Skip to content

Releases: m4vic/detonate

v1.0.0-rc1

v1.0.0-rc1 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 15 Sep 18:27
7306cd1

Changelog

  • e6ca89b Add files via upload
  • 527d4dc Add files via upload
  • 95c2c8a Add files via upload
  • e778246 Add files via upload
  • 727da14 Add files via upload
  • 4ae5fd4 CI and release pipeline
  • ab561f3 CLI redesign: one argument, thorough by default
  • 8e25ad1 Create AI fundamentals.md
  • e5350dc Create AI-security
  • 07c377b Create AgenticAI.md
  • 866bf53 Create ComputerVision.md
  • 7e2335c Create GenAI & AgenticAI.md
  • 304e6f9 Create Machinelearning.md
  • da2e1cf Create README.md
  • edf82f5 Create README.md
  • fd2f564 Create README.md
  • 2e1791a Create README.md
  • 21178d4 Create README.md
  • f51f0de Create README.md
  • c017d1d Create README.md
  • 8bd381f Create README.md
  • d6478cd Create Readme.md
  • d71447c Create Robotics Resources.md
  • 88c4e56 Create Robotics resources
  • f2a1ab4 Create Undeniable Systems Skillset
  • 27a64ab Create deeplearning.md
  • 78ec760 Create detailed Tools & MLOps section in README
  • 3a81e51 Create fundamentals.md
  • fde9f99 Create fundamentals.md
  • 29a4338 Create images
  • 2d050e7 Create images
  • 50dc7f6 Create readme.md
  • 22ccdce Create readme.md
  • 7a58e82 Delete AGI directory
  • 339ccae Delete AI resources directory
  • 8973546 Delete AI-security
  • 25ee29e Delete ARCHITECTURE.md
  • fd6cd80 Delete Ai-security directory
  • 55e9040 Delete DeepLearning directory
  • 56d7a5b Delete Fundamentals directory
  • c43b206 Delete GenerativeAI directory
  • d4acaa0 Delete IMPLEMENTATION_PLAN.md
  • 14d8801 Delete MachineLearning directory
  • 2d4c594 Delete PRODUCTION_GRADE.md
  • 1063bb7 Delete QuantFinance directory
  • 55e0c8b Delete QuantFinance directory
  • 817e87d Delete README.md
  • 8dfbcff Delete README.md
  • 1a1d981 Delete Robotics Resources
  • cbd754b Delete Robotics directory
  • c07e2d0 Delete Robotics resources
  • 37ee727 Delete RoboticsResources directory
  • fa24db6 Delete STATUS.md
  • 4139791 Delete Tools directory
  • 92210c0 Delete Undeniable Systems Skillset
  • 74e404d Delete Undeniable Systems Skillset directory
  • a6a5533 Delete Undeniable Systems Skillset/Readme.md
  • 16e6be7 Delete extras directory
  • 88eddfc Delete fields-connection-diagram.png
  • b52612c Delete images
  • 75b486d Delete images
  • f8916b7 Delete images directory
  • 9e31a6c Delete papers directory
  • 28a7d9d Delete papers directory
  • e2346df Delete skills directory
  • a926f6c Delete skills directory
  • 70be1b7 Delete specifics directory
  • a2353c7 Dynamic tests: seven hostile MCP servers
  • 4dc2ef8 Initial commit
  • c6fea0e Interactive mode: run 'detonate' with no arguments
  • 4cc02a9 JSON and SARIF output
  • d5d909f M0: scaffold — CLI, MCP+skill targets, Docker pre-flight, docs
  • 2fd31fa M1: enumerate MCP servers and agent skills
  • 3b7b1ae M2: sandbox — run untrusted code in a disposable container
  • efee62d M3: wire the sandbox into the scan path
  • 7490dc2 M4: behavioural monitor — detonate now catches what manifests hide
  • c953638 M5: adversarial probes - call the tools, don't just watch the boot
  • 6f932fa Merge branch 'docs/status-and-production-grade'
  • df47cf5 Merge branch 'main' into feat/ci-gate-and-detection
  • 7e5ae06 Merge branch 'release/r0-reproducible-alpha' into docs/research-plan
  • c29c97d Merge origin/main into the R0 branch
  • 5c5aa38 Merge pull request #1 from m4vic/docs/research-plan
  • 24ffd77 Merge pull request #10 from m4vic/fix/writable-home-linux
  • 0a92329 Merge pull request #11 from m4vic/docs/corpus-coverage-and-testing
  • 92196fe Merge pull request #12 from m4vic/release/v0.4.2
  • a17ca0e Merge pull request #13 from m4vic/fix/ssh-decoy-derived-encodings
  • c734876 Merge pull request #14 from m4vic/feat/postmark-fixture-and-repositioning
  • 45bc378 Merge pull request #15 from m4vic/feat/v1-cli-and-docs
  • 7306cd1 Merge pull request #16 from m4vic/feat/rc1-verification
  • 428918c Merge pull request #2 from m4vic/docs/status-and-production-grade
  • 58f3517 Merge pull request #3 from m4vic/release/v0.3.0-alpha.1
  • b2c2def Merge pull request #4 from m4vic/feat/ci-gate-and-detection
  • 2fe1c94 Merge pull request #5 from m4vic/fix/inconclusive-never-exits-clean
  • 0681b6b Merge pull request #6 from m4vic/feat/skill-credential-decoy
  • 55a9c72 Merge pull request #8 from m4vic/feat/detection-corpus
  • bd407ec Merge pull request #9 from m4vic/feat/close-detection-gaps
  • b11ae46 Node support: match the container image to the ecosystem
  • 22aa300 Port M0-M1 to Go
  • 9603047 Prompts, git URLs, skill script detonation, and rug-pull detection
  • a41426f Rename ChatGPT Image Nov 25, 2025, 02_28_51 PM.png to image.png
  • a47a256 Rename MAIN_README.md to README.md
  • 5536bc0 Rename Machinelearning.md to Machine learning.md
  • 86c3074 Rename README.md to README.md
  • 29b6a9e Rename Robotics Resources.md to Robotics Resources
  • f1876d8 Rename deeplearning.md to Deep learning.md
  • 2fdc06f Rename image.png to fields-connection-diagram.png
  • 2912e6b Skill analysis: read the instructions, not just the frontmatter
  • 40236c9 Two-phase acquisition: scan MCP servers that have dependencies
  • efd8d08 Update AI fundamentals.md
  • 3aeed12 Update AI fundamentals.md
  • c7c4816 Update AgenticAI.md
  • 126da0c Update AgenticAI.md
  • 07c0a80 Update AgenticAI.md
  • 2840a35 Update AgenticAI.md
  • fdf579f Update AgenticAI.md
  • 50912bf Update AgenticAI.md
  • ff8f602 Update AgenticAI.md
  • da8255d Update AgenticAI.md
  • 3f81c50 Update Deep learning.md
  • 231a6c9 Update GenAI & AgenticAI.md
  • 15a5d85 Update MAIN_README.md
  • 10ae8ea Update MAIN_README.md
  • 12a0ecb Update MAIN_README.md
  • ce04e22 Update MAIN_README.md
  • 6ff09f7 Update MAIN_README.md
  • b06b1ff Update Machine learning.md
  • d03921f Update README.md
  • 382ea9a Update README.md
  • d9008ae Update README.md
  • a6e70e3 Update README.md
  • d9c29f1 Update README.md
  • 66fe02e Upd...
Read more

v0.4.2

Choose a tag to compare

@github-actions github-actions released this 05 Sep 07:45
92196fe

Changelog

  • 24ffd77 Merge pull request #10 from m4vic/fix/writable-home-linux
  • 0a92329 Merge pull request #11 from m4vic/docs/corpus-coverage-and-testing
  • 92196fe Merge pull request #12 from m4vic/release/v0.4.2
  • 2fe1c94 Merge pull request #5 from m4vic/fix/inconclusive-never-exits-clean
  • 0681b6b Merge pull request #6 from m4vic/feat/skill-credential-decoy
  • 55a9c72 Merge pull request #8 from m4vic/feat/detection-corpus
  • bd407ec Merge pull request #9 from m4vic/feat/close-detection-gaps
  • 0ded5f2 ci: build with Go 1.27
  • a1de86c feat: catch credential exfiltration staged to disk
  • fca190a feat: check bundled skill scripts for credential exfiltration
  • 92f9621 feat: close five detection gaps the corpus surfaced
  • 19b2cfa fix: a scan that lost its target no longer exits 0
  • 7a0ea91 fix: make the decoy home writable by the sandbox user on Linux
  • d982fba release: cut v0.4.2

v0.4.1

Choose a tag to compare

@github-actions github-actions released this 23 Aug 18:19

A patch release, and the reason for it is worth stating plainly: v0.4.0 shipped three false-positive generators, and the first corpus run against servers written by strangers found all three.

Fixtures are written by the same author as the detection rules. That makes this class of defect structurally invisible until you point the tool at code nobody involved has ever seen.

What was wrong

One dead socket was reported as 935 findings. A 682-tool server came back with 949 findings. A payload killed the server process, and every subsequent call — across every remaining tool — returned connection closed: client is closing: EOF. Each one was recorded as that tool crashing under hostile input.

The first crash is kept, because a payload that kills the target is a genuine result. What stops is treating the corpse as evidence about tools that were never reached. The scan now halts and says so:

the target stopped responding after "affiliate_scaleo_list_programmes";
129 tool(s) were never probed

That server went from 949 findings to 4.

A two-digit leak marker. The template-injection probe sent {{7*7}} and searched responses for "49". A benign error carrying "timestamp": "2026-08-23T13:15:54.497Z" was reported as CRITICAL server-side template injection — because .497 contains 49. One report from that scan held 33 incidental occurrences of it.

Now {{31337*31337}} matched against 982007569. Zero occurrences in the same report. That is the standard the credential decoys already meet with their 128-bit nonce, and every marker should meet it.

Tool shadowing fired on honest documentation. Two separate errors. A directive anywhere in a description paired with a tool name anywhere else in it — near-certain on a server whose 682 tools all begin affiliate_ — and two of three findings displayed evidence that did not contain the trigger at all. Both must now occur in the same sentence, and the evidence is that sentence.

The second error was conflating two different things:

Shape Example Verdict
Redirection — supersedes or suppresses another tool "call this instead of get_weather" CRITICAL finding
Sequencing — orders calls within one workflow "always call read_docx before …" observation to confirm

A real registry server ships that second sentence as a correctness constraint, explaining that IDs go stale. It was reported CRITICAL. Structurally the two are identical and only intent separates them, so sequencing is now surfaced to confirm rather than asserted as a finding.

Capability is not malice — the same lesson this project already learned when treating a skill's use of an API key as an attack flagged 30 of 59 known-good skills.

Measured

Server v0.4.0 v0.4.1
affiliate-networks-mcp (682 tools) 949 findings 4
@adeu/mcp-server (9 tools) 1 CRITICAL clean, exit 0
@aetherwealth/mcp (49 tools) 1 CRITICAL clean, exit 0

Controls unchanged — the poisoned fixture still exits 3, benign 0, thief 3, honest 0. Every fix is mutation-checked: reverting it fails its test.

New

scripts/find-targets.py finds servers detonate can actually probe, by reading the official MCP registry rather than a curated list. Of the first 400 entries: 289 are remote-only (an endpoint someone else operates — no code to sandbox, and probing it would be attacking a live third-party service), 3 require API keys, and 33 are probeable.

python scripts/find-targets.py

Install

VERSION=$(curl -sSL https://api.github.com/repos/m4vic/detonate/releases/latest | grep '"tag_name"' | head -1 | cut -d'"' -f4)
OS=$(uname -s | tr '[:upper:]' '[:lower:]')
ARCH=$(uname -m | sed 's/x86_64/amd64/; s/aarch64/arm64/')
curl -sSL "https://github.com/m4vic/detonate/releases/download/${VERSION}/detonate_${VERSION#v}_${OS}_${ARCH}.tar.gz" | tar xz
sudo mv detonate /usr/local/bin/

In CI, uses: m4vic/detonate@v0 picks this up automatically.

Worth knowing

Three servers is not a false-positive rate. The surviving crash finding has not been confirmed as a genuine vulnerability rather than an unhandled oversized input, and no server author has reviewed these results. What this release does establish is that a fixture corpus cannot find this class of defect at all.

Still 0.x. A no_findings result is not a security certification. Measured results, including the failures, are in docs/COMPATIBILITY.md.

v0.4.0

Choose a tag to compare

@github-actions github-actions released this 23 Aug 10:38

Test your MCP server or Agent Skill before you publish it. Detonate runs your target in a locked sandbox, plants fake credentials where a thief would look, and reports what it actually did — with a CI-gateable exit code and SARIF for the GitHub Security tab.

This release makes a clean result mean something. Before it, "no findings" and "we could not look" were too easy to confuse.

Proof, not opinion

The sandbox is now furnished with a decoy developer machine: SSH keys, cloud credentials, a .env, a .netrc, a GitHub token, and shell history — each carrying a unique 128-bit nonce that exists nowhere else.

[FINDING] 1  [CRITICAL] tool "read_file" returned the contents of /home/detonate/.ssh/id_rsa
   evidence : planted secret returned base64-encoded (nonce b6b4f5d63c3d52f44d00a51c920543a6)
   source   : decoy

The nonce was generated for that one run. It came back base64-encoded, so the tool read the file and re-encoded it rather than echoing our input. There is no benign explanation to argue about, and no model was asked its opinion — no LLM is involved in any verdict.

The other half matters just as much: a clean scan now asserts what it proved — "planted 6 credential decoys in the sandbox; none were returned by any tool" — instead of only reporting an absence.

What else is new

  • Nested input schemas are probed. Payloads reach strings inside arrays and objects, not only top-level parameters. On the official MCP memory server, tools with a reachable attack surface went from 3 of 11 to 10 of 11 — the other eight had been silently untested.
  • The sandbox stops taking the blame. A tool that fails because egress is denied, or because the root filesystem is read-only, is now reported as unsupported naming the restriction. Accusing a working server of being broken is a false positive like any other.
  • A scan that assessed nothing no longer exits 0. Four real community MCP servers returned not_assessed and exited clean; a pipeline reads 0 as "safe to merge". They now exit 4.
  • MCP tool-metadata analysis — instruction injection, concealment, tool shadowing, invisible Unicode tag smuggling (decoded into the evidence), and bidi overrides. Deterministic.
  • A GitHub Action, a 15-minute total scan budget, and --help on every subcommand.

Install

VERSION=$(curl -sSL https://api.github.com/repos/m4vic/detonate/releases/latest | grep '"tag_name"' | head -1 | cut -d'"' -f4)
OS=$(uname -s | tr '[:upper:]' '[:lower:]')
ARCH=$(uname -m | sed 's/x86_64/amd64/; s/aarch64/arm64/')
curl -sSL "https://github.com/m4vic/detonate/releases/download/${VERSION}/detonate_${VERSION#v}_${OS}_${ARCH}.tar.gz" | tar xz
sudo mv detonate /usr/local/bin/

Or go install github.com/m4vic/detonate/cmd/detonate@latest, or grab a binary below and check it against checksums.txt.

In CI:

- uses: m4vic/detonate@v0

See it work

Two fixtures ship with the repo — one steals, one behaves — and both are probed identically. That pairing is the argument: a scanner that only ever alarms proves nothing.

detonate dynamic testdata/thief  --cmd "python /target/server.py" --no-install   # exit 3
detonate dynamic testdata/honest --cmd "python /target/server.py" --no-install   # exit 0

Worth knowing

This is 0.x. A no_findings result is not a security certification.

One bug found in this cycle is worth stating plainly, because it shaped the release: the credential decoy was unreadable inside the sandbox on Linux. Files were planted 0600, the sandbox runs as a different uid, so the target could not open the credentials it was being tempted with — nothing leaked, and scans reported clean results they had not earned. It survived because Docker Desktop on Windows and macOS ignores POSIX ownership on bind mounts, so every local run passed. The first CI run on a Linux runner caught it.

It is fixed, it is covered by tests that fail without Docker on every platform, and the fix is verified on Linux in CI. But every dynamic "no credential was returned" result measured before this release was measured on Windows.

Static mode reaches roughly a third of targets — it needs an MCPB manifest.json. Tools that need network or filesystem writes cannot be behaviourally probed inside a sealed sandbox, and are reported as such rather than as findings.

Measured results against real targets, including the failures, are in docs/COMPATIBILITY.md. Full detail in the changelog.

v0.3.0-alpha.1

Choose a tag to compare

@m4vic m4vic released this 13 Aug 11:58
58f3517

Changelog

  • 2d4c594 Delete PRODUCTION_GRADE.md
  • fa24db6 Delete STATUS.md
  • 58f3517 Merge pull request #3 from m4vic/release/v0.3.0-alpha.1
  • c309cfc Update README.md
  • 1d8f36b Update README.md
  • 7706fb7 Update README.md
  • 8ad8da8 feat: add NetworkProxy configuration field to Policy for future intercepting proxy support
  • 511f607 feat: modular Probe interface, canary token generator, TargetDir on Session
  • 32cbd02 feat: prepare v0.3.0-alpha.1 release candidate
  • 1a11887 fix: avoid ownership preservation during node acquisition
  • 0f711cc fix: derive interactive banner version from build metadata

V0.2.0

Choose a tag to compare

@m4vic m4vic released this 07 Aug 15:06
v0.2.0

docs: update shields.io badges to match requested flat-style layout

v0.1.0

Choose a tag to compare

@m4vic m4vic released this 05 Aug 10:46
5c5aa38
Merge pull request #1 from m4vic/docs/research-plan

Docs/research plan