Skip to main content
Panopticon logo: a panopticon floor plan drawn as an eye, one cell lit in orange Panopticon — We don't watch you. We watch your MCPs. A local-first MCP behavior observatory.

Version Python Platform License No telemetry

pano finds the MCP servers installed in your AI clients, runs them inside a decoy-filled sandbox, and shows you what they actually did — file by file, host by host, per tool call — against what they claim to do.

$ pano watch github

Ran github MCP in an isolated sandbox and called 3 tools. (14s)

list_issues
  READ   ~/.gitconfig
  READ   ~/.ssh/config                        not declared
  NET    api.github.com:443
  NET    collector.example-telemetry.io:443    not in docs
  LEAK   AWS_ACCESS_KEY_ID sent to host above  <- decoy value

Declared   repo read/write (README, tool descriptions)
Observed   2 files · 2 hosts · 1 decoy leak

Findings   2 undeclared behaviors, 1 leak
           details: pano explain WATCH-003 WATCH-001
An inspection tower at the centre of a ring of cells, each holding an MCP server. One beam catches a single cell mid-reach for a key.

Install

uvx panopticon-mcp doctor        # discovery + config checks, no Docker needed
uvx panopticon-mcp watch --all   # needs Docker or Podman

See the release, installation, upgrade, and rollback guide for pinned uvx, pipx, Homebrew, and native archive instructions.

Principles

  1. Observation before judgment — we report what happened; you decide.
  2. Unknown is visible — anything not observed, skipped, unsupported, or timed out is reported as UNKNOWN or INCOMPLETE, never collapsed into a pass.
  3. Your home never enters a container — decoys only. No telemetry, no crash reports, no update pings. Every user-invoked outbound path—including registries, observed MCP traffic, remote observation, FIX-008 validation, and scan --mode deep—is listed in docs/privacy.md; --offline disables them.

Status

The 1.0 contracts and artifacts are built from the implementation plan. Agents: read AGENTS.md.

Lineage

The static, semantic, and dependency analysis assets in the scan line come from MCP-Sentinel at commit e717e955 (MIT), carried here with the original copyright headers intact and the exact file list in THIRD_PARTY_NOTICES.md. Dynamic behavior is not inherited: Panopticon's own sandbox and decoy-probe engine replaces upstream dynamic probing entirely.

License

MIT.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

panopticon_mcp-1.0.1.tar.gz (3.9 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

panopticon_mcp-1.0.1-py3-none-any.whl (1.1 MB view details)

Uploaded Python 3

File details

Details for the file panopticon_mcp-1.0.1.tar.gz.

File metadata

  • Download URL: panopticon_mcp-1.0.1.tar.gz
  • Upload date:
  • Size: 3.9 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for panopticon_mcp-1.0.1.tar.gz
Algorithm Hash digest
SHA256 85d92d43ab5a5db58588c65065fc2357913f3b955aaa869341a4bb822f269157
MD5 0c92755952af5f083f346e794b5662c7
BLAKE2b-256 0be12c7f220e21821e59b57b62da3e27a4e3b8a66f09a85d624d3352530258bc

See more details on using hashes here.

Provenance

The following attestation bundles were made for panopticon_mcp-1.0.1.tar.gz:

Publisher: release.yml on brnyxx/panopticon

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file panopticon_mcp-1.0.1-py3-none-any.whl.

File metadata

  • Download URL: panopticon_mcp-1.0.1-py3-none-any.whl
  • Upload date:
  • Size: 1.1 MB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for panopticon_mcp-1.0.1-py3-none-any.whl
Algorithm Hash digest
SHA256 290bd5c421e749b90c8c7c6dda86e12d99c49bbcf984a618c4260b26fd63dca4
MD5 577ffac2423415f5cba0afe5821bef5b
BLAKE2b-256 e693127027db5808137905f865c524e7690f14daeb7126893f754717e839658c

See more details on using hashes here.

Provenance

The following attestation bundles were made for panopticon_mcp-1.0.1-py3-none-any.whl:

Publisher: release.yml on brnyxx/panopticon

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

This release

1.0.1 This release

2 files

1.0.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page