{"data":{"slug":"tracecathq-tracecat","name":"tracecat","tagline":"Open-source security automation platform for teams and AI agents","github_url":"https://github.com/TracecatHQ/tracecat","owner":"TracecatHQ","repo":"tracecat","owner_avatar_url":"https://avatars.githubusercontent.com/u/137193901?v=4","primary_language":"Python","stars":3805,"forks":416,"topics":["agents","automation","case-management","fastapi","incident-response","low-code","nextjs","orchestration","security","temporalio"],"archived":false,"github_pushed_at":"2026-09-18T04:32:07+00:00","maintenance_label":"Very active","stars_delta_30d":44,"url":"https://www.graphcanon.com/tools/tracecathq-tracecat","markdown_url":"https://www.graphcanon.com/tools/tracecathq-tracecat.md","api_url":"https://www.graphcanon.com/api/graphcanon/tools/tracecathq-tracecat","graph_url":"https://www.graphcanon.com/api/graphcanon/graph?tool=tracecathq-tracecat","description":"Open-source security automation platform for teams and AI agents","homepage_url":"https://tracecat.com","license":"AGPL-3.0","open_issues":155,"watchers":22,"ai_summary":"Tracecat is an open-source platform that supports building custom agents with prompts, tools, and chat capabilities. It includes features like event-driven workflows, case management, sandboxed execution of untrusted code, lookup tables, integrations with enterprise tools, and a managed cloud presence.","readme_excerpt":"<div align=\"center\">\n  <picture>\n    <source media=\"(prefers-color-scheme: dark)\" srcset=\"img/banner-dark.svg\">\n    <source media=\"(prefers-color-scheme: light)\" srcset=\"img/banner-light.svg\">\n    <img src=\"img/banner-light.svg\" alt=\"The AI-native security automation platform.\" width=\"85%\">\n  </picture>\n  <p align=\"center\">\n    The agentic security automation platform.\n  </p>\n\n  <br>\n</div>\n\n<div align=\"center\">\n\n\n\n\n\n</div>\n\n## Introduction\n\n[Tracecat](https://tracecat.com) is the open source security automation platform for teams and AI agents. A unified platform with everything AI-native security teams need to build agents and automate cyber defense.\n## Core Features\n\n<p align=\"center\">Unlimited agents, cases, lookup tables, and workflows.</p>\n\n<table>\n  <tr>\n    <td width=\"50%\" valign=\"top\">\n      <img src=\"img/readme/agents.gif\" alt=\"An agent preset in Tracecat with its tools and skills, then a chat where the agent investigates a case by calling tools\" width=\"100%\"/>\n      <p align=\"center\"><b>Agents and skills</b> — build custom agents with prompts, tools, MCP, and skills</p>\n    </td>\n    <td width=\"50%\" valign=\"top\">\n      <img src=\"img/readme/cases.gif\" alt=\"The Tracecat case list, then a case with an agent-written verdict, timeline, IoCs, and evidence\" width=\"100%\"/>\n      <p align=\"center\"><b>Case management</b> — track, automate, and resolve incidents with agents</p>\n    </td>\n  </tr>\n  <tr>\n    <td width=\"50%\" valign=\"top\">\n      <img src=\"img/readme/workflows.gif\" alt=\"A workflow DAG in the Tracecat builder, zoomed out to show every step, then an agent step opened for editing\" width=\"100%\"/>\n      <p align=\"center\"><b>Workflows</b> — execute deterministic logic with resilience and scale on Temporal</p>\n    </td>\n    <td width=\"50%\" valign=\"top\">\n      <img src=\"img/readme/tables.gif\" alt=\"Tracecat workspace tables, opening an entities table and an entity observations table\" width=\"100%\"/>\n      <p align=\"center\"><b>Tables</b> — store and query structured data</p>\n    </td>\n  </tr>\n  <tr>\n    <td width=\"50%\" valign=\"top\">\n      <img src=\"img/readme/mcp.gif\" alt=\"A Claude Code session that calls Tracecat MCP tools to list and summarize the open critical cases\" width=\"100%\"/>\n      <p align=\"center\"><b>Tracecat MCP</b> — turn prompts into automations from Claude Code, Codex, Copilot, and more</p>\n    </td>\n    <td width=\"50%\" valign=\"top\">\n      <img src=\"img/readme/integrations.gif\" alt=\"Tracecat credentials, OAuth integrations, and the hosted MCP server catalog\" width=\"100%\"/>\n      <p align=\"center\"><b>Integrations</b> — 100+ pre-built connectors and 50+ hosted MCP servers for security tools</p>\n    </td>\n  </tr>\n</table>\n\n## Other Highlights\n\n- **Pre-built MCP servers**: 50+ Tracecat-hosted MCP servers for security operations\n- **MCP client**: connect custom agents any MCP server (remote HTTP / OAuth or local via `npx` / `uvx` commands)\n- **Custom registry**: sync custom Python scripts from your Git repo into Tracecat\n- **Sandboxed**: run untrusted code and agents within `nsjail` sandboxes or `pid` runtimes\n- **Durable execution**: built on [Temporal](https://temporal.io) for resilience and scale\n- **Variables**: reuse values across workflows and agents\n- **No SSO tax**: SAML / OIDC support\n- **Free audit logs**: exportable into your SIEM\n- **Deploy anywhere**: sign up for Tracecat Cloud, or self-host with Docker, AWS Fargate, or Kubernetes. Runs fully [air-gapped](https://docs.tracecat.com/self-hosting/air-gapped).\n\n## Enterprise Edition\n\n- **Multi-tenant**: isoated different teams and dev / prod environments into workspaces\n- **Fine-grained access control**: RBAC, ABAC, OAuth2.0 scopes for humans and agents\n- **Human-in-the-loop**: review and approve sensitive tools calls from a unified inbox, Slack, or email\n- **Workspace version control**: sync workflows, agents, and table schemas to GitHub, GitLab, Bitbucket, etc.\n- **Metrics and monitoring**: for workflows, agents, and cases\n\n## Open Source vs Enterprise\n\nT","github_created_at":"2024-02-27T06:48:32+00:00","created_at":"2026-07-15T10:51:07.250448+00:00","updated_at":"2026-09-20T04:28:19.597576+00:00","categories":[{"slug":"ai-agents","name":"AI Agents","url":"https://www.graphcanon.com/categories/ai-agents","markdown_url":"https://www.graphcanon.com/categories/ai-agents.md","api_url":"https://www.graphcanon.com/api/graphcanon/categories/ai-agents"},{"slug":"evaluation-observability","name":"Evaluation & Observability","url":"https://www.graphcanon.com/categories/evaluation-observability","markdown_url":"https://www.graphcanon.com/categories/evaluation-observability.md","api_url":"https://www.graphcanon.com/api/graphcanon/categories/evaluation-observability"}],"tags":[{"slug":"agents","name":"agents"},{"slug":"automation","name":"automation"},{"slug":"event-driven","name":"event-driven"},{"slug":"fastapi","name":"fastapi"},{"slug":"llm","name":"llm"},{"slug":"low-code","name":"low-code"},{"slug":"monitoring","name":"monitoring"},{"slug":"nextjs","name":"nextjs"}],"trust":{"provenance":{"is_fork":false,"github_id":763923484,"owner_type":"Organization","methodology":"github_public_v1","parent_repo":null,"near_duplicate_slugs":[]},"computed_at":"2026-09-18T06:00:50.803Z","maintenance":{"label":"Very active","score":96,"methodology":"github_public_v1","releases_90d":30,"days_since_push":0,"last_release_at":"2026-09-18T01:49:28Z","stars_delta_30d":44,"open_issues_delta_30d":13},"security_summary":{"status":"no_lockfile","scanner":null,"low_count":0,"high_count":0,"last_scan_at":"2026-08-30T04:01:35.919Z","medium_count":0,"scan_profile":"none","critical_count":0}},"capability_facts":{"scan":{"source":"repo_scan","observed_at":"2026-09-18T06:00:51.290Z"},"deploy":{"source":"dockerfile:Dockerfile","self_host":true,"observed_at":"2026-09-18T06:00:51.290Z","managed_saas":false},"languages":{"value":["python"],"source":"github.language+pyproject.toml","observed_at":"2026-09-18T06:00:51.290Z"},"has_docker":{"value":true,"source":"dockerfile:Dockerfile","observed_at":"2026-09-18T06:00:51.290Z"},"license_spdx":{"value":"AGPL-3.0","source":"github.license","observed_at":"2026-09-18T06:00:51.290Z"}},"decision_facts":{"hosting":null,"pricing":{"model":"freemium","summary":"`tracecat` is available under the AGPL-3.0 license with options to access enterprise features through managed Cloud or self-hosted deployments with dedicated support."},"requirements":{"min_ram_gb":null,"requires_docker":true},"constraints":{"min_ram_gb":null,"pricing_model":"freemium","requires_docker":true},"when_to_use":["When you need an all-in-one solution for automating workflows that includes agents, case management, and event-driven systems.","If your team requires the development of custom Python scripts within a secure environment such as `nsjail` sandboxes or `pid` runtimes."],"when_not_to_use":["For teams strictly looking to use closed-source proprietary solutions for security automation platforms.","When you prefer a tool that does not require manual setup and maintenance for sandboxed execution environments like nsjail."],"source":"enrich:decision_facts","observed_at":"2026-07-16T20:38:34.379Z"},"constraint_facets":{"min_ram_gb":null,"pricing_model":"freemium","requires_docker":true},"decision_summary":[{"label":"Pricing","value":"freemium - `tracecat` is available under the AGPL-3.0 license with options to access enterprise features through managed Cloud or self-hosted deployments with dedicated support."},{"label":"Requirements","value":"Requires Docker"},{"label":"Adopt for","value":"An open-source security automation platform with features encompassing custom agent building, sandboxed execution of untrusted code, and integration with enterprise tools."}]}}