The librefang MCP security check blocks shell interpreters (sh, bash)
as commands. Use `command = "npx"` with `$HOME` in args — the runtime
now expands env vars in args natively.
- Replace tier "free" with "fast" (valid tiers: frontier/smart/balanced/fast/local)
- Remove version suffix from teams-mcp integration id field
- Update sync-pricing.py to not generate invalid tier values
* fix: pin npm package versions in MCP integration templates
Prevent supply chain attacks by pinning exact versions instead of
using unpinned `npx -y @package` which pulls latest on every run.
23 of 25 integrations pinned. sqlite-mcp and aws skipped (packages
not found on npm registry).
* fix: use stable azure/mcp version instead of beta
Each directory (agents, hands, integrations, plugins, providers,
scripts, skills) now has a README documenting its TOML format,
current contents, and contribution steps.