Skip to main content

mcp-sentinel

Security monitoring agent for Claude Skills and MCP servers. Real-time protection layer (PreToolUse hook, zero LLM cost by default): hard-blocks confirmed-malicious tool calls (known-bad domains from real incidents and an auto-updating URLhaus malware feed) and, for merely suspicious ones (credential exfiltration, reverse shells, curl|bash pipes, raw-IP URLs, cloud-metadata/IMDS, config/persistence writes), asks you to approve or deny at the native prompt instead of blocking outright. Approving a flagged path/domain is remembered so it stops asking (trust builds as you confirm what you use). v3 adds: multi-step attack-chain detection (credential access then egress), cross-server data-flow tracking, a config/MCP scanner + integrity baseline (catches a malicious hook planted in a cloned repo), a shadow/audit-only mode (SENTINEL_SHADOW: never blocks, just tallies what it would have stopped), and an OPTIONAL, off-by-default AI escalation layer (SENTINEL_AI: only for ambiguous cases, token-budgeted, hardened again

Jump to install

Source facts

Repository
soy-rafa/claude-mcp-sentinel
Last source activity
July 13, 2026 at 17:29
Detected SKILL.md language
English
Stars
185
Forks
22

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.