Skip to main content

mcp-sentinel

Security monitoring agent for Claude Skills and MCP servers. Real-time protection layer (PreToolUse hook, zero LLM cost by default): hard-blocks confirmed-malicious tool calls (known-bad domains from real incidents and an auto-updating URLhaus malware feed) and, for merely suspicious ones (credential exfiltration, reverse shells, curl|bash pipes, raw-IP URLs, cloud-metadata/IMDS, config/persistence writes), asks you to approve or deny at the native prompt instead of blocking outright. Approving a flagged path/domain is remembered so it stops asking (trust builds as you confirm what you use). v3 adds: multi-step attack-chain detection (credential access then egress), cross-server data-flow tracking, a config/MCP scanner + integrity baseline (catches a malicious hook planted in a cloned repo), a shadow/audit-only mode (SENTINEL_SHADOW: never blocks, just tallies what it would have stopped), and an OPTIONAL, off-by-default AI escalation layer (SENTINEL_AI: only for ambiguous cases, token-budgeted, hardened again

跳到安装

来源信息

仓库
soy-rafa/claude-mcp-sentinel
最近来源活动
2026年7月13日 17:29
检测到的 SKILL.md 语言
英语
星标
185
分支
22

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。