Repository navigation
Changelog
1.1.2 — 2026-10-06
- Docker setup is self-service. Choosing
2) dockerinsetupno longer asks for an image ID. The wizard resolves thedockerpath, checks that the daemon answers (docker version) and explains what to install or start when it does not, proposesghcr.io/nuoframework/darktrace-mcp:<package version>, accepts a tag, aname@sha256:digest or a localsha256:image ID (strictly validated), offersPull it now? [Y/n]when the image is missing (--pullfor--yesruns) and showsdocker pullprogress. Client entries keep starting the immutable image ID with--pull=never, the caller's UID:GID and read-only token mounts;setup.jsonand the summary record the image ID and the registry digest for comparison with the GitHub Release notes. Nothing is written when a preflight step fails. configandtestwith Docker.config <client>reuses the saved image ID and prints its digest.test/doctor --onlinefirst runs the image's--check-configin a container with the client entry's mounts and user and no network, then checks the appliance from the host.- No saved appliance URL in prompts. The wizard's URL prompt is
Darktrace appliance URL (https://...):with no default and never prints a previously saved address; an empty answer is refused.--urland non-interactive reruns keep working. - Plugin bundle.
claude-plugin/packages the server as a Claude Code plugin (manifest withuserConfigfor the appliance URL, both tokens, profiles, the sensitive-write acknowledgement and the signature date format; apackage.jsonandpackage-lock.jsonthat install the published package at the pinned version when the plugin is installed;.mcp.jsonstartingnodeon the installed entry; an icon; thedarktrace-investigationskill) and, in the same folder, the portableplugin.jsonandmcp.jsonthat Codex reads (Codex keeps the pinnednpxlauncher). Root.claude-plugin/marketplace.jsonand.agents/plugins/marketplace.jsonexpose it as a repository marketplace for Claude Code and Codex. Plugin distribution describes the Claude Directory submission and the per-release version bump. uninstall. Newdarktrace-mcp uninstall(aliasremove --all) shows a plan, asks once (--yes,--dry-run), removes thedarktraceentry from every client (backups kept), deletes the stored tokens,setup.json, the installer directory and the fixed copies (--keep-copieskeeps them), removes the image ID recorded by setup with--docker(never other images), and prints thenpm uninstall -gcommand when the package is installed globally. Symbolic links and unknown files are never touched.- Signed releases with provenance. The
github-releasejob now signs every release asset with cosign (keyless Sigstore bundle<asset>.sigstore.json, identityrelease.yml@refs/tags/v<version>) and attests SLSA v1 build provenance for all assets withactions/attest(darktrace-mcp-<version>.intoto.jsonl, full bundledarktrace-mcp-<version>.provenance.sigstore.json, also stored in the GitHub attestations API). Verification commands: releases. The newsign-release.ymlworkflow adds signature bundles to releases published before this change without touching their assets (supply-chain checks). - Pinned npm fallback.
publish-npmno longer runsnpm install -g npm@^11when the bundled npm is too old; it downloads the npm 11.21.0 tarball, verifies its registry sha512 integrity and runs it in place. - Property-based tests. 22 new tests with fast-check (
test/unit/*-properties.test.ts) covervalidatePathSegment,checkInputandvalidateSearchHash, the request signer (determinism, wire encoding round trip, encoded and unencoded signature modes, the Advanced Search Base64 segment, JSON bodies, UTC dates) and the canonical JSON andargsDigestbehind preview binding and the audit chain. Functional CI pin 245 → 267 (release pins). - Runtime image: zlib 1.3.2-r1. Alpine v3.24 replaced
zlib-1.3.2-r0with1.3.2-r1, whose recipe backports the fix for CVE-2026-85091 (the High finding retained in the patched runtime review). The architecture pins in theDockerfilenow name the r1 packages and their SHA-256; nothing else in the pinned input set changed. The CI Docker gates fetch and verify the set on every run, so the old pins could no longer be fetched. - Scorecard.
scorecard.ymlpassesrepo_token: ${{ secrets.SCORECARD_TOKEN || github.token }}so the owner can enable the Branch-Protection check with a fine-grained token. Supply-chain checks now record each Scorecard check, its status and the accepted gaps, and the remaining OpenSSF Best Practices silver criteria. - CodeQL. The open code-scanning alerts in the release and Docker scripts are fixed (
scripts/prepare-docker-runtime.mjs,scripts/lab-read-smoke.mjs,scripts/verify-release.mjs); no production source changed.scripts/prepare-docker-runtime.mjsalso fetches the committed APK revisions from the Alpine archive when the repository index has moved on, so the pinned input set stays reproducible. - Release workflow.
publish-npmfails only whennpm publishitself fails; it then polls the public registry for up to 15 minutes and records the tarball shasum and sha512 integrity when the version is still propagating.github-releaseruns unless a gate or a publish actually failed, and records the npm status in the release body (releases). - Dependencies. Runtime
zod4.2.0 → 4.6.5; development@types/node24.0.0 → 26.6.4 andfast-check4.10.2 added; GitHub Actions pins bumped by Dependabot.@modelcontextprotocol/serverstays at 2.3.0. - Repository and documentation. No lab appliance hostnames remain in evidence, reports or probe defaults.
CONTRIBUTING.mddescribes the pull request process and acceptance requirements;SECURITY.mdstates the vulnerability response-time commitment; both READMEs carry the OpenSSF Best Practices (project 15261) and Scorecard badges. The Darktrace/Email API shapes observed from a console capture are recorded as documentation only (observed shapes); the email action stays excluded. - Version pins. Install snippets,
server.json,manifest.jsonand the version literal now say 1.1.2. The Claude Code plugin inclaude-plugin/keeps its exact pin on 1.1.1 until the registry shows 1.1.2 (plugin distribution); the release pins are in release-pins-1.1.2.md.
Known limitations in 1.1.2
- Surface and lab evidence unchanged. 1.1.2 registers the same 77 executable operations in 50 tools as 1.1.1, with the same tool contracts and profile hashes; 59 operations have lab evidence, 6 of them partial. No new lab run was made for 1.1.2: production source changes are limited to
src/cli/and the version literal. Every item under known limitations in 1.1.1 still applies. - Distribution. Release assets are signed and carry build provenance from this release; the ghcr image still has no attestation, and the image published by
release.ymlis rebuilt, not the image the CI Docker job tested. The runtime image carries zlib 1.3.2-r1 (the Alpine backport for CVE-2026-85091); no new vulnerability scan of the 1.1.x runtime is recorded. The Docker setup path resolves and records the image digest but verifies no signature for the image: compare the digest with the release notes. - Plugin pin lag. The plugin installs an exact npm version, so the plugin on
mainfollows a release by one merge; until that merge it installs the previous version. - Uninstall scope.
uninstallremoves only whatsetupwrote: thedarktraceclient entries, the token files,setup.json, the fixed copies and, with--docker, the one recorded image ID. A globalnpm install -gis reported, not removed; files it does not recognise are left in place.
1.1.1 — 2026-10-06
- Lab evidence (gap campaign, 2026-10-06). New live runs on the Darktrace 7.1.0 lab, through the MCP stdio path and the final write controls (report). Now validated:
post_devices,post_aianalyst_investigations,post_pcaps,get_pcaps_filename(both the whole-file and theoutput_limit_exceededbranch),get_advancedsearch_api_search_query,get_advancedsearch_api_analyze_field_analysis_queryandget_advancedsearch_api_graph_graphmode_interval_querywith the current Base64 path encoding, andpost_antigena(activate, extend, clear, reactivate). 59 operations have lab evidence, 6 of them partial (was 56 and 11). Narrower partial notes for manual Antigena (connectiononly;pol,gpol,quarantineOutgoinggot HTTP 400 on a client-sensor device), subnets (label,uniqueHostnames) and the intel feed (addentry,addlist,expiry,removeentry;hostnameaccepted but not read back). The three tag DELETE operations applied live, but the lab gateway still answers HTTP 502, so they stay not lab-validated with that note. - Lab driver.
scripts/lab-gap-campaign.mjsdrives the built server over MCP stdio for owner-authorised lab campaigns (token files only; critical actions through preview,confirmand the server dialog).scripts/lab-status-tap.mjsoptionally records the HTTP status of each appliance response (method, route prefix and status only). - Error-code naming. Full model, component and enum lists surface the public error code
response_limit_exceeded; earlier lab notes used the internal error kindtoo_large. PCAP output refusals remainoutput_limit_exceeded. - CI and supply-chain controls. CodeQL runs the JavaScript/TypeScript
security-extendedqueries on production source and release scripts. ESLint with TypeScript and security rules runs in CI. Dependabot checks npm and GitHub Actions dependencies weekly, with runtime major upgrades reviewed by hand. OpenSSF Scorecard publishes scheduled analysis and SARIF results. Release helper fixes use fresh private temporary directories, exclusive output writes and descriptor-based reads that reject symlinks.
Known limitations in 1.1.1
- Email. The action remains excluded; Email reads remain unvalidated because the lab token gets HTTP 403. Schemas come from darktrace-sdk 0.10.1.
- Lab scope. One Darktrace 7.1.0 appliance and one broad token: 59 operations with evidence, 6 partial. Manual Antigena covers
connectiononly (pol,gpol,quarantineOutgoinggot HTTP 400 on a client-sensor device;quarantineandquarantineIncomingwere not run). Subnet writes coverlabelanduniqueHostnames. Intel-feed writes coveraddentry,addlist,expiryandremoveentry;hostnamewas accepted but its flag could not be read back. Models, components and enums coverresponsedataonly; full lists fail withresponse_limit_exceeded.get_cvesstill gets HTTP 500 (Darktrace/OT only) andget_filtertypesHTTP 302; redirects are never followed. - PCAP. Whole-file downloads and the
output_limit_exceededrefusal were checked live. Captures above about 45 KB still exceed the 60,000-character output budget. - DELETE.
delete_tags_tid_entities_teid,delete_tags_entitiesanddelete_tags_tidapplied live, but the lab gateway answered HTTP 502. They remain not lab-validated; the server reportswrite_outcome_unknown, never retries, and opens the write breaker after three failed or unknown outcomes in one process. - Lab residue. The campaign left a completed capture, an investigation and its alert, an empty intel-feed source, and cleared Antigena actions. Device and subnet changes were restored; tags were deleted. Earlier undeletable test comments remain. See the campaign report.
- The remaining limitations recorded for 1.1.0 still apply: consent and taint controls, per-process state, auditing, protected targets, token scope, egress, signing, distribution and preview eviction. The 1.1.0 lab-scope and PCAP notes below are historical; this section supersedes them.
1.1.0 — 2026-10-06
- Public distribution. The package is
@nuoframework/darktrace-mcpon the public npm registry (published from CI with npm trusted publishing and provenance), the image isghcr.io/nuoframework/darktrace-mcp:<version>(linux/amd64 and linux/arm64, pinned by digest), and the server is described for the MCP Registry asio.github.nuoframework/darktrace-mcp(mcpNameinpackage.json,server.json). Bootstrap:npx -y @nuoframework/darktrace-mcp@1.1.0 setup. When run from the npx cache,setupcopies the verified package tree to~/.local/share/darktrace-mcp/<version>/and writes absolutenode+dist/src/index.jspaths, so clients never launchnpx. These channels are live only after the owner's publication steps (releases). - Full API surface with profiles. 77 of the 79 catalogue operations are executable, as 50 tools. One operation is excluded (the Darktrace/Email action, below) and one is deprecated (
GET /aianalyst/incidents).DARKTRACE_PROFILESselectsread(default),sensitive,write,criticalorall. Every Darktrace/Email read needssensitive. 56 operations have evidence from one Darktrace 7.1.0 lab, 11 of them only partial; the others are marked "not lab-validated" (tool reference). - Write controls. Ordinary writes accept
dryRun:truefor a value-free preview; without it they run, relying on the host's tool-permission prompt (DARKTRACE_WRITE_APPROVAL=host, the default). Critical actions need adryRun:truepreview, thenconfirm:truewith its single-usepreviewId(5 minutes) and, by default, an accepted server confirmation dialog (approved:true, at most one per session and four per process, 30-second deadline); a call withoutconfirm:trueis refused withconfirmation_required.DARKTRACE_CRITICAL_APPROVAL=hostneedsDARKTRACE_ACKNOWLEDGE_HOST_APPROVAL=true. Writes are rate-limited (at most 10 per minute), a breaker stops all writes after three failed or unknown outcomes in a row until restart, optional protected targets and fixed per-call target caps apply, and every preview, refusal and write is written to a hash-chained audit line on stderr. - Sensitive and write together. Any profile list with both
sensitiveandwrite, includingall, starts only withDARKTRACE_ACKNOWLEDGE_SENSITIVE_WRITE=true. - Darktrace/Email action excluded.
darktrace_email_actionis not registered in any profile: its signing and request schema are unvalidated and the lab token got 403. - Older variables.
DARKTRACE_SENSITIVE_READandDARKTRACE_WRITE_CRITICALstill work on their own. WhenDARKTRACE_PROFILESis set they may only agree with it or narrow it; a value that would add an unlisted capability stops startup. - Easier installation. New
darktrace-mcp setupwizard (hidden token entry,0600token files under~/.config/darktrace-mcp/, permission preset, automatic configuration of Claude Desktop, Claude Code, Codex, Cursor, VS Code, Windsurf, OpenCode and Gemini CLI with backups), plusconfig <client>,removeandtest. One-line installersscripts/install.shandscripts/install.ps1. - Claude Desktop extension.
npm run pack:mcpbbuilds a.mcpbbundle; Claude Desktop stores the tokens in the OS keychain. - Documentation restructure. Short bilingual READMEs; task-oriented guides (getting started, clients, configuration, troubleshooting, security overview) with Spanish versions in
docs/es/; generated tool reference (npm run docs:tools); past review and release reports moved todocs/history/.
Known limitations in 1.1.0
From the 1.1.0 final gate review §4. None is an exploitable defect found in the server, and none is an owner acceptance of risk.
- Email. The email action is excluded. Email reads are not lab-validated (the lab token got 403). Their schemas come from darktrace-sdk 0.10.1, and responses may be sparse.
- Lab scope. One 7.1.0 appliance and one broad token. Partial tests: Antigena manual block and
clearonly; subnets label only; intel feed add and remove only; models, components and enums only withresponsedata(full lists returntoo_large). Appliance errors:get_cvesreturns 500 andget_filtertypesreturns 302. Most write evidence predates the final write controls; after them, only the intel-feed critical flow, thepost_tagspreview, theconfirmation_requiredrefusal and POST Advanced Search were checked live. The GET Advanced Search forms passed live only before their path encoding changed; the current encoding has probe evidence for=only. - PCAP. A download is returned whole or fails with
output_limit_exceeded. Captures above about 45 KB do not fit the 60,000-character output budget. The current contract was never tested live. - DELETE and the write breaker. The lab gateway answers 502 to every DELETE after applying it, which the server records as
outcome:"unknown". Three in a row open the write breaker until restart. - Sensitive and write together. There is no taint control. Once acknowledged, ordinary free-text writes (comments, tag descriptions, labels) can carry sensitive data out of the appliance. Comments cannot be deleted and every appliance user can see them.
- Approval. Ordinary writes default to
writeApproval=host: no server prompt.hostmode delegates critical consent to the host. Auto-answering clients or "always allow" rules remove the human; the server cannot verify that a human answered. - Per-process state. Rate limits, the breaker, previews and the audit chain are per process; several host processes multiply the budgets. Audit chains share one genesis and carry no boot identifier. The audit goes to stderr only, with no external anchor. A restart resets the breaker.
- Sensitive reads are not audited.
- Protected targets are opt-in and match literal values only. For
post_antigenathey match the actioncodeid, not the device.maxTargetsis owner policy. - Token scope. There is no least-privilege token mapping per profile. Appliance token permissions remain the real ceiling.
- Data egress. Every result, including Base64 PCAP data and email metadata, reaches the MCP host and its model provider.
- Signing. GET Advanced Search depends on proxies keeping percent-encoding byte-exact. A combined query and JSON body is refused.
- Distribution. No image attestation; the SBOMs are inventories, not clearances. The ghcr image is rebuilt in
release.yml; it is not the CI-tested image. For 1.1.0, the linux/arm64 image passed the local Docker gates; linux/amd64 is verified only by CI on the release commit, and there is no vulnerability scan of the 1.1.0 runtime yet. Docker Desktop needsDARKTRACE_TOKEN_FILE_OWNER=root-or-current. Theserver.jsonOCI launch passes tokens as container environment variables, readable by anyone with Docker access. Native Windows cannot protect token files. - Previews. The preview store evicts the oldest live critical preview once it holds 256 (availability only).
- Lab residue. Undeletable
[mcp-test]and[mcp-ux]comments remain on the lab appliance.
1.0.0 — prepared 2026-10-06
- Reviewed lab harness now requires schema-2 source/runtime and complete installed host SDK/Zod tree binding before SDK import; bounded deterministic hashing rejects symlinks and special files. Docker preflight/session use init, PID and memory limits. This is offline readiness, not final lab or image approval.
Private stable artifact preparation: package/server metadata is now 1.0.0, with private: true, unchanged dependencies and immutable false write capability. Historical alpha assets remain unchanged; publication approval is separate.
- Added a private local Docker build recipe and hardened stdio setup with explicit nonroot identity, read-only token mounts, disabled daemon logging, no ports/TTY, restricted privileges/resources and immutable image selection for operator use. Final candidate image, appliance and provider gates remain separate.
- Corrected object-first response unions so device arrays keep their reviewed projection; unmodeled fields still use bounded safe output. Output projection and text neutralization are not universal compatibility or sensitive-data-removal guarantees.
- Bound MR-04's four complete MCP
tools/listcontracts (descriptions, input schemas, annotations and order) to reviewed fixture/profile hashes in candidate build evidence and checksums. Preparation compares generated listings with the versioned oracle and never recaptures it automatically. - Added release evidence verification for missing/altered contracts, metadata and checksums, full generator inputs including operation inventory, and source-only Docker/Spanish README/vector inputs. Runtime package allowlist and locked three-library runtime dependency/SRI remain unchanged.
- Extended offline JSON/TOML and documentation launch checks to absolute installed executables, user-scoped setup, project-config trust warnings and reviewed immutable Docker templates; negative warnings are not executable advice.
- Made isolated security receipts report a nullable revision with factual Git probe metadata when Git or a checkout is unavailable; test completeness and security assertions remain required.
No new CI, lab or image success is asserted by this section. Per-operation live compatibility is partial; unresolved compatibility/security, final independent artifact review and deployment/provider approval prevent stable publication.
0.1.0-alpha.0 — prepared 2026-10-05
Private alpha; no npm release or container publication.
-
Added English operator guides and Spanish quickstart with source installation and current MCP client configuration.
-
Documented API 6.1 evidence, the unvalidated 7.1 lab target and the 79-operation inventory: 54 executable by profile, five critical previews, 19 blocked and one excluded.
-
Added portable explicit build tooling, private package metadata, a shipped npm shrinkwrap and a compiled-runtime file allowlist.
-
Added offline CI and local private artifact inspection; credential examples use separate token-file paths and contain no secrets.
-
Added versioned private GitHub Release preparation, SHA256SUMS, verified runtime CycloneDX SBOM and installed-file inventory.
-
Added isolated reproducible archive verification, exact three-library runtime/SRI checks, help/version/doctor checks and JSON/TOML example validation.
-
Added
test:securityand Node 22/24 CI; manual preparation workflow has read-only repository permissions and does not publish.
Release publication, final independent review and live compatibility validation remain owner gates. This changelog is not release approval or a statement that all baseline controls have passed audit.
Published artifacts (126e5ea)
npm
Status: published
npx -y @nuoframework/darktrace-mcp@1.1.2 setup
{
"name": "@nuoframework/darktrace-mcp",
"version": "1.1.2",
"dist.integrity": "sha512-TIdr8PaJ3/OtItU008JNS+Wq2eRTNkflMhPp+bG3fDl4R+XcZLhRoBdUhEqwmXlKJDoFQ30Wcp0WKv6Fev7E3Q==",
"dist.shasum": "b83bb7b6a1eae79f8bd67c66459901a2a5f13098",
"dist.tarball": "https://registry.npmjs.org/@nuoframework/darktrace-mcp/-/darktrace-mcp-1.1.2.tgz"
}
ghcr.io
ghcr.io/nuoframework/darktrace-mcp:1.1.2
ghcr.io/nuoframework/darktrace-mcp@sha256:fa261c2f7423fa79c66b0b5ddf74d6d8bb53b59a64608dda869959b43900d9ee
linux/amd64 sha256:8a7f06cb4c62ffe003e792a058dd7f38e4f51d00aa4a7fa757887f9971fe20f5
linux/arm64 sha256:2967fab09f65fd985e1c8304dc1e008642be51ea69a33fd2b376922639b0905b
Pin clients to the digest: darktrace-mcp setup --runtime docker --image ghcr.io/nuoframework/darktrace-mcp@sha256:fa261c2f7423fa79c66b0b5ddf74d6d8bb53b59a64608dda869959b43900d9ee
Claude Desktop bundle (.mcpb)
a6bed56e7fd3dcf891a4f13d5c516baeaf701dbec11e47247bd83b7135c67478 darktrace-mcp-1.1.2.mcpb
Docker gates (ci.yml at 126e5ea)
- CI run: https://github.com/nuoframework/darktrace-mcp/actions/runs/37536315729
- docker (amd64, ubuntu-24.04): success https://github.com/nuoframework/darktrace-mcp/actions/runs/37536315729/job/112519190034
- docker (arm64, ubuntu-24.04-arm): success https://github.com/nuoframework/darktrace-mcp/actions/runs/37536315729/job/112519190119
Verify downloads with sha256sum -c SHA256SUMS.
Signatures and provenance
Every asset has a keyless Sigstore signature from this workflow run (<asset>.sigstore.json, cosign) and SLSA build provenance (darktrace-mcp-1.1.2.intoto.jsonl; full bundle darktrace-mcp-1.1.2.provenance.sigstore.json; GitHub attestation). Verify, for example, the npm tarball:
gh attestation verify nuoframework-darktrace-mcp-1.1.2.tgz --repo nuoframework/darktrace-mcp
cosign verify-blob --bundle nuoframework-darktrace-mcp-1.1.2.tgz.sigstore.json \
--certificate-identity https://github.com/nuoframework/darktrace-mcp/.github/workflows/release.yml@refs/tags/v1.1.2 \
--certificate-oidc-issuer https://token.actions.githubusercontent.com nuoframework-darktrace-mcp-1.1.2.tgz