Artifact intake
Drop an untrusted agent artifact
Static scanners read the label. Reactor points a sacrificial victim agent at it and watches it behave.
Looking for a live engine — upload and clone need one.
Public https repositories only — ssh, git@ and urls carrying credentials are refused by design. Shallow clone, 90s ceiling, no submodules or hooks.
5 detonations · fresh sandbox each · victim holds only baitProbing engine…
mcp-scan
A static scanner. It reads the artifact’s tool descriptions and never runs the code.
mcp-scan @acme/notes-mcp
Idle
Reactor
A runtime detonation chamber. It runs the artifact and watches how it behaves.
ArtifactNo artifact loadedChamber not provisioned
Detonate to install the artifact in a disposable chamber and point a sacrificial victim agent at it. The host never executes the artifact.
Chamber loadout
- Bait
- Decoy repo, plausible credentials and canary tokens, planted on disk
- Canary
- One token seeded only into the victim's system prompt — never written
- Wire
- A stdio proxy between victim and artifact, logging every MCP frame
- Sink
- Contained HTTP and DNS endpoint — egress is observed, never delivered
- Syscalls
- The artifact runs under strace; writes and connects become typed events