Repository navigation
Releases: nuoframework/darktrace-mcp
Release list
Darktrace MCP v1.1.2
Changelog
1.1.2 — 2026-10-06
- Docker setup is self-service. Choosing
2) dockerinsetupno longer asks for an image ID. The wizard resolves thedockerpath, checks that the daemon answers (docker version) and explains what to install or start when it does not, proposesghcr.io/nuoframework/darktrace-mcp:<package version>, accepts a tag, aname@sha256:digest or a localsha256:image ID (strictly validated), offersPull it now? [Y/n]when the image is missing (--pullfor--yesruns) and showsdocker pullprogress. Client entries keep starting the immutable image ID with--pull=never, the caller's UID:GID and read-only token mounts;setup.jsonand the summary record the image ID and the registry digest for comparison with the GitHub Release notes. Nothing is written when a preflight step fails. configandtestwith Docker.config <client>reuses the saved image ID and prints its digest.test/doctor --onlinefirst runs the image's--check-configin a container with the client entry's mounts and user and no network, then checks the appliance from the host.- No saved appliance URL in prompts. The wizard's URL prompt is
Darktrace appliance URL (https://...):with no default and never prints a previously saved address; an empty answer is refused.--urland non-interactive reruns keep working. - Plugin bundle.
claude-plugin/packages the server as a Claude Code plugin (manifest withuserConfigfor the appliance URL, both tokens, profiles, the sensitive-write acknowledgement and the signature date format; apackage.jsonandpackage-lock.jsonthat install the published package at the pinned version when the plugin is installed;.mcp.jsonstartingnodeon the installed entry; an icon; thedarktrace-investigationskill) and, in the same folder, the portableplugin.jsonandmcp.jsonthat Codex reads (Codex keeps the pinnednpxlauncher). Root.claude-plugin/marketplace.jsonand.agents/plugins/marketplace.jsonexpose it as a repository marketplace for Claude Code and Codex. Plugin distribution describes the Claude Directory submission and the per-release version bump. uninstall. Newdarktrace-mcp uninstall(aliasremove --all) shows a plan, asks once (--yes,--dry-run), removes thedarktraceentry from every client (backups kept), deletes the stored tokens,setup.json, the installer directory and the fixed copies (--keep-copieskeeps them), removes the image ID recorded by setup with--docker(never other images), and prints thenpm uninstall -gcommand when the package is installed globally. Symbolic links and unknown files are never touched.- Signed releases with provenance. The
github-releasejob now signs every release asset with cosign (keyless Sigstore bundle<asset>.sigstore.json, identityrelease.yml@refs/tags/v<version>) and attests SLSA v1 build provenance for all assets withactions/attest(darktrace-mcp-<version>.intoto.jsonl, full bundledarktrace-mcp-<version>.provenance.sigstore.json, also stored in the GitHub attestations API). Verification commands: releases. The newsign-release.ymlworkflow adds signature bundles to releases published before this change without touching their assets (supply-chain checks). - Pinned npm fallback.
publish-npmno longer runsnpm install -g npm@^11when the bundled npm is too old; it downloads the npm 11.21.0 tarball, verifies its registry sha512 integrity and runs it in place. - Property-based tests. 22 new tests with fast-check (
test/unit/*-properties.test.ts) covervalidatePathSegment,checkInputandvalidateSearchHash, the request signer (determinism, wire encoding round trip, encoded and unencoded signature modes, the Advanced Search Base64 segment, JSON bodies, UTC dates) and the canonical JSON andargsDigestbehind preview binding and the audit chain. Functional CI pin 245 → 267 (release pins). - Runtime image: zlib 1.3.2-r1. Alpine v3.24 replaced
zlib-1.3.2-r0with1.3.2-r1, whose recipe backports the fix for CVE-2026-85091 (the High finding retained in the patched runtime review). The architecture pins in theDockerfilenow name the r1 packages and their SHA-256; nothing else in the pinned input set changed. The CI Docker gates fetch and verify the set on every run, so the old pins could no longer be fetched. - Scorecard.
scorecard.ymlpassesrepo_token: ${{ secrets.SCORECARD_TOKEN || github.token }}so the owner can enable the Branch-Protection check with a fine-grained token. Supply-chain checks now record each Scorecard check, its status and the accepted gaps, and the remaining OpenSSF Best Practices silver criteria. - CodeQL. The open code-scanning alerts in the release and Docker scripts are fixed (
scripts/prepare-docker-runtime.mjs,scripts/lab-read-smoke.mjs,scripts/verify-release.mjs); no production source changed.scripts/prepare-docker-runtime.mjsalso fetches the committed APK revisions from the Alpine archive when the repository index has moved on, so the pinned input set stays reproducible. - Release workflow.
publish-npmfails only whennpm publishitself fails; it then polls the public registry for up to 15 minutes and records the tarball shasum and sha512 integrity when the version is still propagating.github-releaseruns unless a gate or a publish actually failed, and records the npm status in the release body (releases). - Dependencies. Runtime
zod4.2.0 → 4.6.5; development@types/node24.0.0 → 26.6.4 andfast-check4.10.2 added; GitHub Actions pins bumped by Dependabot.@modelcontextprotocol/serverstays at 2.3.0. - Repository and documentation. No lab appliance hostnames remain in evidence, reports or probe defaults.
CONTRIBUTING.mddescribes the pull request process and acceptance requirements;SECURITY.mdstates the vulnerability response-time commitment; both READMEs carry the OpenSSF Best Practices (project 15261) and Scorecard badges. The Darktrace/Email API shapes observed from a console capture are recorded as documentation only (observed shapes); the email action stays excluded. - Version pins. Install snippets,
server.json,manifest.jsonand the version literal now say 1.1.2. The Claude Code plugin inclaude-plugin/keeps its exact pin on 1.1.1 until the registry shows 1.1.2 (plugin distribution); the release pins are in release-pins-1.1.2.md.
Known limitations in 1.1.2
- Surface and lab evidence unchanged. 1.1.2 registers the same 77 executable operations in 50 tools as 1.1.1, with the same tool contracts and profile hashes; 59 operations have lab evidence, 6 of them partial. No new lab run was made for 1.1.2: production source changes are limited to
src/cli/and the version literal. Every item under known limitations in 1.1.1 still applies. - Distribution. Release assets are signed and carry build provenance from this release; the ghcr image still has no attestation, and the image published by
release.ymlis rebuilt, not the image the CI Docker job tested. The runtime image carries zlib 1.3.2-r1 (the Alpine backport for CVE-2026-85091); no new vulnerability scan of the 1.1.x runtime is recorded. The Docker setup path resolves and records the image digest but verifies no signature for the image: compare the digest with the release notes. - Plugin pin lag. The plugin installs an exact npm version, so the plugin on
mainfollows a release by one merge; until that merge it installs the previous version. - Uninstall scope.
uninstallremoves only whatsetupwrote: thedarktraceclient entries, the token files,setup.json, the fixed copies and, with--docker, the one recorded image ID. A globalnpm install -gis reported, not removed; files it does not recognise are left in place.
1.1.1 — 2026-10-06
- Lab evidence (gap campaign, 2026-10-06). New live runs on the Darktrace 7.1.0 lab, through the MCP stdio path and the final write controls (report). Now validated:
post_devices,post_aianalyst_investigations,post_pcaps,get_pcaps_filename(both the whole-file and theoutput_limit_exceededbranch),get_advancedsearch_api_search_query,get_advancedsearch_api_analyze_field_analysis_queryandget_advancedsearch_api_graph_graphmode_interval_querywith the current Base64 path encoding, andpost_antigena(activate, extend, clear, reactivate). 59 operations have lab evidence, 6 of them partial (was 56 and 11). Narrower partial notes for manual Antigena (connectiononly;pol,gpol,quarantineOutgoinggot HTTP 400 on a client-sensor device), subnets (label,uniqueHostnames) and the intel feed (addentry,addlist,expiry,removeentry;hostnameaccepted but not read back). The three tag DELETE operations applied live, but the lab gateway still answers HTTP 502, so they stay not lab-validated with that note. - Lab driver.
scripts/lab-gap-campaign.mjsdrives the built server over MCP stdio for owner-authorised lab campaigns (token files only; critical actions through preview,confirmand the server dialog).scripts/lab-status-tap.mjsoptionally records the HTTP status of each appliance response (method, route prefix and status only). - Error-code naming. Full mo...
Darktrace MCP v1.1.1
Darktrace MCP v1.1.1
- Lab evidence (gap campaign, 2026-10-06). New live runs on the Darktrace 7.1.0 lab, through the MCP stdio path and the final write controls (report). Now validated:
post_devices,post_aianalyst_investigations,post_pcaps,get_pcaps_filename(both the whole-file and theoutput_limit_exceededbranch),get_advancedsearch_api_search_query,get_advancedsearch_api_analyze_field_analysis_queryandget_advancedsearch_api_graph_graphmode_interval_querywith the current Base64 path encoding, andpost_antigena(activate, extend, clear, reactivate). 59 operations have lab evidence, 6 of them partial (was 56 and 11). Narrower partial notes for manual Antigena (connectiononly;pol,gpol,quarantineOutgoinggot HTTP 400 on a client-sensor device), subnets (label,uniqueHostnames) and the intel feed (addentry,addlist,expiry,removeentry;hostnameaccepted but not read back). The three tag DELETE operations applied live, but the lab gateway still answers HTTP 502, so they stay not lab-validated with that note. - Lab driver.
scripts/lab-gap-campaign.mjsdrives the built server over MCP stdio for owner-authorised lab campaigns (token files only; critical actions through preview,confirmand the server dialog).scripts/lab-status-tap.mjsoptionally records the HTTP status of each appliance response (method, route prefix and status only). - Error-code naming. Full model, component and enum lists surface the public error code
response_limit_exceeded; earlier lab notes used the internal error kindtoo_large. PCAP output refusals remainoutput_limit_exceeded. - CI and supply-chain controls. CodeQL runs the JavaScript/TypeScript
security-extendedqueries on production source and release scripts. ESLint with TypeScript and security rules runs in CI. Dependabot checks npm and GitHub Actions dependencies weekly, with runtime major upgrades reviewed by hand. OpenSSF Scorecard publishes scheduled analysis and SARIF results. Release helper fixes use fresh private temporary directories, exclusive output writes and descriptor-based reads that reject symlinks.
Known limitations in 1.1.1
- Email. The action remains excluded; Email reads remain unvalidated because the lab token gets HTTP 403. Schemas come from darktrace-sdk 0.10.1.
- Lab scope. One Darktrace 7.1.0 appliance and one broad token: 59 operations with evidence, 6 partial. Manual Antigena covers
connectiononly (pol,gpol,quarantineOutgoinggot HTTP 400 on a client-sensor device;quarantineandquarantineIncomingwere not run). Subnet writes coverlabelanduniqueHostnames. Intel-feed writes coveraddentry,addlist,expiryandremoveentry;hostnamewas accepted but its flag could not be read back. Models, components and enums coverresponsedataonly; full lists fail withresponse_limit_exceeded.get_cvesstill gets HTTP 500 (Darktrace/OT only) andget_filtertypesHTTP 302; redirects are never followed. - PCAP. Whole-file downloads and the
output_limit_exceededrefusal were checked live. Captures above about 45 KB still exceed the 60,000-character output budget. - DELETE.
delete_tags_tid_entities_teid,delete_tags_entitiesanddelete_tags_tidapplied live, but the lab gateway answered HTTP 502. They remain not lab-validated; the server reportswrite_outcome_unknown, never retries, and opens the write breaker after three failed or unknown outcomes in one process. - Lab residue. The campaign left a completed capture, an investigation and its alert, an empty intel-feed source, and cleared Antigena actions. Device and subnet changes were restored; tags were deleted. Earlier undeletable test comments remain. See the campaign report.
- The remaining limitations recorded for 1.1.0 still apply: consent and taint controls, per-process state, auditing, protected targets, token scope, egress, signing, distribution and preview eviction. The 1.1.0 lab-scope and PCAP notes below are historical; this section supersedes them.
Install
npx -y @nuoframework/darktrace-mcp@1.1.1 setupClaude Desktop: download darktrace-mcp-1.1.1.mcpb below and open it. Docker: pin the digest.
ghcr.io
ghcr.io/nuoframework/darktrace-mcp:1.1.1
ghcr.io/nuoframework/darktrace-mcp@sha256:a1e3944426eddae0e1fa13db0f58a380ae601562dcd4dd93f1767fa42a98a1e1
linux/amd64 sha256:16f7295753b292c123ea7864b29c7ebfb9b8a3b767fe5a9ed64add25c79ca497
linux/arm64 sha256:8c864d47f88f8e9cfdb26562f2dc73101acadd441173c38e545629fa355ed3d7
Pin clients to the digest: darktrace-mcp setup --runtime docker --image ghcr.io/nuoframework/darktrace-mcp@sha256:a1e3944426eddae0e1fa13db0f58a380ae601562dcd4dd93f1767fa42a98a1e1
Docker gates (ci.yml at 62b238a)
- CI run: https://github.com/nuoframework/darktrace-mcp/actions/runs/37506526165
- docker (amd64, ubuntu-24.04): success https://github.com/nuoframework/darktrace-mcp/actions/runs/37506526165/job/112417575565
- docker (arm64, ubuntu-24.04-arm): success https://github.com/nuoframework/darktrace-mcp/actions/runs/37506526165/job/112417575643
npm
@nuoframework/darktrace-mcp@1.1.1 was published through npm trusted publishing (OIDC from GitHub Actions) with a signed provenance statement; the attached tarball is the identical, verified artifact.
Verify
shasum -a 256 --ignore-missing -c SHA256SUMSDarktrace MCP v1.1.0
darktrace-mcp 1.1.0
- Public distribution. The package is
@nuoframework/darktrace-mcpon the public npm registry (published from CI with npm trusted publishing and provenance), the image isghcr.io/nuoframework/darktrace-mcp:<version>(linux/amd64 and linux/arm64, pinned by digest), and the server is described for the MCP Registry asio.github.nuoframework/darktrace-mcp(mcpNameinpackage.json,server.json). Bootstrap:npx -y @nuoframework/darktrace-mcp@1.1.0 setup. When run from the npx cache,setupcopies the verified package tree to~/.local/share/darktrace-mcp/<version>/and writes absolutenode+dist/src/index.jspaths, so clients never launchnpx. These channels are live only after the owner's publication steps (releases). - Full API surface with profiles. 77 of the 79 catalogue operations are executable, as 50 tools. One operation is excluded (the Darktrace/Email action, below) and one is deprecated (
GET /aianalyst/incidents).DARKTRACE_PROFILESselectsread(default),sensitive,write,criticalorall. Every Darktrace/Email read needssensitive. 56 operations have evidence from one Darktrace 7.1.0 lab, 11 of them only partial; the others are marked "not lab-validated" (tool reference). - Write controls. Ordinary writes accept
dryRun:truefor a value-free preview; without it they run, relying on the host's tool-permission prompt (DARKTRACE_WRITE_APPROVAL=host, the default). Critical actions need adryRun:truepreview, thenconfirm:truewith its single-usepreviewId(5 minutes) and, by default, an accepted server confirmation dialog (approved:true, at most one per session and four per process, 30-second deadline); a call withoutconfirm:trueis refused withconfirmation_required.DARKTRACE_CRITICAL_APPROVAL=hostneedsDARKTRACE_ACKNOWLEDGE_HOST_APPROVAL=true. Writes are rate-limited (at most 10 per minute), a breaker stops all writes after three failed or unknown outcomes in a row until restart, optional protected targets and fixed per-call target caps apply, and every preview, refusal and write is written to a hash-chained audit line on stderr. - Sensitive and write together. Any profile list with both
sensitiveandwrite, includingall, starts only withDARKTRACE_ACKNOWLEDGE_SENSITIVE_WRITE=true. - Darktrace/Email action excluded.
darktrace_email_actionis not registered in any profile: its signing and request schema are unvalidated and the lab token got 403. - Older variables.
DARKTRACE_SENSITIVE_READandDARKTRACE_WRITE_CRITICALstill work on their own. WhenDARKTRACE_PROFILESis set they may only agree with it or narrow it; a value that would add an unlisted capability stops startup. - Easier installation. New
darktrace-mcp setupwizard (hidden token entry,0600token files under~/.config/darktrace-mcp/, permission preset, automatic configuration of Claude Desktop, Claude Code, Codex, Cursor, VS Code, Windsurf, OpenCode and Gemini CLI with backups), plusconfig <client>,removeandtest. One-line installersscripts/install.shandscripts/install.ps1. - Claude Desktop extension.
npm run pack:mcpbbuilds a.mcpbbundle; Claude Desktop stores the tokens in the OS keychain. - Documentation restructure. Short bilingual READMEs; task-oriented guides (getting started, clients, configuration, troubleshooting, security overview) with Spanish versions in
docs/es/; generated tool reference (npm run docs:tools); past review and release reports moved todocs/history/.
Known limitations in 1.1.0
From the 1.1.0 final gate review §4. None is an exploitable defect found in the server, and none is an owner acceptance of risk.
- Email. The email action is excluded. Email reads are not lab-validated (the lab token got 403). Their schemas come from darktrace-sdk 0.10.1, and responses may be sparse.
- Lab scope. One 7.1.0 appliance and one broad token. Partial tests: Antigena manual block and
clearonly; subnets label only; intel feed add and remove only; models, components and enums only withresponsedata(full lists returntoo_large). Appliance errors:get_cvesreturns 500 andget_filtertypesreturns 302. Most write evidence predates the final write controls; after them, only the intel-feed critical flow, thepost_tagspreview, theconfirmation_requiredrefusal and POST Advanced Search were checked live. The GET Advanced Search forms passed live only before their path encoding changed; the current encoding has probe evidence for=only. - PCAP. A download is returned whole or fails with
output_limit_exceeded. Captures above about 45 KB do not fit the 60,000-character output budget. The current contract was never tested live. - DELETE and the write breaker. The lab gateway answers 502 to every DELETE after applying it, which the server records as
outcome:"unknown". Three in a row open the write breaker until restart. - Sensitive and write together. There is no taint control. Once acknowledged, ordinary free-text writes (comments, tag descriptions, labels) can carry sensitive data out of the appliance. Comments cannot be deleted and every appliance user can see them.
- Approval. Ordinary writes default to
writeApproval=host: no server prompt.hostmode delegates critical consent to the host. Auto-answering clients or "always allow" rules remove the human; the server cannot verify that a human answered. - Per-process state. Rate limits, the breaker, previews and the audit chain are per process; several host processes multiply the budgets. Audit chains share one genesis and carry no boot identifier. The audit goes to stderr only, with no external anchor. A restart resets the breaker.
- Sensitive reads are not audited.
- Protected targets are opt-in and match literal values only. For
post_antigenathey match the actioncodeid, not the device.maxTargetsis owner policy. - Token scope. There is no least-privilege token mapping per profile. Appliance token permissions remain the real ceiling.
- Data egress. Every result, including Base64 PCAP data and email metadata, reaches the MCP host and its model provider.
- Signing. GET Advanced Search depends on proxies keeping percent-encoding byte-exact. A combined query and JSON body is refused.
- Distribution. No image attestation; the SBOMs are inventories, not clearances. The ghcr image is rebuilt in
release.yml; it is not the CI-tested image. For 1.1.0, the linux/arm64 image passed the local Docker gates; linux/amd64 is verified only by CI on the release commit, and there is no vulnerability scan of the 1.1.0 runtime yet. Docker Desktop needsDARKTRACE_TOKEN_FILE_OWNER=root-or-current. Theserver.jsonOCI launch passes tokens as container environment variables, readable by anyone with Docker access. Native Windows cannot protect token files. - Previews. The preview store evicts the oldest live critical preview once it holds 256 (availability only).
- Lab residue. Undeletable
[mcp-test]and[mcp-ux]comments remain on the lab appliance.
Install
npx -y @nuoframework/darktrace-mcp@1.1.0 setupClaude Desktop: download darktrace-mcp-1.1.0.mcpb below and open it. Docker: pin the digest.
ghcr.io
ghcr.io/nuoframework/darktrace-mcp:1.1.0
ghcr.io/nuoframework/darktrace-mcp@sha256:dd79adb2dfe78134fa9721508a1f46776ed1736158dcf0b7f54e1dd0bca2d511
linux/amd64 sha256:4828a4782695127a759f281e6786b24d5bd9b785ab4c56d64a965888e9a5df84
linux/arm64 sha256:e4317b8ee34d8342498590279ca868b6691733bef9562f2a9071af318925a978
Pin clients to the digest: darktrace-mcp setup --runtime docker --image ghcr.io/nuoframework/darktrace-mcp@sha256:dd79adb2dfe78134fa9721508a1f46776ed1736158dcf0b7f54e1dd0bca2d511
Docker gates (ci.yml at f95e798)
- CI run: https://github.com/nuoframework/darktrace-mcp/actions/runs/37497433186
- docker (amd64, ubuntu-24.04): success https://github.com/nuoframework/darktrace-mcp/actions/runs/37497433186/job/112386889221
- docker (arm64, ubuntu-24.04-arm): success https://github.com/nuoframework/darktrace-mcp/actions/runs/37497433186/job/112386889549
npm
@nuoframework/darktrace-mcp@1.1.0 is live on the public npm registry with a signed provenance statement (Sigstore log index 3112942967; tarball SHA-256 1b36cc9f65d9dbdd9558f1dfc2e5aa96041a1fdbc0a3f6ab33ceb4862f257c49, shasum 98bb85d46b286fc89822b2524f5ad2e6a9d58b41). The attached tarball is the identical, verified artifact.
Verify
shasum -a 256 --ignore-missing -c SHA256SUMSEvidence: security-receipt.json, verification.json, build-evidence.json, runtime-sbom.cdx.json, mcp-tool-contracts.json. Disclosed residual risks: see CHANGELOG 'Known limitations in 1.1.0' and docs/security/final-gate-review-1.1.0.md.
Darktrace MCP v1.0.0 — read-only release
Darktrace MCP 1.0.0 (private)
Unofficial MCP. Developed by an independent third party, unaffiliated with Darktrace and without authorization from Darktrace. · MCP no oficial. Desarrollado por un tercero independiente, sin afiliación con Darktrace y sin autorización de Darktrace. Claims / reclamaciones: contacto@pabloarrabal.com
English
First stable private release: 15 read-only MCP tools covering 19 validated GET selectors, identical in the read and read + sensitiveRead profiles. Writes, critical operations, email, PCAP export and HTTP transport are not available.
Runtime. A nonroot, shell-free scratch Docker image with no listener. It uses Alpine 3.24 packages: Alpine-maintained, musl-linked Node.js 24.18.1 with shared OpenSSL 3.5.9. This is a distribution-maintained runtime, not an upstream Node.js Tier 1 binary.
Evidence.
- Lab: 19/19 real queries passed on Darktrace 7.1.0 on 2026-10-06, using arm64 image
sha256:8cd85604…. The released images use the same query/policy implementation and dependencies; the only production source difference is the1.0.0version literal, which was reviewed in the final diff and covered by the SDK and native tests. The lab is closed, and the released images were not retested live. - CI: run 37423665585 on source commit
2adb84bpassed all jobs: Node 22/24 offline plus native Docker on amd64 and arm64, 130 functional + 325 security tests, 0 skipped. The release tag points to a later documentation-only commit with identical production, build and shipped-document files. - Scans: Trivy 0. Grype keeps a High for zlib 1.3.2 (CVE-2026-85091). The library is affected, but an independent review found its vulnerable code is not in the application's execution path. zlib is not fixed: Alpine has no fixed package yet. Grype's Medium for
ada(CVE-2024-9410) is a product-name collision. This is not a zero-CVE claim.
Install (Docker, recommended). Choose linux-arm64 or linux-amd64:
gh release download v1.0.0 --repo nuoframework/darktrace-mcp \
--pattern 'darktrace-mcp-1.0.0-linux-arm64.tar.gz' --pattern SHA256SUMS
shasum -a 256 --ignore-missing -c SHA256SUMS
docker load --input darktrace-mcp-1.0.0-linux-arm64.tar.gz
docker image inspect --format '{{.Id}}' darktrace-mcp:1.0.0-arm64On amd64, use the amd64 archive and the darktrace-mcp:1.0.0-amd64 tag. The loaded ID must match the table below. Configure the client with that sha256: ID, --pull=never, --read-only, --cap-drop=ALL, --security-opt=no-new-privileges and read-only token-file mounts (see README). No public registry image exists.
Native package. Install darktrace-mcp-1.0.0.tgz with npm install --ignore-scripts --omit=dev. Only do this on a maintained Node.js runtime whose OpenSSL you have verified as 3.5.9 or later. Official upstream Node.js releases examined on 2026-10-05 bundle 3.5.8.
Español
Primera versión estable privada: 15 herramientas MCP de solo lectura que cubren 19 selectores GET validados, idénticas en los perfiles read y read + sensitiveRead. No hay escrituras, operaciones críticas, email, exportación PCAP ni transporte HTTP.
Runtime. Imagen Docker scratch no root, sin shell ni listener. Usa paquetes de Alpine 3.24: Node.js 24.18.1 mantenido por Alpine, enlazado con musl y con OpenSSL 3.5.9 compartido. Es un runtime mantenido por la distribución, no un binario Tier 1 de Node.js upstream.
Evidencia.
- Lab: 19/19 consultas reales superadas en Darktrace 7.1.0 el 2026-10-06, con la imagen arm64
sha256:8cd85604…. Las imágenes publicadas usan la misma implementación de consultas y políticas y las mismas dependencias; la única diferencia en el código de producción es el literal de versión1.0.0, revisado en el diff final y cubierto por las pruebas SDK y nativas. El lab está cerrado y las imágenes publicadas no se volvieron a probar en vivo. - CI: la ejecución 37423665585 sobre el commit
2adb84bsuperó todos los jobs: Node 22/24 offline y Docker nativo en amd64 y arm64, 130 pruebas funcionales + 325 de seguridad, 0 omitidas. La etiqueta apunta a un commit posterior solo de documentación, con archivos de producción, compilación y documentos distribuidos idénticos. - Escaneos: Trivy 0. Grype mantiene un High en zlib 1.3.2 (CVE-2026-85091). La biblioteca está afectada, pero una revisión independiente determinó que su código vulnerable no está en la ruta de ejecución de la aplicación. zlib no está corregido: Alpine aún no tiene paquete corregido. El Medium de Grype para
ada(CVE-2024-9410) es una colisión de nombre de producto. No se afirma cero CVE.
Instalación (Docker, recomendada). Elige linux-arm64 o linux-amd64 y usa los comandos de la sección en inglés. El ID cargado debe coincidir con la tabla. Configura el cliente con ese ID sha256:, --pull=never, --read-only, --cap-drop=ALL, --security-opt=no-new-privileges y tokens montados en solo lectura (ver README.es). No existe imagen en un registro público.
Paquete nativo. Instala darktrace-mcp-1.0.0.tgz con npm install --ignore-scripts --omit=dev. Hazlo solo con un runtime Node.js mantenido cuyo OpenSSL hayas verificado como 3.5.9 o posterior.
Assets / Archivos
| Asset | SHA-256 | Image ID |
|---|---|---|
darktrace-mcp-1.0.0-linux-amd64.tar.gz |
3594f1051a1f334603681b3869b25dbe9b0c52e6ec5e243b39b457e775a86cad |
sha256:59a490c78a08b63e6757a7d872526a16b60cd119efc2240e607a97581844c0a3 (darktrace-mcp:1.0.0-amd64) |
darktrace-mcp-1.0.0-linux-arm64.tar.gz |
8c0d7c8ddb18c4d20d38802105ebe4d55a1018242ad074206314e77e064cfe5e |
sha256:bc0a29b49347c2ed21557b34193a2b8aa26017c8459c526665e09ee632a03f92 (darktrace-mcp:1.0.0-arm64) |
darktrace-mcp-1.0.0.tgz |
3abf8b7a5be5a0d56b23529c62a883fbf49a28cb08a6e606d6ac3fcb9916b37b |
— |
darktrace-mcp-1.0.0-security-provenance.tar.gz |
356c91522678bfbaafcfafb8b12e87b1ec9475014ec7389719a6faceda316b31 |
— |
darktrace-mcp-1.0.0-native-ci-evidence.tar.gz |
0b2a8954a9a22ad9b406f12260bea304e4558feb4efbc8bae70f7ebe40b0d86e |
— |
darktrace-mcp-1.0.0-package-evidence.tar.gz |
b6e538ec8caf823832c515e41d0c9bf63b2e81063e37c5d2762ae10311ca9b74 |
— |
SHA256SUMS |
Verifies all six archives / Verifica los seis archivos | — |
The package-evidence archive preserves the original package verifier sidecars and their canonical checksum file. The top-level SHA256SUMS covers every downloadable archive, including Docker. Native CI evidence contains the complete final amd64 and arm64 suite receipts.
El archivo package-evidence conserva los ficheros originales del verificador del paquete y su checksum canónico. El SHA256SUMS de la release verifica todos los archivos descargables, incluido Docker. Las evidencias de CI incluyen los resultados completos de amd64 y arm64.
Darktrace MCP v0.1.0-alpha.0 — private offline alpha
Darktrace MCP 0.1.0-alpha.0
Private prerelease with installation instructions, checksums and offline verification evidence.
Included
- Read-first stdio MCP server: 54 operations executable by profile, five critical previews, 19 blocked and one excluded.
- Protected credential files, constrained HTTPS transport, response minimization and write audit controls.
- English documentation and Spanish quickstart; versioned installation from release assets.
- Threat modeling, independent source and artifact reviews; no known open findings in those review scopes.
Verification
- Reviewed commit:
8b4f42a0fa7d5ef2688176493a83b4cd10617949. - GitHub CI: Node 22 and 24 on Linux.
- Local Node 22/24: 102 standard tests passed; 238 adversarial cases, 235 passed and three OS-dependent cases blocked/skipped.
- Reproducible runtime archive, exact dependency/SRI checks and independently reviewed package assets.
Installation
Follow private release installation. Verify SHA256SUMS before installation. No npm or container publication.
Pending validation
Authenticated Darktrace 7.1 lab compatibility, provider eligibility and real deployment network pinning remain pending. Docker was not built locally. This prerelease is not a security certification.
The next alpha will record lab validation results and changes in its own release notes.