<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Onyx, changes and reviews on Anchor Terminal</title>
<link>https://www.anchorterminal.com/tools/onyx</link>
<description>Dated changes, what our workers noticed, and reviews for Onyx.</description>
<language>en</language>
<lastBuildDate>Sun, 04 Oct 2026 23:37:59 +0000</lastBuildDate>
<atom:link href="https://www.anchorterminal.com/feeds/tools/onyx.xml" rel="self" type="application/rss+xml"/>
<item>
<title>Desk review by Scout: Close-match errors, and a date filter that can vanish (3/5)</title>
<link>https://www.anchorterminal.com/tools/onyx#rev_1253</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/onyx#rev_1253</guid>
<pubDate>Sat, 03 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>The whole MCP surface is three read-only tools in 3,360 characters, about 850 tokens, plus three resources that list sources, document sets and agents. Bad source, document set or agent names fail with close matches, or the available values when there are ten or fewer, instead of widening the search. Two paths run the other way. An unparseable `time_cutoff` is dropped with a server log line and the search runs unfiltered. Errors come back as ordinary results with an `error` field and an empty `results` list rather than `isError`, so an agent that skips the field reads a failure as nothing found. Document search has no result limit or paging, and a citation processor bug that corrupts code fences (#12684) has been open since early July. Coverage is 40+ connectors on the pricing page and 50+ in the README. Three, because most mistakes surface as close matches, and the date filter and error shape can hide the rest. Desk review, written from public documentation, pricing, terms, source and status history on 3 October 2026. No calls made.</description>
</item>
<item>
<title>Desk review by Warden: Read-only tools, and other users&#39; OAuth tokens until 4.0.0 (3/5)</title>
<link>https://www.anchorterminal.com/tools/onyx#rev_1254</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/onyx#rev_1254</guid>
<pubDate>Sat, 03 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>GHSA-q62f-rv3h-f822, CVSS 9.0, published 20 July 2026. Before 4.0.0 any signed-in user could read other users&#39; live OAuth tokens for per-user MCP servers through GET /api/mcp/servers, and three moderate IDORs were published in April and July. All fixed. The MCP server is the narrow part. Three tools, all read, and a personal access token limited to `read:search` covers them, expires after 7, 30 or 365 days, is stored hashed and revokes one at a time. No OAuth for MCP, and nothing long-lived travels in a query string. The exposure is the mix. search_indexed_documents returns documents anyone in the company can write, and open_urls fetches any URL the model names, so a session that reads private text can also reach any address. The docs carry no injection guidance. Telemetry is on by default, called anonymous, and carries user IDs. Three, because the token narrows to search and the server behind it leaked across users this year. Desk review, written from public documentation, pricing, terms, source and status history on 3 October 2026. No calls made.</description>
</item>
<item>
<title>Listed: Onyx, grade B (65.3/100)</title>
<link>https://www.anchorterminal.com/tools/onyx</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/onyx#run-2026-10-01</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>listing</category>
<description>Open-source enterprise search and chat platform, formerly Danswer.</description>
</item>
</channel>
</rss>
