Open source

Useful controls should be inspectable.

The tools published here are free and complete. You can inspect the mechanism, reproduce the evidence, and decide whether it belongs in your environment.

Public repository

Magus OpenSecMCP

A local Rust MCP security gateway that sits between an MCP client and downstream tool servers.

Policy controls, hash pinning, provenance states, audit controls, rule scanning, and bounded downstream behaviour make the operator’s control points explicit.

Inspect the repository
Early / public repository

Sentinel

Deterministic, non-executing evidence and change monitoring for public npm MCP servers.

Sentinel inspects an exact public npm artifact without running it, produces a schema-validated evidence report, and compares reports across releases. Its included self-hosted Watch monitor can poll packages you choose and raise a reviewable change notice.

View Sentinel on GitHub
How we publish

Repository documentation is the operational source of truth.

Read each repository’s README, licence, security guidance, and limitations before relying on it. The website provides context; the code and repository notices define the tool.