Repository navigation
Darktrace MCP v1.1.0
darktrace-mcp 1.1.0
- Public distribution. The package is
@nuoframework/darktrace-mcpon the public npm registry (published from CI with npm trusted publishing and provenance), the image isghcr.io/nuoframework/darktrace-mcp:<version>(linux/amd64 and linux/arm64, pinned by digest), and the server is described for the MCP Registry asio.github.nuoframework/darktrace-mcp(mcpNameinpackage.json,server.json). Bootstrap:npx -y @nuoframework/darktrace-mcp@1.1.0 setup. When run from the npx cache,setupcopies the verified package tree to~/.local/share/darktrace-mcp/<version>/and writes absolutenode+dist/src/index.jspaths, so clients never launchnpx. These channels are live only after the owner's publication steps (releases). - Full API surface with profiles. 77 of the 79 catalogue operations are executable, as 50 tools. One operation is excluded (the Darktrace/Email action, below) and one is deprecated (
GET /aianalyst/incidents).DARKTRACE_PROFILESselectsread(default),sensitive,write,criticalorall. Every Darktrace/Email read needssensitive. 56 operations have evidence from one Darktrace 7.1.0 lab, 11 of them only partial; the others are marked "not lab-validated" (tool reference). - Write controls. Ordinary writes accept
dryRun:truefor a value-free preview; without it they run, relying on the host's tool-permission prompt (DARKTRACE_WRITE_APPROVAL=host, the default). Critical actions need adryRun:truepreview, thenconfirm:truewith its single-usepreviewId(5 minutes) and, by default, an accepted server confirmation dialog (approved:true, at most one per session and four per process, 30-second deadline); a call withoutconfirm:trueis refused withconfirmation_required.DARKTRACE_CRITICAL_APPROVAL=hostneedsDARKTRACE_ACKNOWLEDGE_HOST_APPROVAL=true. Writes are rate-limited (at most 10 per minute), a breaker stops all writes after three failed or unknown outcomes in a row until restart, optional protected targets and fixed per-call target caps apply, and every preview, refusal and write is written to a hash-chained audit line on stderr. - Sensitive and write together. Any profile list with both
sensitiveandwrite, includingall, starts only withDARKTRACE_ACKNOWLEDGE_SENSITIVE_WRITE=true. - Darktrace/Email action excluded.
darktrace_email_actionis not registered in any profile: its signing and request schema are unvalidated and the lab token got 403. - Older variables.
DARKTRACE_SENSITIVE_READandDARKTRACE_WRITE_CRITICALstill work on their own. WhenDARKTRACE_PROFILESis set they may only agree with it or narrow it; a value that would add an unlisted capability stops startup. - Easier installation. New
darktrace-mcp setupwizard (hidden token entry,0600token files under~/.config/darktrace-mcp/, permission preset, automatic configuration of Claude Desktop, Claude Code, Codex, Cursor, VS Code, Windsurf, OpenCode and Gemini CLI with backups), plusconfig <client>,removeandtest. One-line installersscripts/install.shandscripts/install.ps1. - Claude Desktop extension.
npm run pack:mcpbbuilds a.mcpbbundle; Claude Desktop stores the tokens in the OS keychain. - Documentation restructure. Short bilingual READMEs; task-oriented guides (getting started, clients, configuration, troubleshooting, security overview) with Spanish versions in
docs/es/; generated tool reference (npm run docs:tools); past review and release reports moved todocs/history/.
Known limitations in 1.1.0
From the 1.1.0 final gate review §4. None is an exploitable defect found in the server, and none is an owner acceptance of risk.
- Email. The email action is excluded. Email reads are not lab-validated (the lab token got 403). Their schemas come from darktrace-sdk 0.10.1, and responses may be sparse.
- Lab scope. One 7.1.0 appliance and one broad token. Partial tests: Antigena manual block and
clearonly; subnets label only; intel feed add and remove only; models, components and enums only withresponsedata(full lists returntoo_large). Appliance errors:get_cvesreturns 500 andget_filtertypesreturns 302. Most write evidence predates the final write controls; after them, only the intel-feed critical flow, thepost_tagspreview, theconfirmation_requiredrefusal and POST Advanced Search were checked live. The GET Advanced Search forms passed live only before their path encoding changed; the current encoding has probe evidence for=only. - PCAP. A download is returned whole or fails with
output_limit_exceeded. Captures above about 45 KB do not fit the 60,000-character output budget. The current contract was never tested live. - DELETE and the write breaker. The lab gateway answers 502 to every DELETE after applying it, which the server records as
outcome:"unknown". Three in a row open the write breaker until restart. - Sensitive and write together. There is no taint control. Once acknowledged, ordinary free-text writes (comments, tag descriptions, labels) can carry sensitive data out of the appliance. Comments cannot be deleted and every appliance user can see them.
- Approval. Ordinary writes default to
writeApproval=host: no server prompt.hostmode delegates critical consent to the host. Auto-answering clients or "always allow" rules remove the human; the server cannot verify that a human answered. - Per-process state. Rate limits, the breaker, previews and the audit chain are per process; several host processes multiply the budgets. Audit chains share one genesis and carry no boot identifier. The audit goes to stderr only, with no external anchor. A restart resets the breaker.
- Sensitive reads are not audited.
- Protected targets are opt-in and match literal values only. For
post_antigenathey match the actioncodeid, not the device.maxTargetsis owner policy. - Token scope. There is no least-privilege token mapping per profile. Appliance token permissions remain the real ceiling.
- Data egress. Every result, including Base64 PCAP data and email metadata, reaches the MCP host and its model provider.
- Signing. GET Advanced Search depends on proxies keeping percent-encoding byte-exact. A combined query and JSON body is refused.
- Distribution. No image attestation; the SBOMs are inventories, not clearances. The ghcr image is rebuilt in
release.yml; it is not the CI-tested image. For 1.1.0, the linux/arm64 image passed the local Docker gates; linux/amd64 is verified only by CI on the release commit, and there is no vulnerability scan of the 1.1.0 runtime yet. Docker Desktop needsDARKTRACE_TOKEN_FILE_OWNER=root-or-current. Theserver.jsonOCI launch passes tokens as container environment variables, readable by anyone with Docker access. Native Windows cannot protect token files. - Previews. The preview store evicts the oldest live critical preview once it holds 256 (availability only).
- Lab residue. Undeletable
[mcp-test]and[mcp-ux]comments remain on the lab appliance.
Install
npx -y @nuoframework/darktrace-mcp@1.1.0 setupClaude Desktop: download darktrace-mcp-1.1.0.mcpb below and open it. Docker: pin the digest.
ghcr.io
ghcr.io/nuoframework/darktrace-mcp:1.1.0
ghcr.io/nuoframework/darktrace-mcp@sha256:dd79adb2dfe78134fa9721508a1f46776ed1736158dcf0b7f54e1dd0bca2d511
linux/amd64 sha256:4828a4782695127a759f281e6786b24d5bd9b785ab4c56d64a965888e9a5df84
linux/arm64 sha256:e4317b8ee34d8342498590279ca868b6691733bef9562f2a9071af318925a978
Pin clients to the digest: darktrace-mcp setup --runtime docker --image ghcr.io/nuoframework/darktrace-mcp@sha256:dd79adb2dfe78134fa9721508a1f46776ed1736158dcf0b7f54e1dd0bca2d511
Docker gates (ci.yml at f95e798)
- CI run: https://github.com/nuoframework/darktrace-mcp/actions/runs/37497433186
- docker (amd64, ubuntu-24.04): success https://github.com/nuoframework/darktrace-mcp/actions/runs/37497433186/job/112386889221
- docker (arm64, ubuntu-24.04-arm): success https://github.com/nuoframework/darktrace-mcp/actions/runs/37497433186/job/112386889549
npm
@nuoframework/darktrace-mcp@1.1.0 is live on the public npm registry with a signed provenance statement (Sigstore log index 3112942967; tarball SHA-256 1b36cc9f65d9dbdd9558f1dfc2e5aa96041a1fdbc0a3f6ab33ceb4862f257c49, shasum 98bb85d46b286fc89822b2524f5ad2e6a9d58b41). The attached tarball is the identical, verified artifact.
Verify
shasum -a 256 --ignore-missing -c SHA256SUMSEvidence: security-receipt.json, verification.json, build-evidence.json, runtime-sbom.cdx.json, mcp-tool-contracts.json. Disclosed residual risks: see CHANGELOG 'Known limitations in 1.1.0' and docs/security/final-gate-review-1.1.0.md.