Skip to content

Releases: nuoframework/darktrace-mcp

Darktrace MCP v1.1.2

Choose a tag to compare

@github-actions github-actions released this 06 Oct 21:56
126e5ea

Changelog

1.1.2 — 2026-10-06

  • Docker setup is self-service. Choosing 2) docker in setup no longer asks for an image ID. The wizard resolves the docker path, checks that the daemon answers (docker version) and explains what to install or start when it does not, proposes ghcr.io/nuoframework/darktrace-mcp:<package version>, accepts a tag, a name@sha256: digest or a local sha256: image ID (strictly validated), offers Pull it now? [Y/n] when the image is missing (--pull for --yes runs) and shows docker pull progress. Client entries keep starting the immutable image ID with --pull=never, the caller's UID:GID and read-only token mounts; setup.json and the summary record the image ID and the registry digest for comparison with the GitHub Release notes. Nothing is written when a preflight step fails.
  • config and test with Docker. config <client> reuses the saved image ID and prints its digest. test / doctor --online first runs the image's --check-config in a container with the client entry's mounts and user and no network, then checks the appliance from the host.
  • No saved appliance URL in prompts. The wizard's URL prompt is Darktrace appliance URL (https://...): with no default and never prints a previously saved address; an empty answer is refused. --url and non-interactive reruns keep working.
  • Plugin bundle. claude-plugin/ packages the server as a Claude Code plugin (manifest with userConfig for the appliance URL, both tokens, profiles, the sensitive-write acknowledgement and the signature date format; a package.json and package-lock.json that install the published package at the pinned version when the plugin is installed; .mcp.json starting node on the installed entry; an icon; the darktrace-investigation skill) and, in the same folder, the portable plugin.json and mcp.json that Codex reads (Codex keeps the pinned npx launcher). Root .claude-plugin/marketplace.json and .agents/plugins/marketplace.json expose it as a repository marketplace for Claude Code and Codex. Plugin distribution describes the Claude Directory submission and the per-release version bump.
  • uninstall. New darktrace-mcp uninstall (alias remove --all) shows a plan, asks once (--yes, --dry-run), removes the darktrace entry from every client (backups kept), deletes the stored tokens, setup.json, the installer directory and the fixed copies (--keep-copies keeps them), removes the image ID recorded by setup with --docker (never other images), and prints the npm uninstall -g command when the package is installed globally. Symbolic links and unknown files are never touched.
  • Signed releases with provenance. The github-release job now signs every release asset with cosign (keyless Sigstore bundle <asset>.sigstore.json, identity release.yml@refs/tags/v<version>) and attests SLSA v1 build provenance for all assets with actions/attest (darktrace-mcp-<version>.intoto.jsonl, full bundle darktrace-mcp-<version>.provenance.sigstore.json, also stored in the GitHub attestations API). Verification commands: releases. The new sign-release.yml workflow adds signature bundles to releases published before this change without touching their assets (supply-chain checks).
  • Pinned npm fallback. publish-npm no longer runs npm install -g npm@^11 when the bundled npm is too old; it downloads the npm 11.21.0 tarball, verifies its registry sha512 integrity and runs it in place.
  • Property-based tests. 22 new tests with fast-check (test/unit/*-properties.test.ts) cover validatePathSegment, checkInput and validateSearchHash, the request signer (determinism, wire encoding round trip, encoded and unencoded signature modes, the Advanced Search Base64 segment, JSON bodies, UTC dates) and the canonical JSON and argsDigest behind preview binding and the audit chain. Functional CI pin 245 → 267 (release pins).
  • Runtime image: zlib 1.3.2-r1. Alpine v3.24 replaced zlib-1.3.2-r0 with 1.3.2-r1, whose recipe backports the fix for CVE-2026-85091 (the High finding retained in the patched runtime review). The architecture pins in the Dockerfile now name the r1 packages and their SHA-256; nothing else in the pinned input set changed. The CI Docker gates fetch and verify the set on every run, so the old pins could no longer be fetched.
  • Scorecard. scorecard.yml passes repo_token: ${{ secrets.SCORECARD_TOKEN || github.token }} so the owner can enable the Branch-Protection check with a fine-grained token. Supply-chain checks now record each Scorecard check, its status and the accepted gaps, and the remaining OpenSSF Best Practices silver criteria.
  • CodeQL. The open code-scanning alerts in the release and Docker scripts are fixed (scripts/prepare-docker-runtime.mjs, scripts/lab-read-smoke.mjs, scripts/verify-release.mjs); no production source changed. scripts/prepare-docker-runtime.mjs also fetches the committed APK revisions from the Alpine archive when the repository index has moved on, so the pinned input set stays reproducible.
  • Release workflow. publish-npm fails only when npm publish itself fails; it then polls the public registry for up to 15 minutes and records the tarball shasum and sha512 integrity when the version is still propagating. github-release runs unless a gate or a publish actually failed, and records the npm status in the release body (releases).
  • Dependencies. Runtime zod 4.2.0 → 4.6.5; development @types/node 24.0.0 → 26.6.4 and fast-check 4.10.2 added; GitHub Actions pins bumped by Dependabot. @modelcontextprotocol/server stays at 2.3.0.
  • Repository and documentation. No lab appliance hostnames remain in evidence, reports or probe defaults. CONTRIBUTING.md describes the pull request process and acceptance requirements; SECURITY.md states the vulnerability response-time commitment; both READMEs carry the OpenSSF Best Practices (project 15261) and Scorecard badges. The Darktrace/Email API shapes observed from a console capture are recorded as documentation only (observed shapes); the email action stays excluded.
  • Version pins. Install snippets, server.json, manifest.json and the version literal now say 1.1.2. The Claude Code plugin in claude-plugin/ keeps its exact pin on 1.1.1 until the registry shows 1.1.2 (plugin distribution); the release pins are in release-pins-1.1.2.md.

Known limitations in 1.1.2

  • Surface and lab evidence unchanged. 1.1.2 registers the same 77 executable operations in 50 tools as 1.1.1, with the same tool contracts and profile hashes; 59 operations have lab evidence, 6 of them partial. No new lab run was made for 1.1.2: production source changes are limited to src/cli/ and the version literal. Every item under known limitations in 1.1.1 still applies.
  • Distribution. Release assets are signed and carry build provenance from this release; the ghcr image still has no attestation, and the image published by release.yml is rebuilt, not the image the CI Docker job tested. The runtime image carries zlib 1.3.2-r1 (the Alpine backport for CVE-2026-85091); no new vulnerability scan of the 1.1.x runtime is recorded. The Docker setup path resolves and records the image digest but verifies no signature for the image: compare the digest with the release notes.
  • Plugin pin lag. The plugin installs an exact npm version, so the plugin on main follows a release by one merge; until that merge it installs the previous version.
  • Uninstall scope. uninstall removes only what setup wrote: the darktrace client entries, the token files, setup.json, the fixed copies and, with --docker, the one recorded image ID. A global npm install -g is reported, not removed; files it does not recognise are left in place.

1.1.1 — 2026-10-06

  • Lab evidence (gap campaign, 2026-10-06). New live runs on the Darktrace 7.1.0 lab, through the MCP stdio path and the final write controls (report). Now validated: post_devices, post_aianalyst_investigations, post_pcaps, get_pcaps_filename (both the whole-file and the output_limit_exceeded branch), get_advancedsearch_api_search_query, get_advancedsearch_api_analyze_field_analysis_query and get_advancedsearch_api_graph_graphmode_interval_query with the current Base64 path encoding, and post_antigena (activate, extend, clear, reactivate). 59 operations have lab evidence, 6 of them partial (was 56 and 11). Narrower partial notes for manual Antigena (connection only; pol, gpol, quarantineOutgoing got HTTP 400 on a client-sensor device), subnets (label, uniqueHostnames) and the intel feed (addentry, addlist, expiry, removeentry; hostname accepted but not read back). The three tag DELETE operations applied live, but the lab gateway still answers HTTP 502, so they stay not lab-validated with that note.
  • Lab driver. scripts/lab-gap-campaign.mjs drives the built server over MCP stdio for owner-authorised lab campaigns (token files only; critical actions through preview, confirm and the server dialog). scripts/lab-status-tap.mjs optionally records the HTTP status of each appliance response (method, route prefix and status only).
  • Error-code naming. Full mo...
Read more

Darktrace MCP v1.1.1

Choose a tag to compare

@nuoframework nuoframework released this 06 Oct 18:10
62b238a

Darktrace MCP v1.1.1

  • Lab evidence (gap campaign, 2026-10-06). New live runs on the Darktrace 7.1.0 lab, through the MCP stdio path and the final write controls (report). Now validated: post_devices, post_aianalyst_investigations, post_pcaps, get_pcaps_filename (both the whole-file and the output_limit_exceeded branch), get_advancedsearch_api_search_query, get_advancedsearch_api_analyze_field_analysis_query and get_advancedsearch_api_graph_graphmode_interval_query with the current Base64 path encoding, and post_antigena (activate, extend, clear, reactivate). 59 operations have lab evidence, 6 of them partial (was 56 and 11). Narrower partial notes for manual Antigena (connection only; pol, gpol, quarantineOutgoing got HTTP 400 on a client-sensor device), subnets (label, uniqueHostnames) and the intel feed (addentry, addlist, expiry, removeentry; hostname accepted but not read back). The three tag DELETE operations applied live, but the lab gateway still answers HTTP 502, so they stay not lab-validated with that note.
  • Lab driver. scripts/lab-gap-campaign.mjs drives the built server over MCP stdio for owner-authorised lab campaigns (token files only; critical actions through preview, confirm and the server dialog). scripts/lab-status-tap.mjs optionally records the HTTP status of each appliance response (method, route prefix and status only).
  • Error-code naming. Full model, component and enum lists surface the public error code response_limit_exceeded; earlier lab notes used the internal error kind too_large. PCAP output refusals remain output_limit_exceeded.
  • CI and supply-chain controls. CodeQL runs the JavaScript/TypeScript security-extended queries on production source and release scripts. ESLint with TypeScript and security rules runs in CI. Dependabot checks npm and GitHub Actions dependencies weekly, with runtime major upgrades reviewed by hand. OpenSSF Scorecard publishes scheduled analysis and SARIF results. Release helper fixes use fresh private temporary directories, exclusive output writes and descriptor-based reads that reject symlinks.

Known limitations in 1.1.1

  • Email. The action remains excluded; Email reads remain unvalidated because the lab token gets HTTP 403. Schemas come from darktrace-sdk 0.10.1.
  • Lab scope. One Darktrace 7.1.0 appliance and one broad token: 59 operations with evidence, 6 partial. Manual Antigena covers connection only (pol, gpol, quarantineOutgoing got HTTP 400 on a client-sensor device; quarantine and quarantineIncoming were not run). Subnet writes cover label and uniqueHostnames. Intel-feed writes cover addentry, addlist, expiry and removeentry; hostname was accepted but its flag could not be read back. Models, components and enums cover responsedata only; full lists fail with response_limit_exceeded. get_cves still gets HTTP 500 (Darktrace/OT only) and get_filtertypes HTTP 302; redirects are never followed.
  • PCAP. Whole-file downloads and the output_limit_exceeded refusal were checked live. Captures above about 45 KB still exceed the 60,000-character output budget.
  • DELETE. delete_tags_tid_entities_teid, delete_tags_entities and delete_tags_tid applied live, but the lab gateway answered HTTP 502. They remain not lab-validated; the server reports write_outcome_unknown, never retries, and opens the write breaker after three failed or unknown outcomes in one process.
  • Lab residue. The campaign left a completed capture, an investigation and its alert, an empty intel-feed source, and cleared Antigena actions. Device and subnet changes were restored; tags were deleted. Earlier undeletable test comments remain. See the campaign report.
  • The remaining limitations recorded for 1.1.0 still apply: consent and taint controls, per-process state, auditing, protected targets, token scope, egress, signing, distribution and preview eviction. The 1.1.0 lab-scope and PCAP notes below are historical; this section supersedes them.

Install

npx -y @nuoframework/darktrace-mcp@1.1.1 setup

Claude Desktop: download darktrace-mcp-1.1.1.mcpb below and open it. Docker: pin the digest.

ghcr.io

ghcr.io/nuoframework/darktrace-mcp:1.1.1
ghcr.io/nuoframework/darktrace-mcp@sha256:a1e3944426eddae0e1fa13db0f58a380ae601562dcd4dd93f1767fa42a98a1e1
linux/amd64 sha256:16f7295753b292c123ea7864b29c7ebfb9b8a3b767fe5a9ed64add25c79ca497
linux/arm64 sha256:8c864d47f88f8e9cfdb26562f2dc73101acadd441173c38e545629fa355ed3d7

Pin clients to the digest: darktrace-mcp setup --runtime docker --image ghcr.io/nuoframework/darktrace-mcp@sha256:a1e3944426eddae0e1fa13db0f58a380ae601562dcd4dd93f1767fa42a98a1e1

Docker gates (ci.yml at 62b238a)

npm

@nuoframework/darktrace-mcp@1.1.1 was published through npm trusted publishing (OIDC from GitHub Actions) with a signed provenance statement; the attached tarball is the identical, verified artifact.

Verify

shasum -a 256 --ignore-missing -c SHA256SUMS

Darktrace MCP v1.1.0

Choose a tag to compare

@nuoframework nuoframework released this 06 Oct 16:51
f95e798

darktrace-mcp 1.1.0

  • Public distribution. The package is @nuoframework/darktrace-mcp on the public npm registry (published from CI with npm trusted publishing and provenance), the image is ghcr.io/nuoframework/darktrace-mcp:<version> (linux/amd64 and linux/arm64, pinned by digest), and the server is described for the MCP Registry as io.github.nuoframework/darktrace-mcp (mcpName in package.json, server.json). Bootstrap: npx -y @nuoframework/darktrace-mcp@1.1.0 setup. When run from the npx cache, setup copies the verified package tree to ~/.local/share/darktrace-mcp/<version>/ and writes absolute node + dist/src/index.js paths, so clients never launch npx. These channels are live only after the owner's publication steps (releases).
  • Full API surface with profiles. 77 of the 79 catalogue operations are executable, as 50 tools. One operation is excluded (the Darktrace/Email action, below) and one is deprecated (GET /aianalyst/incidents). DARKTRACE_PROFILES selects read (default), sensitive, write, critical or all. Every Darktrace/Email read needs sensitive. 56 operations have evidence from one Darktrace 7.1.0 lab, 11 of them only partial; the others are marked "not lab-validated" (tool reference).
  • Write controls. Ordinary writes accept dryRun:true for a value-free preview; without it they run, relying on the host's tool-permission prompt (DARKTRACE_WRITE_APPROVAL=host, the default). Critical actions need a dryRun:true preview, then confirm:true with its single-use previewId (5 minutes) and, by default, an accepted server confirmation dialog (approved:true, at most one per session and four per process, 30-second deadline); a call without confirm:true is refused with confirmation_required. DARKTRACE_CRITICAL_APPROVAL=host needs DARKTRACE_ACKNOWLEDGE_HOST_APPROVAL=true. Writes are rate-limited (at most 10 per minute), a breaker stops all writes after three failed or unknown outcomes in a row until restart, optional protected targets and fixed per-call target caps apply, and every preview, refusal and write is written to a hash-chained audit line on stderr.
  • Sensitive and write together. Any profile list with both sensitive and write, including all, starts only with DARKTRACE_ACKNOWLEDGE_SENSITIVE_WRITE=true.
  • Darktrace/Email action excluded. darktrace_email_action is not registered in any profile: its signing and request schema are unvalidated and the lab token got 403.
  • Older variables. DARKTRACE_SENSITIVE_READ and DARKTRACE_WRITE_CRITICAL still work on their own. When DARKTRACE_PROFILES is set they may only agree with it or narrow it; a value that would add an unlisted capability stops startup.
  • Easier installation. New darktrace-mcp setup wizard (hidden token entry, 0600 token files under ~/.config/darktrace-mcp/, permission preset, automatic configuration of Claude Desktop, Claude Code, Codex, Cursor, VS Code, Windsurf, OpenCode and Gemini CLI with backups), plus config <client>, remove and test. One-line installers scripts/install.sh and scripts/install.ps1.
  • Claude Desktop extension. npm run pack:mcpb builds a .mcpb bundle; Claude Desktop stores the tokens in the OS keychain.
  • Documentation restructure. Short bilingual READMEs; task-oriented guides (getting started, clients, configuration, troubleshooting, security overview) with Spanish versions in docs/es/; generated tool reference (npm run docs:tools); past review and release reports moved to docs/history/.

Known limitations in 1.1.0

From the 1.1.0 final gate review §4. None is an exploitable defect found in the server, and none is an owner acceptance of risk.

  1. Email. The email action is excluded. Email reads are not lab-validated (the lab token got 403). Their schemas come from darktrace-sdk 0.10.1, and responses may be sparse.
  2. Lab scope. One 7.1.0 appliance and one broad token. Partial tests: Antigena manual block and clear only; subnets label only; intel feed add and remove only; models, components and enums only with responsedata (full lists return too_large). Appliance errors: get_cves returns 500 and get_filtertypes returns 302. Most write evidence predates the final write controls; after them, only the intel-feed critical flow, the post_tags preview, the confirmation_required refusal and POST Advanced Search were checked live. The GET Advanced Search forms passed live only before their path encoding changed; the current encoding has probe evidence for = only.
  3. PCAP. A download is returned whole or fails with output_limit_exceeded. Captures above about 45 KB do not fit the 60,000-character output budget. The current contract was never tested live.
  4. DELETE and the write breaker. The lab gateway answers 502 to every DELETE after applying it, which the server records as outcome:"unknown". Three in a row open the write breaker until restart.
  5. Sensitive and write together. There is no taint control. Once acknowledged, ordinary free-text writes (comments, tag descriptions, labels) can carry sensitive data out of the appliance. Comments cannot be deleted and every appliance user can see them.
  6. Approval. Ordinary writes default to writeApproval=host: no server prompt. host mode delegates critical consent to the host. Auto-answering clients or "always allow" rules remove the human; the server cannot verify that a human answered.
  7. Per-process state. Rate limits, the breaker, previews and the audit chain are per process; several host processes multiply the budgets. Audit chains share one genesis and carry no boot identifier. The audit goes to stderr only, with no external anchor. A restart resets the breaker.
  8. Sensitive reads are not audited.
  9. Protected targets are opt-in and match literal values only. For post_antigena they match the action codeid, not the device. maxTargets is owner policy.
  10. Token scope. There is no least-privilege token mapping per profile. Appliance token permissions remain the real ceiling.
  11. Data egress. Every result, including Base64 PCAP data and email metadata, reaches the MCP host and its model provider.
  12. Signing. GET Advanced Search depends on proxies keeping percent-encoding byte-exact. A combined query and JSON body is refused.
  13. Distribution. No image attestation; the SBOMs are inventories, not clearances. The ghcr image is rebuilt in release.yml; it is not the CI-tested image. For 1.1.0, the linux/arm64 image passed the local Docker gates; linux/amd64 is verified only by CI on the release commit, and there is no vulnerability scan of the 1.1.0 runtime yet. Docker Desktop needs DARKTRACE_TOKEN_FILE_OWNER=root-or-current. The server.json OCI launch passes tokens as container environment variables, readable by anyone with Docker access. Native Windows cannot protect token files.
  14. Previews. The preview store evicts the oldest live critical preview once it holds 256 (availability only).
  15. Lab residue. Undeletable [mcp-test] and [mcp-ux] comments remain on the lab appliance.

Install

npx -y @nuoframework/darktrace-mcp@1.1.0 setup

Claude Desktop: download darktrace-mcp-1.1.0.mcpb below and open it. Docker: pin the digest.

ghcr.io

ghcr.io/nuoframework/darktrace-mcp:1.1.0
ghcr.io/nuoframework/darktrace-mcp@sha256:dd79adb2dfe78134fa9721508a1f46776ed1736158dcf0b7f54e1dd0bca2d511
linux/amd64 sha256:4828a4782695127a759f281e6786b24d5bd9b785ab4c56d64a965888e9a5df84
linux/arm64 sha256:e4317b8ee34d8342498590279ca868b6691733bef9562f2a9071af318925a978

Pin clients to the digest: darktrace-mcp setup --runtime docker --image ghcr.io/nuoframework/darktrace-mcp@sha256:dd79adb2dfe78134fa9721508a1f46776ed1736158dcf0b7f54e1dd0bca2d511

Docker gates (ci.yml at f95e798)

npm

@nuoframework/darktrace-mcp@1.1.0 is live on the public npm registry with a signed provenance statement (Sigstore log index 3112942967; tarball SHA-256 1b36cc9f65d9dbdd9558f1dfc2e5aa96041a1fdbc0a3f6ab33ceb4862f257c49, shasum 98bb85d46b286fc89822b2524f5ad2e6a9d58b41). The attached tarball is the identical, verified artifact.

Verify

shasum -a 256 --ignore-missing -c SHA256SUMS

Evidence: security-receipt.json, verification.json, build-evidence.json, runtime-sbom.cdx.json, mcp-tool-contracts.json. Disclosed residual risks: see CHANGELOG 'Known limitations in 1.1.0' and docs/security/final-gate-review-1.1.0.md.

Darktrace MCP v1.0.0 — read-only release

Choose a tag to compare

@nuoframework nuoframework released this 06 Oct 07:11

Darktrace MCP 1.0.0 (private)

Unofficial MCP. Developed by an independent third party, unaffiliated with Darktrace and without authorization from Darktrace. · MCP no oficial. Desarrollado por un tercero independiente, sin afiliación con Darktrace y sin autorización de Darktrace. Claims / reclamaciones: contacto@pabloarrabal.com

English

First stable private release: 15 read-only MCP tools covering 19 validated GET selectors, identical in the read and read + sensitiveRead profiles. Writes, critical operations, email, PCAP export and HTTP transport are not available.

Runtime. A nonroot, shell-free scratch Docker image with no listener. It uses Alpine 3.24 packages: Alpine-maintained, musl-linked Node.js 24.18.1 with shared OpenSSL 3.5.9. This is a distribution-maintained runtime, not an upstream Node.js Tier 1 binary.

Evidence.

  • Lab: 19/19 real queries passed on Darktrace 7.1.0 on 2026-10-06, using arm64 image sha256:8cd85604…. The released images use the same query/policy implementation and dependencies; the only production source difference is the 1.0.0 version literal, which was reviewed in the final diff and covered by the SDK and native tests. The lab is closed, and the released images were not retested live.
  • CI: run 37423665585 on source commit 2adb84b passed all jobs: Node 22/24 offline plus native Docker on amd64 and arm64, 130 functional + 325 security tests, 0 skipped. The release tag points to a later documentation-only commit with identical production, build and shipped-document files.
  • Scans: Trivy 0. Grype keeps a High for zlib 1.3.2 (CVE-2026-85091). The library is affected, but an independent review found its vulnerable code is not in the application's execution path. zlib is not fixed: Alpine has no fixed package yet. Grype's Medium for ada (CVE-2024-9410) is a product-name collision. This is not a zero-CVE claim.

Install (Docker, recommended). Choose linux-arm64 or linux-amd64:

gh release download v1.0.0 --repo nuoframework/darktrace-mcp \
  --pattern 'darktrace-mcp-1.0.0-linux-arm64.tar.gz' --pattern SHA256SUMS
shasum -a 256 --ignore-missing -c SHA256SUMS
docker load --input darktrace-mcp-1.0.0-linux-arm64.tar.gz
docker image inspect --format '{{.Id}}' darktrace-mcp:1.0.0-arm64

On amd64, use the amd64 archive and the darktrace-mcp:1.0.0-amd64 tag. The loaded ID must match the table below. Configure the client with that sha256: ID, --pull=never, --read-only, --cap-drop=ALL, --security-opt=no-new-privileges and read-only token-file mounts (see README). No public registry image exists.

Native package. Install darktrace-mcp-1.0.0.tgz with npm install --ignore-scripts --omit=dev. Only do this on a maintained Node.js runtime whose OpenSSL you have verified as 3.5.9 or later. Official upstream Node.js releases examined on 2026-10-05 bundle 3.5.8.

Español

Primera versión estable privada: 15 herramientas MCP de solo lectura que cubren 19 selectores GET validados, idénticas en los perfiles read y read + sensitiveRead. No hay escrituras, operaciones críticas, email, exportación PCAP ni transporte HTTP.

Runtime. Imagen Docker scratch no root, sin shell ni listener. Usa paquetes de Alpine 3.24: Node.js 24.18.1 mantenido por Alpine, enlazado con musl y con OpenSSL 3.5.9 compartido. Es un runtime mantenido por la distribución, no un binario Tier 1 de Node.js upstream.

Evidencia.

  • Lab: 19/19 consultas reales superadas en Darktrace 7.1.0 el 2026-10-06, con la imagen arm64 sha256:8cd85604…. Las imágenes publicadas usan la misma implementación de consultas y políticas y las mismas dependencias; la única diferencia en el código de producción es el literal de versión 1.0.0, revisado en el diff final y cubierto por las pruebas SDK y nativas. El lab está cerrado y las imágenes publicadas no se volvieron a probar en vivo.
  • CI: la ejecución 37423665585 sobre el commit 2adb84b superó todos los jobs: Node 22/24 offline y Docker nativo en amd64 y arm64, 130 pruebas funcionales + 325 de seguridad, 0 omitidas. La etiqueta apunta a un commit posterior solo de documentación, con archivos de producción, compilación y documentos distribuidos idénticos.
  • Escaneos: Trivy 0. Grype mantiene un High en zlib 1.3.2 (CVE-2026-85091). La biblioteca está afectada, pero una revisión independiente determinó que su código vulnerable no está en la ruta de ejecución de la aplicación. zlib no está corregido: Alpine aún no tiene paquete corregido. El Medium de Grype para ada (CVE-2024-9410) es una colisión de nombre de producto. No se afirma cero CVE.

Instalación (Docker, recomendada). Elige linux-arm64 o linux-amd64 y usa los comandos de la sección en inglés. El ID cargado debe coincidir con la tabla. Configura el cliente con ese ID sha256:, --pull=never, --read-only, --cap-drop=ALL, --security-opt=no-new-privileges y tokens montados en solo lectura (ver README.es). No existe imagen en un registro público.

Paquete nativo. Instala darktrace-mcp-1.0.0.tgz con npm install --ignore-scripts --omit=dev. Hazlo solo con un runtime Node.js mantenido cuyo OpenSSL hayas verificado como 3.5.9 o posterior.

Assets / Archivos

Asset SHA-256 Image ID
darktrace-mcp-1.0.0-linux-amd64.tar.gz 3594f1051a1f334603681b3869b25dbe9b0c52e6ec5e243b39b457e775a86cad sha256:59a490c78a08b63e6757a7d872526a16b60cd119efc2240e607a97581844c0a3 (darktrace-mcp:1.0.0-amd64)
darktrace-mcp-1.0.0-linux-arm64.tar.gz 8c0d7c8ddb18c4d20d38802105ebe4d55a1018242ad074206314e77e064cfe5e sha256:bc0a29b49347c2ed21557b34193a2b8aa26017c8459c526665e09ee632a03f92 (darktrace-mcp:1.0.0-arm64)
darktrace-mcp-1.0.0.tgz 3abf8b7a5be5a0d56b23529c62a883fbf49a28cb08a6e606d6ac3fcb9916b37b —
darktrace-mcp-1.0.0-security-provenance.tar.gz 356c91522678bfbaafcfafb8b12e87b1ec9475014ec7389719a6faceda316b31 —
darktrace-mcp-1.0.0-native-ci-evidence.tar.gz 0b2a8954a9a22ad9b406f12260bea304e4558feb4efbc8bae70f7ebe40b0d86e —
darktrace-mcp-1.0.0-package-evidence.tar.gz b6e538ec8caf823832c515e41d0c9bf63b2e81063e37c5d2762ae10311ca9b74 —
SHA256SUMS Verifies all six archives / Verifica los seis archivos —

The package-evidence archive preserves the original package verifier sidecars and their canonical checksum file. The top-level SHA256SUMS covers every downloadable archive, including Docker. Native CI evidence contains the complete final amd64 and arm64 suite receipts.

El archivo package-evidence conserva los ficheros originales del verificador del paquete y su checksum canónico. El SHA256SUMS de la release verifica todos los archivos descargables, incluido Docker. Las evidencias de CI incluyen los resultados completos de amd64 y arm64.

Darktrace MCP v0.1.0-alpha.0 — private offline alpha

Choose a tag to compare

@nuoframework nuoframework released this 05 Oct 14:20

Darktrace MCP 0.1.0-alpha.0

Private prerelease with installation instructions, checksums and offline verification evidence.

Included

  • Read-first stdio MCP server: 54 operations executable by profile, five critical previews, 19 blocked and one excluded.
  • Protected credential files, constrained HTTPS transport, response minimization and write audit controls.
  • English documentation and Spanish quickstart; versioned installation from release assets.
  • Threat modeling, independent source and artifact reviews; no known open findings in those review scopes.

Verification

  • Reviewed commit: 8b4f42a0fa7d5ef2688176493a83b4cd10617949.
  • GitHub CI: Node 22 and 24 on Linux.
  • Local Node 22/24: 102 standard tests passed; 238 adversarial cases, 235 passed and three OS-dependent cases blocked/skipped.
  • Reproducible runtime archive, exact dependency/SRI checks and independently reviewed package assets.

Installation

Follow private release installation. Verify SHA256SUMS before installation. No npm or container publication.

Pending validation

Authenticated Darktrace 7.1 lab compatibility, provider eligibility and real deployment network pinning remain pending. Docker was not built locally. This prerelease is not a security certification.

The next alpha will record lab validation results and changes in its own release notes.