Repository navigation
Darktrace MCP v1.1.1
Darktrace MCP v1.1.1
- Lab evidence (gap campaign, 2026-10-06). New live runs on the Darktrace 7.1.0 lab, through the MCP stdio path and the final write controls (report). Now validated:
post_devices,post_aianalyst_investigations,post_pcaps,get_pcaps_filename(both the whole-file and theoutput_limit_exceededbranch),get_advancedsearch_api_search_query,get_advancedsearch_api_analyze_field_analysis_queryandget_advancedsearch_api_graph_graphmode_interval_querywith the current Base64 path encoding, andpost_antigena(activate, extend, clear, reactivate). 59 operations have lab evidence, 6 of them partial (was 56 and 11). Narrower partial notes for manual Antigena (connectiononly;pol,gpol,quarantineOutgoinggot HTTP 400 on a client-sensor device), subnets (label,uniqueHostnames) and the intel feed (addentry,addlist,expiry,removeentry;hostnameaccepted but not read back). The three tag DELETE operations applied live, but the lab gateway still answers HTTP 502, so they stay not lab-validated with that note. - Lab driver.
scripts/lab-gap-campaign.mjsdrives the built server over MCP stdio for owner-authorised lab campaigns (token files only; critical actions through preview,confirmand the server dialog).scripts/lab-status-tap.mjsoptionally records the HTTP status of each appliance response (method, route prefix and status only). - Error-code naming. Full model, component and enum lists surface the public error code
response_limit_exceeded; earlier lab notes used the internal error kindtoo_large. PCAP output refusals remainoutput_limit_exceeded. - CI and supply-chain controls. CodeQL runs the JavaScript/TypeScript
security-extendedqueries on production source and release scripts. ESLint with TypeScript and security rules runs in CI. Dependabot checks npm and GitHub Actions dependencies weekly, with runtime major upgrades reviewed by hand. OpenSSF Scorecard publishes scheduled analysis and SARIF results. Release helper fixes use fresh private temporary directories, exclusive output writes and descriptor-based reads that reject symlinks.
Known limitations in 1.1.1
- Email. The action remains excluded; Email reads remain unvalidated because the lab token gets HTTP 403. Schemas come from darktrace-sdk 0.10.1.
- Lab scope. One Darktrace 7.1.0 appliance and one broad token: 59 operations with evidence, 6 partial. Manual Antigena covers
connectiononly (pol,gpol,quarantineOutgoinggot HTTP 400 on a client-sensor device;quarantineandquarantineIncomingwere not run). Subnet writes coverlabelanduniqueHostnames. Intel-feed writes coveraddentry,addlist,expiryandremoveentry;hostnamewas accepted but its flag could not be read back. Models, components and enums coverresponsedataonly; full lists fail withresponse_limit_exceeded.get_cvesstill gets HTTP 500 (Darktrace/OT only) andget_filtertypesHTTP 302; redirects are never followed. - PCAP. Whole-file downloads and the
output_limit_exceededrefusal were checked live. Captures above about 45 KB still exceed the 60,000-character output budget. - DELETE.
delete_tags_tid_entities_teid,delete_tags_entitiesanddelete_tags_tidapplied live, but the lab gateway answered HTTP 502. They remain not lab-validated; the server reportswrite_outcome_unknown, never retries, and opens the write breaker after three failed or unknown outcomes in one process. - Lab residue. The campaign left a completed capture, an investigation and its alert, an empty intel-feed source, and cleared Antigena actions. Device and subnet changes were restored; tags were deleted. Earlier undeletable test comments remain. See the campaign report.
- The remaining limitations recorded for 1.1.0 still apply: consent and taint controls, per-process state, auditing, protected targets, token scope, egress, signing, distribution and preview eviction. The 1.1.0 lab-scope and PCAP notes below are historical; this section supersedes them.
Install
npx -y @nuoframework/darktrace-mcp@1.1.1 setupClaude Desktop: download darktrace-mcp-1.1.1.mcpb below and open it. Docker: pin the digest.
ghcr.io
ghcr.io/nuoframework/darktrace-mcp:1.1.1
ghcr.io/nuoframework/darktrace-mcp@sha256:a1e3944426eddae0e1fa13db0f58a380ae601562dcd4dd93f1767fa42a98a1e1
linux/amd64 sha256:16f7295753b292c123ea7864b29c7ebfb9b8a3b767fe5a9ed64add25c79ca497
linux/arm64 sha256:8c864d47f88f8e9cfdb26562f2dc73101acadd441173c38e545629fa355ed3d7
Pin clients to the digest: darktrace-mcp setup --runtime docker --image ghcr.io/nuoframework/darktrace-mcp@sha256:a1e3944426eddae0e1fa13db0f58a380ae601562dcd4dd93f1767fa42a98a1e1
Docker gates (ci.yml at 62b238a)
- CI run: https://github.com/nuoframework/darktrace-mcp/actions/runs/37506526165
- docker (amd64, ubuntu-24.04): success https://github.com/nuoframework/darktrace-mcp/actions/runs/37506526165/job/112417575565
- docker (arm64, ubuntu-24.04-arm): success https://github.com/nuoframework/darktrace-mcp/actions/runs/37506526165/job/112417575643
npm
@nuoframework/darktrace-mcp@1.1.1 was published through npm trusted publishing (OIDC from GitHub Actions) with a signed provenance statement; the attached tarball is the identical, verified artifact.
Verify
shasum -a 256 --ignore-missing -c SHA256SUMS