Change detection
Artifact digest, per-file inventory, dependencies, install scripts and entrypoints are recorded on every package, every time. If something moved, you will know.
Commercial work informed by
VaHive Systems Lab
MCP servers update. Dependencies shift, tool schemas widen, install scripts appear, descriptions your model reads as instructions get rewritten. Sentinel records exactly what an npm artifact declares — without ever running it — and tells you what changed between two releases.
Apache-2.0 and complete. No withheld tier.
Almost every update is routine. The one that isn’t looks identical from the outside — same package, same name, same install command — and registries make versions discoverable without telling you what changed inside one.
An agent makes this worse than an ordinary dependency. It reads tool descriptions as instructions, and it acts on them without a human in the loop. Something has to be recording the shape of each artifact as it arrives, or the release that matters passes unnoticed.
Sentinel’s limitations page reports two numbers, not one: across a pinned corpus of 50 real published MCP servers, 37 yield a usable tool inventory and only 12 can be resolved completely. Both are stated because only the second permits the conclusion that a tool was removed. It names the five specific ways extraction breaks, and warns about the most likely way to misread a report. The corpus is checked in with exact versions and digests, so you can re-run the figure rather than take it on trust.
Artifact digest, per-file inventory, dependencies, install scripts and entrypoints are recorded on every package, every time. If something moved, you will know.
Recovered by parsing shipped JavaScript. Of 50 corpus packages, 37 yield a usable inventory and 12 resolve completely; the rest say why not. A list without complete: true is a lower bound.
Nothing is run, imported or started. No install scripts, no MCP session. A package can do things at runtime that no report mentions, and we say so.
Findings are facts with a severity input. Sentinel does not decide whether a package is malicious, and an empty findings list does not mean clean.
A local Rust MCP security gateway that sits between an MCP client and downstream tool servers.
Inspect the repository ↗Deterministic, non-executing evidence and change monitoring for public npm MCP servers.
View Sentinel on GitHub ↗A policy written in prose does not enforce itself. A model can make nuanced assessments, but it cannot make a deterministic claim. A guardrail can help, but it should not be asked to be the whole system.
The decision context: what a person or organisation intends to authorise.
A probabilistic system that generates, reasons, classifies, and proposes actions.
Useful screening and routing controls; valuable, but not a universal guarantee.
The explicit rules defining who or what may act, and under which conditions.
Repeatable specified checks or blocks before tools, APIs, files, or other actions.
Audit records, version history, and human judgement as context, authority, and dependencies change.
Time is a control surface too: permissions, dependencies, context, and accumulated risk can change after an agent is deployed.
These papers frame questions and proposed architectures. They are not product certification or evidence that a theoretical mechanism has been deployed.
A theoretical governance architecture and open issues register for structural alignment drift in long-running agentic systems. It is not a report of a deployed product.
Read the preprint ↗A proposed framework for comparing input, expressed reasoning, activation-level representations, and execution intent. It makes no empirical performance claims.
Read the preprint ↗We offer structural governance and drift audits, adversarial issues registers, and scoped advisory work. The same boundaries apply: we say what we can assess before an engagement begins.