Skip to main content
Run any Skill in Manus
with one click

mcp-sentinel

Security monitoring agent for Claude Skills and MCP servers. v2 adds a real-time protection layer (PreToolUse hook) that blocks malicious tool calls — credential exfiltration, known-bad domains like giftshop.club (Postmark MCP incident), reverse shells, curl|bash pipes — BEFORE they execute, with zero LLM cost. v1 static analysis still runs: scans installed skills/MCPs against multiple vulnerability databases (GitHub Advisory DB, vulnerablemcp.info, CVE feeds, mcpscan.ai, Snyk, ClawHub/VirusTotal) and community alerts (Reddit r/ClaudeAI, Discord), maintains a local threat database, performs coherence analysis and update diff detection. Use this skill whenever: the user asks about security of their skills or MCPs, wants to audit installed plugins, enable real-time protection, mentions "vulnerability", "CVE", "malicious skill", "security scan", "threat", "audit", "runtime protection", "block", says "is this skill safe?", asks to check dependencies, or wants ongoing security monitoring. Also trigger proactively

Overview

Security monitoring agent for Claude Skills and MCP servers. v2 adds a real-time protection layer (PreToolUse hook) that blocks malicious tool calls — credential exfiltration, known-bad domains like giftshop.club (Postmark MCP incident), reverse shells, curl|bash pipes — BEFORE they execute, with zero LLM cost. v1 static analysis still runs: scans installed skills/MCPs against multiple vulnerability databases (GitHub Advisory DB, vulnerablemcp.info, CVE feeds, mcpscan.ai, Snyk, ClawHub/VirusTotal) and community alerts (Reddit r/ClaudeAI, Discord), maintains a local threat database, performs coherence analysis and update diff detection. Use this skill whenever: the user asks about security of their skills or MCPs, wants to audit installed plugins, enable real-time protection, mentions "vulnerability", "CVE", "malicious skill", "security scan", "threat", "audit", "runtime protection", "block", says "is this skill safe?", asks to check dependencies, or wants ongoing security monitoring. Also trigger proactively

Install command
npx skills add https://github.com/soy-rafa/claude-mcp-sentinel --skill mcp-sentinel

Copy and paste this command into Claude Code to install the skill

Stars162
Forks22
UpdatedApril 18, 2026 at 00:11
SKILL.md
readonly