Skip to content

Darktrace MCP v1.1.1

Choose a tag to compare

@nuoframework nuoframework released this 06 Oct 18:10
· 98 commits to main since this release
62b238a

Darktrace MCP v1.1.1

  • Lab evidence (gap campaign, 2026-10-06). New live runs on the Darktrace 7.1.0 lab, through the MCP stdio path and the final write controls (report). Now validated: post_devices, post_aianalyst_investigations, post_pcaps, get_pcaps_filename (both the whole-file and the output_limit_exceeded branch), get_advancedsearch_api_search_query, get_advancedsearch_api_analyze_field_analysis_query and get_advancedsearch_api_graph_graphmode_interval_query with the current Base64 path encoding, and post_antigena (activate, extend, clear, reactivate). 59 operations have lab evidence, 6 of them partial (was 56 and 11). Narrower partial notes for manual Antigena (connection only; pol, gpol, quarantineOutgoing got HTTP 400 on a client-sensor device), subnets (label, uniqueHostnames) and the intel feed (addentry, addlist, expiry, removeentry; hostname accepted but not read back). The three tag DELETE operations applied live, but the lab gateway still answers HTTP 502, so they stay not lab-validated with that note.
  • Lab driver. scripts/lab-gap-campaign.mjs drives the built server over MCP stdio for owner-authorised lab campaigns (token files only; critical actions through preview, confirm and the server dialog). scripts/lab-status-tap.mjs optionally records the HTTP status of each appliance response (method, route prefix and status only).
  • Error-code naming. Full model, component and enum lists surface the public error code response_limit_exceeded; earlier lab notes used the internal error kind too_large. PCAP output refusals remain output_limit_exceeded.
  • CI and supply-chain controls. CodeQL runs the JavaScript/TypeScript security-extended queries on production source and release scripts. ESLint with TypeScript and security rules runs in CI. Dependabot checks npm and GitHub Actions dependencies weekly, with runtime major upgrades reviewed by hand. OpenSSF Scorecard publishes scheduled analysis and SARIF results. Release helper fixes use fresh private temporary directories, exclusive output writes and descriptor-based reads that reject symlinks.

Known limitations in 1.1.1

  • Email. The action remains excluded; Email reads remain unvalidated because the lab token gets HTTP 403. Schemas come from darktrace-sdk 0.10.1.
  • Lab scope. One Darktrace 7.1.0 appliance and one broad token: 59 operations with evidence, 6 partial. Manual Antigena covers connection only (pol, gpol, quarantineOutgoing got HTTP 400 on a client-sensor device; quarantine and quarantineIncoming were not run). Subnet writes cover label and uniqueHostnames. Intel-feed writes cover addentry, addlist, expiry and removeentry; hostname was accepted but its flag could not be read back. Models, components and enums cover responsedata only; full lists fail with response_limit_exceeded. get_cves still gets HTTP 500 (Darktrace/OT only) and get_filtertypes HTTP 302; redirects are never followed.
  • PCAP. Whole-file downloads and the output_limit_exceeded refusal were checked live. Captures above about 45 KB still exceed the 60,000-character output budget.
  • DELETE. delete_tags_tid_entities_teid, delete_tags_entities and delete_tags_tid applied live, but the lab gateway answered HTTP 502. They remain not lab-validated; the server reports write_outcome_unknown, never retries, and opens the write breaker after three failed or unknown outcomes in one process.
  • Lab residue. The campaign left a completed capture, an investigation and its alert, an empty intel-feed source, and cleared Antigena actions. Device and subnet changes were restored; tags were deleted. Earlier undeletable test comments remain. See the campaign report.
  • The remaining limitations recorded for 1.1.0 still apply: consent and taint controls, per-process state, auditing, protected targets, token scope, egress, signing, distribution and preview eviction. The 1.1.0 lab-scope and PCAP notes below are historical; this section supersedes them.

Install

npx -y @nuoframework/darktrace-mcp@1.1.1 setup

Claude Desktop: download darktrace-mcp-1.1.1.mcpb below and open it. Docker: pin the digest.

ghcr.io

ghcr.io/nuoframework/darktrace-mcp:1.1.1
ghcr.io/nuoframework/darktrace-mcp@sha256:a1e3944426eddae0e1fa13db0f58a380ae601562dcd4dd93f1767fa42a98a1e1
linux/amd64 sha256:16f7295753b292c123ea7864b29c7ebfb9b8a3b767fe5a9ed64add25c79ca497
linux/arm64 sha256:8c864d47f88f8e9cfdb26562f2dc73101acadd441173c38e545629fa355ed3d7

Pin clients to the digest: darktrace-mcp setup --runtime docker --image ghcr.io/nuoframework/darktrace-mcp@sha256:a1e3944426eddae0e1fa13db0f58a380ae601562dcd4dd93f1767fa42a98a1e1

Docker gates (ci.yml at 62b238a)

npm

@nuoframework/darktrace-mcp@1.1.1 was published through npm trusted publishing (OIDC from GitHub Actions) with a signed provenance statement; the attached tarball is the identical, verified artifact.

Verify

shasum -a 256 --ignore-missing -c SHA256SUMS