AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
MCP unreviewed MIT Self-run

OpenDerisk

mcp-derisk-ai-openderisk · by derisk-ai

AI-Native Risk Intelligence Systems, OpenDeRisk——Your application system risk intelligent manager provides 7* 24-hour comprehensive and in-depth protection.

No reviews yet
0 installs
15 views
0.0% view→install

Install

$ agentstack add mcp-derisk-ai-openderisk

Open-source listing, not yet scanned by AgentStack. Follow the source repository for install instructions.

Security review

⚠ Flagged

1 finding(s); flagged for manual review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures
  • high Pipes remote content directly into a shell (remote code execution).

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Reliability & compatibility

Not yet reviewed
0 installs to date
no reviews yet
3mo ago

Declared compatibility

Claude CodeClaude DesktopCursorWindsurf

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of OpenDerisk? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

OpenDeRisk

OpenDeRisk is an AI-Native Risk Intelligence System designed as your application system's intelligent manager, providing 7×24 hour comprehensive and in-depth protection.

[English](README.md) | [简体中文](README.zh.md) | [日本語](README.ja.md) | Video Tutorial

Features

  1. DeepResearch RCA: Quickly locate root causes through in-depth analysis of logs, traces, and code.
  2. Visualized Evidence Chain: Fully visualize diagnostic processes and evidence chains for clear, accurate judgment.
  3. Multi-Agent Collaboration: SRE-Agent, Code-Agent, ReportAgent, Vis-Agent, and Data-Agent working in coordination.
  4. Open-Source Architecture: Built with a completely open architecture, enabling framework and code reuse in open-source projects.

Architecture

Introduction

The system employs a multi-agent architecture. Currently, the code primarily implements the highlighted components. Alert awareness is based on Microsoft's open-source OpenRCA dataset. The decompressed dataset is approximately 26GB. On this dataset, we achieve root cause analysis through multi-agent collaboration, with Code-Agent dynamically writing code for final analysis.

Technical Implementation

Data Layer: Pull the large-scale OpenRCA dataset (20GB) from GitHub, decompress locally, and process for analysis.

Logic Layer: Multi-agent architecture with SRE-Agent, Code-Agent, ReportAgent, Vis-Agent, and Data-Agent collaborating for deep DeepResearch RCA (Root Cause Analysis).

Visualization Layer: Use the Vis protocol to dynamically render the entire processing flow and evidence chain, as well as the multi-role collaboration and switching process.

Digital Employees (Agents) in OpenDeRisk

Install (recommended)

Install via curl
# Download and install latest version
curl -fsSL https://raw.githubusercontent.com/derisk-ai/OpenDerisk/main/install.sh | bash
Configuration File

After installation, the default configuration file is automatically initialized at: ~/.openderisk/configs/derisk-proxy-aliyun.toml

Edit this file and set your API keys:

vi ~/.openderisk/configs/derisk-proxy-aliyun.toml
Start
openderisk-server  

From source(development)

Install uv (required)

macOS/Linux:

curl -LsSf https://astral.sh/uv/install.sh | sh

Windows:

powershell -c "irm https://astral.sh/uv/install.ps1 | iex"
Clone and Install Dependencies
git clone https://github.com/derisk-ai/OpenDerisk.git

cd OpenDerisk

# Install Dependencies with uv
uv sync --all-packages --frozen \
    --extra "base" \
    --extra "proxy_openai" \
    --extra "rag" \
    --extra "storage_chromadb" \
    --extra "derisks" \
    --extra "storage_oss2" \
    --extra "client" \
    --extra "ext_base" \
    --extra "channel_dingtalk"

> Note: channel_dingtalk is optional. Skip it if you don't need DingTalk channel support.

Start Server

🚀 Quick Start (Zero Configuration, Recommended)

Start without any configuration file:

# Method 1: Use quickstart command
uv run derisk quickstart

# Method 2: Use startup script
./start.sh

# Method 3: Specify port
uv run derisk quickstart -p 8888

After starting, visit http://localhost:7777 and configure models and settings through the web UI.

For detailed instructions, see: [Quick Start Guide](QUICKSTART.md)

📝 Start with Configuration File

Configure the API_KEY in derisk-proxy-aliyun.toml, then run:

> Note: By default, we use the Telecom dataset from OpenRCA. Download via: > gdown https://drive.google.com/uc?id=1cyOKpqyAP4fy-QiJ6a_cKuwR7D46zyVe

After downloading, move datasets to pilot/datasets/

Run the startup command:

# Start with configuration file
uv run derisk quickstart -c configs/derisk-proxy-aliyun.toml

# Or use traditional method
uv run python packages/derisk-app/src/derisk_app/derisk_server.py --config configs/derisk-proxy-aliyun.toml
Access Web UI

Open your browser and visit http://localhost:7777

Usage Modes

  • AI-SRE (OpenRCA)
  • Notice: We use the OpenRCA Dataset Bank Dataset
  • Download: gdown https://drive.google.com/uc?id=1enBrdPT3wLG94ITGbSOwUFg9fkLR-16R
  • Place datasets in ${derisk}/pilot/datasets
  • Flame Graph Assistant
  • Upload flame graphs (Java/Python) from your local application for analysis
  • DataExpert
  • Upload metrics, logs, traces, or Excel data for conversational analysis

Development

  • Agent Development
  • Refer to implementations under derisk-ext.agent.agents
  • Tool Development
  • Skills
  • MCP (Model Context Protocol)
  • DeRisk-Skills
  • derisk-skills
Execution Results

Citation

If you find this repository helpful, please cite:

@misc{di2025openderiskindustrialframeworkaidriven,
      title={OpenDerisk: An Industrial Framework for AI-Driven SRE, with Design, Implementation, and Case Studies}, 
      author={Peng Di and Faqiang Chen and Xiao Bai and Hongjun Yang and Qingfeng Li and Ganglin Wei and Jian Mou and Feng Shi and Keting Chen and Peng Tang and Zhitao Shen and Zheng Li and Wenhui Shi and Junwei Guo and Hang Yu},
      year={2025},
      eprint={2510.13561},
      archivePrefix={arXiv},
      primaryClass={cs.SE},
      url={https://arxiv.org/abs/2510.13561}, 
}

Acknowledgement

The OpenDeRisk-AI community is dedicated to building AI-native risk intelligence systems. 🛡️ We hope our community can provide you with better services, and we also hope that you can join us to create a better future together. 🤝

[](https://star-history.com/#derisk-ai/OpenDerisk)

Community Group

Join our DingTalk group and share your experience with other developers!

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.