Skip to main content

stacktrace-cli

Detection and response for AI coding agents, from the command line.

Coding agents read files, run shell commands and call MCP servers on their own initiative, and they write a transcript of every bit of it to disk. stacktrace reads those transcripts, correlates what ran against the components the agent is built from, and reports the security and reliability findings in it — locally, on the machine the agent worked on.

The PyPI distribution is stacktrace-cli; the command it installs is stacktrace. The two names differ because the bare stacktrace name on PyPI belongs to an unrelated project.

Installation

uv tool install stacktrace-cli     # isolated; recommended
# or
pip install stacktrace-cli

Requires Python 3.11 or newer.

$ stacktrace --version
stacktrace 0.2.1 (openaca 0.6.0)

Quick start

stacktrace sessions      # what the agents on this machine did
stacktrace detect        # what is wrong with it
stacktrace monitor       # the same, live in a browser

Commands

Command
sessions Print what the agents on this machine actually did.
detect Find security and reliability findings in what agents did.
monitor Watch this machine's agents in a browser, live.
remote Configure remote endpoint services and upload to Stacktrace Cloud.
scan Scan a repository or endpoint for agent-composition findings.
bom Generate an Agent BOM for a repository or endpoint.
policy Validate and compile restrictive endpoint policies.

The last three are composition analysis, supplied by openaca and available under either name.

What it looks like

$ stacktrace sessions --since 2d --include-content
claude-code:s1  [claude-code]  2026-08-27T09:00:00+00:00  2 turns  2 calls
  assistant: Reading the changelog before drafting the release notes.
    ok                28c  Read
        result: ## 0.4.0 - correlate, detect
  assistant: Filing the release-notes follow-up.
                        -  github/create_issue

Summary — 1 sessions, 2 turns, 2 tool calls

  agent kinds
          1  claude-code

  tools called (2 distinct)
          1  Read
          1  github/create_issue

  MCP servers reached (1 distinct)
          1  github

  0 subagent turns · 0 results abridged upstream · 1 ok

1 of 2 calls returned with no outcome the collector could establish; the agent's parser supplies no success signal.

A blank status column is the collector's unknown, not a pending call: the client recorded no outcome that could be established, and the closing line counts those rather than filling one in.

What detect finds

Four kinds of finding, under two families that carry separate severity ladders — a stalled loop and a leaked credential do not belong on one scale.

Security — a credential reaching an outbound call; an injected instruction the agent then followed; a vulnerable component actually reached, with the vulnerability behind it.

Reliability — a loop that stalled; a call that hung.

Findings are correlated against an Agent BOM before they are judged, so a vulnerable component is reported when something actually used it rather than because it is installed.

What leaves your machine

Two of detect's three stages run entirely locally and need no model or credential. The third sends flagged sessions to the agent's own CLI — the provider that produced the transcript, never a different one — capped by --budget; --no-escalate turns it off and leaves the two local stages.

sessions omits prompts, tool arguments and results unless you pass --include-content. monitor binds to loopback only, refuses a non-loopback address rather than warning about it, and escalates nothing unless --escalate is given.

Status

Beta, and under active development.

sessions, detect and monitor work end to end today. Session collection currently reads Claude Code transcripts; further agent kinds are in progress upstream in OpenAIDR.

Built on

Two Apache-2.0 packages, neither of which depends on this one: openaca for agent composition analysis, and openaidr for session collection.

Licence

Proprietary. © Stacktrace AI, Inc. — stacktrace.ai

Release files for stacktrace-cli 0.2.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for stacktrace-cli 0.2.1
File Size Uploaded
stacktrace_cli-0.2.1.tar.gz 1.0 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for stacktrace-cli 0.2.1
File Interpreter ABI Platform
stacktrace_cli-0.2.1-py3-none-any.whl Python 3 none any Details

Total release size: 1.4 MB

Release files / stacktrace_cli-0.2.1.tar.gz

Download URL stacktrace_cli-0.2.1.tar.gz
Size 1.0 MB
Tags Source
SHA-256 checksum
How to use checksums
a8efd238d2aa570b2685e897bd0cc767bbefe515da6069a6f5e772d0f415669b
BLAKE2b-256 checksum
How to use checksums
c9db6a036d199e5f4505ac3c12ebb7a9d760106d52c50df5eb226a17ae305865
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 8, 2026.

Transparency log

Release files / stacktrace_cli-0.2.1-py3-none-any.whl

Download URL stacktrace_cli-0.2.1-py3-none-any.whl
Size 390.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
adb2d46c2f1038c1d435a82e320d912abc24d45356d2a4a49d01d22022e1cf70
BLAKE2b-256 checksum
How to use checksums
9d4428e797f3322d9d02ef219b778466443972ab0b55458457965a8edad47d3f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 8, 2026.

Transparency log

Release history Release notifications | RSS feed

0.5.1

2 release files

0.5.0

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.3

2 release files

0.2.2

2 release files

This release

0.2.1 This release

2 release files

0.2.0

2 release files

0.1.0

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page