StackJack 0.1.0.5190+beafdc0
StackJack 0.1.0.5190+beafdc0
This release ships connector wave 5, adding fifteen new integrations and bringing the tool catalog past 16,000 tools. It also tightens safety on several delete and write tools, adds opt-in paging totals for PRTG list reads, and fixes a set of credential-handling problems including the automatic re-enabling of connectors that were disabled after token-refresh failures.
New features
- Fifteen new connectors. Acronis, AlertOps, Alloy Navigator, Axcient, CrowdStrike Falcon, Datto EDR, Dicker Data, GravityZone, Jamf, Petra, PRTG, RoboShadow, SentinelOne, Teramind and Yeastar are now available, each with a setup guide and a full tool catalog.
- PRTG paging totals on request. The sixteen paginated PRTG list tools accept a new optional
includeTotalsargument. When set, the response is wrapped in an envelope carrying the total count, the count on the current page and the next-page link, none of which previously reached the agent. When not set, the response is exactly what it was before. - Datto EDR forensic reads default to a sensible window. A forensic query that does not name a box now targets the tenant's global "Last 7 days" box, matching the vendor's own client, instead of searching everything. A box you supply yourself always wins. If no global box can be found, the read still runs unscoped.
Improvements
- Acronis filter-scoped deletes refuse to run without a selector. Deleting policies, resources, policy applications or alerts now requires a filter; a call with none would otherwise have been read by Acronis as "delete everything in reach".
- Dicker Data CSP cancellation requires a target. The cancel tool now refuses a call that supplies neither a subscription ID nor an order ID.
- Yeastar credential failures no longer risk locking you out. A definitive authentication refusal is remembered for fifteen minutes so repeated tool calls cannot walk the PBX into blocking the gateway's address. Saving new credentials clears the hold immediately.
- Tool safety classifications corrected. The CrowdStrike data-connection token regeneration tool, the AlertOps service update tool and the Yeastar extension update tool are now marked destructive and gated accordingly. The eight PRTG monitoring pause tools (sensor, device, group, probe and their filtered forms) are no longer marked destructive: a pause changes no stored configuration and its paired resume reverses it. Their descriptions still warn that a pause suppresses monitoring and alerting until resumed, and pausing a user account remains destructive.
- Automatic re-enable of auto-disabled connectors is now bounded and resettable. A connector credential that was auto-disabled after token-refresh failures is retried automatically for up to seven days, capped at three attempts. Saving new credentials, running Repair Users or reconnecting the connector resets that budget so a freshly fixed connector never starts out rate-limited.
- Clearer tool descriptions. PRTG's alarm list tool now explains the difference between its two "include" arguments; Datto EDR forensic tools describe the new default box; RoboShadow's MFA report documents its organization identifier accurately; and the Acronis agent-delete tools now cross-reference each other.
Bug fixes
- Auto-disabled connectors were never actually retried. The automatic re-enable path read its candidates in a way that excluded every disabled credential, so no retry ever left. It also wrongly treated the tenant's primary owner as a departed member and refused to re-enable their credential. Both are fixed.
- A departed team member's credential can no longer be re-enabled automatically. A credential belonging to a member who has been removed or deactivated is skipped, regardless of the order in which the disable and the deactivation happened.
- IRONSCALES classification tools now work with partner-level API keys. The permission scopes requested at connect time did not cover classification for some keys, so classification calls failed for exactly the keys most likely to use them.
- RoboShadow MFA report permission errors gave the wrong advice. A permission refusal on the MFA report was treated as an expired token: the connector re-minted a token, retried, and then told you to paste a new refresh token, which would not have helped. It is now reported as an organization-access problem with the correct guidance. The guidance text also no longer refers to a tool name that does not exist.
- Credential validation misread a definitive rejection as a network fault for several connectors. A clear authentication rejection during validation was being treated as a transient error, so the connector's health status did not reflect it.
- Datto EDR forensic reads cannot be failed by the default-box lookup. If the box lookup is refused or errors, the read still runs.
- Quieter, more accurate connector health reporting. Several noisy or misleading log conditions around auto-disabled credentials were corrected so genuine failures (such as a refresh token that was consumed but could not be saved) are surfaced instead of hidden.
Breaking changes
- Acronis tool renamed:
acronis_delete_agents_by_filteris nowacronis_delete_agent_by_id. Acronis requires an agent ID on this endpoint, so the tool has always deregistered exactly one agent; the old name implied a bulk sweep. Update any saved prompts or workflows that reference the old name. - Acronis tool removed:
acronis_delete_psa_sales_itemshas been withdrawn. It issued an unscoped delete against the entire PSA sales-items collection with no way to narrow it. - Unscoped Acronis filter deletes and Dicker Data CSP cancellations without a subscription or order ID are now refused (see Improvements). Agents that relied on the unscoped forms will receive an error instead.
Known issues
- Datto EDR record counts are not box-scoped.
dattoedr_count_recordscounts across the whole collection while the forensic reads it is meant to size now default to the global "Last 7 days" box, so the count can be larger than the read returns. This is deliberate, because the count tool also covers collections that have no box at all; the tool descriptions say so. - The two Acronis agent-delete tools (
acronis_delete_agentandacronis_delete_agent_by_id) perform the same action against two vendor endpoints. Whether to merge them is still under review.