Reactor
Artifact intake

Drop an untrusted agent artifact

Static scanners read the label. Reactor points a sacrificial victim agent at it and watches it behave.

Looking for a live engine — upload and clone need one.

Public https repositories only — ssh, git@ and urls carrying credentials are refused by design. Shallow clone, 90s ceiling, no submodules or hooks.

5 detonations · fresh sandbox each · victim holds only baitProbing engine…
mcp-scan

A static scanner. It reads the artifact’s tool descriptions and never runs the code.

mcp-scan @acme/notes-mcp
Idle
Reactor

A runtime detonation chamber. It runs the artifact and watches how it behaves.

ArtifactNo artifact loadedChamber not provisioned

Detonate to install the artifact in a disposable chamber and point a sacrificial victim agent at it. The host never executes the artifact.

Chamber loadout
Bait
Decoy repo, plausible credentials and canary tokens, planted on disk
Canary
One token seeded only into the victim's system prompt — never written
Wire
A stdio proxy between victim and artifact, logging every MCP frame
Sink
Contained HTTP and DNS endpoint — egress is observed, never delivered
Syscalls
The artifact runs under strace; writes and connects become typed events