Skip to main content
Panopticon logo: a panopticon floor plan drawn as an eye, one cell lit in orange Panopticon — We don't watch you. We watch your MCPs. A local-first MCP behavior observatory.

Version Python Platform License No telemetry

pano finds the MCP servers installed in your AI clients, runs them inside a decoy-filled sandbox, and shows you what they actually did — file by file, host by host, per tool call — against what they claim to do.

$ pano watch github

Ran github MCP in an isolated sandbox and called 3 tools. (14s)

list_issues
  READ   ~/.gitconfig
  READ   ~/.ssh/config                        not declared
  NET    api.github.com:443
  NET    collector.example-telemetry.io:443    not in docs
  LEAK   AWS_ACCESS_KEY_ID sent to host above  <- decoy value

Declared   repo read/write (README, tool descriptions)
Observed   2 files · 2 hosts · 1 decoy leak

Findings   2 undeclared behaviors, 1 leak
           details: pano explain WATCH-003 WATCH-001
An inspection tower at the centre of a ring of cells, each holding an MCP server. One beam catches a single cell mid-reach for a key.

Install

uvx panopticon-mcp doctor        # discovery + config checks, no Docker needed
uvx panopticon-mcp watch --all   # needs Docker or Podman

See the release, installation, upgrade, and rollback guide for pinned uvx, pipx, Homebrew, and native archive instructions.

Principles

  1. Observation before judgment — we report what happened; you decide.
  2. Unknown is visible — anything not observed, skipped, unsupported, or timed out is reported as UNKNOWN or INCOMPLETE, never collapsed into a pass.
  3. Your home never enters a container — decoys only. No telemetry, no crash reports, no update pings. One opt-in exception leaves your machine: scan --mode deep submits redacted source excerpts to the OpenAI API under your own key, shown to you before they are sent, and --offline disables it. Details in docs/privacy.md.

Status

The 1.0 contracts and artifacts are built from the implementation plan; release-channel status and remaining external promotion work are tracked in docs/PROGRESS.md. Agents: read AGENTS.md.

Lineage

The static, semantic, and dependency analysis assets in the scan line come from MCP-Sentinel at commit e717e955 (MIT), carried here with the original copyright headers intact and the exact file list in THIRD_PARTY_NOTICES.md. Dynamic behavior is not inherited: Panopticon's own sandbox and decoy-probe engine replaces upstream dynamic probing entirely.

License

MIT.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

panopticon_mcp-1.0.0.tar.gz (3.9 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

panopticon_mcp-1.0.0-py3-none-any.whl (1.1 MB view details)

Uploaded Python 3

File details

Details for the file panopticon_mcp-1.0.0.tar.gz.

File metadata

  • Download URL: panopticon_mcp-1.0.0.tar.gz
  • Upload date:
  • Size: 3.9 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for panopticon_mcp-1.0.0.tar.gz
Algorithm Hash digest
SHA256 9074db017377cb0ba41232186725d4dc508cc6a9d52e34d52a2c2571f1b18c14
MD5 d4df28f0ab43906fe44e65a138d21e75
BLAKE2b-256 732d573a9a62e41bdee085aabd485e61c1ccead6e337f0ee6a7aca7c77c731b4

See more details on using hashes here.

Provenance

The following attestation bundles were made for panopticon_mcp-1.0.0.tar.gz:

Publisher: release.yml on brnyxx/panopticon

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file panopticon_mcp-1.0.0-py3-none-any.whl.

File metadata

  • Download URL: panopticon_mcp-1.0.0-py3-none-any.whl
  • Upload date:
  • Size: 1.1 MB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for panopticon_mcp-1.0.0-py3-none-any.whl
Algorithm Hash digest
SHA256 6efc434893c1172e4575e86991b67633571f11feaf24830937b01fb4abc88deb
MD5 77bab2e55a3bd13083a654889412c963
BLAKE2b-256 fd779b844f4b4ab08aeb4c3f89b79322b322bd848e90d04b9d3c3b901346fa68

See more details on using hashes here.

Provenance

The following attestation bundles were made for panopticon_mcp-1.0.0-py3-none-any.whl:

Publisher: release.yml on brnyxx/panopticon

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

1.0.1

2 files

This release

1.0.0 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page