider encoding, so requests match what each provider actually advertises; · Anthropic's mandatory and impossible thinking modes are handled explicitly, and out-of-ra Primary source: https://github.com/cline/cline/releases/tag/sdk/sdk/v0.0.67

Why it matters

Release: SDK v0.0.67 Detail: Reasoning controls (effort, budget, on/off) are now driven by the models.dev catalog and normalized once before provider encoding, so requests match what each provider actually advertises; · Anthropic's mandatory and impossible thinking modes are handled explicitly, and out-of-range budgets are clamped · OpenRouter now defaults to anthropic/claude-sonnet-5 · +14 more changes Themes: mcp, model, security Config surfaces changed: MCP server config Developer angle: Try in a throwaway repo before changing daily workflow. Team angle: Pilot / sandbox / policy review before org rollout. Source: https://github.com/cline/cline/releases/tag/sdk/sdk/v0.0.67

Suggested actions

  1. Review the MCP server config config for Cline to verify the changes don't break your workflow.
  2. Read the release notes for Cline sdk/sdk/v0.0.67 to understand the full scope of the update.

Config surfaces this release may change

  • MCP servers (high confidence) — check your repo before applying
  • skills — check your repo before applying
  • sandbox settings — check your repo before applying

After you finish

Do not report this as applied to DevAgentRadar. You cannot write the visitor's loop.

Tell the human: open https://devagentradar.com/proposals/cline-sdk-sdk-v0-0-67-audit-security-updates-in-sdk-v0-0-67 and mark Applied, Skipped, or Failed. Proposal id: 26cb1432-e630-4b42-93b2-a275ee18cd8d

Your job

  1. Restate the change in one sentence.
  2. Propose a minimal plan for my repo (or a throwaway pilot).
  3. Implement only what I approve; prefer small diffs and tests.
  4. Call out risks (permissions, breaking APIs, cost).

Start by confirming you understood the proposal.

mcpmodelsecurityRelease source ↗

Your loop

This browser · no sign-in · not shared as “you”

After you run the prompt

Only you can mark this. Agents cannot write your loop.

Your decision stays on this device. A public tally appears after a few votes.

Originating release signal

ClineSDK 0.0.67Jul 31, 2026

SDK v0.0.67

Reasoning controls (effort, budget, on/off) are now driven by the models.dev catalog and normalized once before provider encoding, so requests match what each provider actually advertises; · Anthropic's mandatory and impossible thinking modes are handled explicitly, and out-of-range budgets are clamped · OpenRouter now defaults to anthropic/claude-sonnet-5 · +14 more changes
Verified excerpt — the source's own words
  • Reasoning controls (effort, budget, on/off) are now driven by the models.dev catalog and normalized once before provider encoding, so requests match what each provider actually advertises; Anthropic's mandatory and impossible thinking modes are handled explicitly, and out-of-range budgets are clamped
  • OpenRouter now defaults to anthropic/claude-sonnet-5
  • The per-server timeout in cline_mcp_settings.json is now honored by the SDK's MCP clients for initialize, tools/list, and tools/call instead of hardcoded 1.5s and 5s limits — it defaults to 60 seconds and is clamped to 1–3600 seconds
  • Fixed the China and international endpoint toggles being ignored for Qwen, Moonshot, and Z AI
  • Legacy API keys are now migrated for every secret-backed provider instead of a subset
  • Legacy OpenAI Compatible model-info overrides are now carried into the seeded models.json instead of being dropped
  • Removed the "Enable R1 messages format" option from the OpenAI Compatible provider
  • Fixed checkpoint restores across session resumes

Excerpt ends here — this release continues at the source ↗.

Primary source ↗