Skip to main content

stacktrace-cli

Detection and response for AI coding agents, from the command line.

Coding agents read files, run shell commands and call MCP servers on their own initiative, and they write a transcript of every bit of it to disk. stacktrace reads those transcripts, correlates what ran against the components the agent is built from, and reports the security and reliability findings in it — locally, on the machine the agent worked on.

The PyPI distribution is stacktrace-cli; the command it installs is stacktrace. The two names differ because the bare stacktrace name on PyPI belongs to an unrelated project.

Installation

uv tool install stacktrace-cli     # isolated; recommended
# or
pip install stacktrace-cli

Requires Python 3.11 or newer.

$ stacktrace --version
stacktrace 0.2.1 (openaca 0.6.0)

Quick start

stacktrace sessions      # what the agents on this machine did
stacktrace detect        # what is wrong with it
stacktrace monitor       # the same, live in a browser

Commands

Command
sessions Print what the agents on this machine actually did.
detect Find security and reliability findings in what agents did.
monitor Watch this machine's agents in a browser, live.
remote Configure remote endpoint services and upload to Stacktrace Cloud.
scan Scan a repository or endpoint for agent-composition findings.
bom Generate an Agent BOM for a repository or endpoint.
policy Validate and compile restrictive endpoint policies.

The last three are composition analysis, supplied by openaca and available under either name.

What it looks like

$ stacktrace sessions --since 2d --include-content
claude-code:s1  [claude-code]  2026-08-27T09:00:00+00:00  2 turns  2 calls
  assistant: Reading the changelog before drafting the release notes.
    ok                28c  Read
        result: ## 0.4.0 - correlate, detect
  assistant: Filing the release-notes follow-up.
                        -  github/create_issue

Summary — 1 sessions, 2 turns, 2 tool calls

  agent kinds
          1  claude-code

  tools called (2 distinct)
          1  Read
          1  github/create_issue

  MCP servers reached (1 distinct)
          1  github

  0 subagent turns · 0 results abridged upstream · 1 ok

1 of 2 calls returned with no outcome the collector could establish; the agent's parser supplies no success signal.

A blank status column is the collector's unknown, not a pending call: the client recorded no outcome that could be established, and the closing line counts those rather than filling one in.

What detect finds

Four kinds of finding, under two families that carry separate severity ladders — a stalled loop and a leaked credential do not belong on one scale.

Security — a credential reaching an outbound call; an injected instruction the agent then followed; a vulnerable component actually reached, with the vulnerability behind it.

Reliability — a loop that stalled; a call that hung.

Findings are correlated against an Agent BOM before they are judged, so a vulnerable component is reported when something actually used it rather than because it is installed.

What leaves your machine

Two of detect's three stages run entirely locally and need no model or credential. The third sends flagged sessions to the agent's own CLI — the provider that produced the transcript, never a different one — capped by --budget; --no-escalate turns it off and leaves the two local stages.

sessions omits prompts, tool arguments and results unless you pass --include-content. monitor binds to loopback only, refuses a non-loopback address rather than warning about it, and escalates nothing unless --escalate is given.

Status

Beta, and under active development.

sessions, detect and monitor work end to end today. Session collection currently reads Claude Code transcripts; further agent kinds are in progress upstream in OpenAIDR.

Built on

Two Apache-2.0 packages, neither of which depends on this one: openaca for agent composition analysis, and openaidr for session collection.

Licence

Proprietary. © Stacktrace AI, Inc. — stacktrace.ai

Release files for stacktrace-cli 0.2.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for stacktrace-cli 0.2.2
File Size Uploaded
stacktrace_cli-0.2.2.tar.gz 1.0 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for stacktrace-cli 0.2.2
File Interpreter ABI Platform
stacktrace_cli-0.2.2-py3-none-any.whl Python 3 none any Details

Total release size: 1.4 MB

Release files / stacktrace_cli-0.2.2.tar.gz

Download URL stacktrace_cli-0.2.2.tar.gz
Size 1.0 MB
Tags Source
SHA-256 checksum
How to use checksums
95349476e6ea7afca316364531935888f05a7744155aaec25fae9e8cf01e7fb5
BLAKE2b-256 checksum
How to use checksums
2ca329ec5957a7df87092795a9d36a83ef51bf9de592758f06b4ebe7f88d004a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 8, 2026.

Transparency log

Release files / stacktrace_cli-0.2.2-py3-none-any.whl

Download URL stacktrace_cli-0.2.2-py3-none-any.whl
Size 390.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
089723dff619d91ff34c598a81cb6535cab48af702517070e2dda30074618ff6
BLAKE2b-256 checksum
How to use checksums
1dfa27324911885e58c321986db3f8ffe31b04fefacd3d64f3bf41f3c86bdd82
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 8, 2026.

Transparency log

Release history Release notifications | RSS feed

0.5.1

2 release files

0.5.0

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.3

2 release files

This release

0.2.2 This release

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.0

2 release files

0.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page