Skip to main content

mcp-sentinel

Security monitoring agent for Claude Skills and MCP servers. Real-time protection layer (PreToolUse hook, zero LLM cost by default): hard-blocks confirmed-malicious tool calls (known-bad domains from real incidents and an auto-updating URLhaus malware feed) and, for merely suspicious ones (credential exfiltration, reverse shells, curl|bash pipes, raw-IP URLs, cloud-metadata/IMDS, config/persistence writes), asks you to approve or deny at the native prompt instead of blocking outright. Approving a flagged path/domain is remembered so it stops asking (trust builds as you confirm what you use). v3 adds: multi-step attack-chain detection (credential access then egress), cross-server data-flow tracking, a config/MCP scanner + integrity baseline (catches a malicious hook planted in a cloned repo), a shadow/audit-only mode (SENTINEL_SHADOW: never blocks, just tallies what it would have stopped), and an OPTIONAL, off-by-default AI escalation layer (SENTINEL_AI: only for ambiguous cases, token-budgeted, hardened again

الانتقال إلى التثبيت

معلومات المصدر

المستودع
soy-rafa/claude-mcp-sentinel
آخر نشاط في المصدر
١٣ يوليو ٢٠٢٦ في ١٧:٢٩
لغة SKILL.md المكتشفة
الإنجليزية
النجوم
١٨٥
التفرعات
٢٢

خيارات التثبيت

يُحدَّد Prompt الذي يراجع المصدر أولًا بشكل افتراضي. يمكنك التبديل إلى أمر مباشر أو تنزيل نسخة محلية.

مراجعة ملفات المصدر

اقرأ SKILL.md وأي ملفات مرافقة يعرضها SkillsMP قبل أن تقرر التثبيت.