
from claude-mcp-sentinel75
Security monitoring and runtime protection for Claude Skills and MCP servers: static scans, update-diff analysis, threat intelligence, and an optional PreToolUs
MCP Sentinel scans installed Claude Skills and MCP servers for vulnerabilities and malicious behavior by combining static analysis, external threat intelligence, coherence checks, and update diff detection. Version 2 adds a PreToolUse runtime hook that inspects tool calls in real time and can block credential exfiltration, dangerous shell patterns, and known-malicious domains before they execute.
Run Sentinel when auditing installed skills/MCPs, before installing a new skill or MCP (pre-install check), after noticing suspicious behavior, or on a regular schedule to detect supply-chain changes. Offer the runtime hook when the user requests live protection or when a suspicious update is detected.
Designed for agents with file access, shell execution, and websearch capabilities (e.g., Claude Code, security-focused assistants). The runtime hook requires Python 3 and jq for installer scripts.
This skill has not been reviewed by our automated audit pipeline yet.