Sentinel
Deterministic, non-executing evidence and change monitoring for public npm MCP servers — built to surface the release where a package you already trusted becomes something else.
Sentinel inspects an exact public npm artifact without executing it, emits a schema-validated report of what that artifact declares, and compares reports to show what changed. The repository also includes Watch: a self-hosted monitor that polls packages you choose, runs Sentinel on new releases, and raises a reviewable change notice.
It does not decide whether a package is safe or malicious. It does not inspect private packages, local source trees, production credentials, MCP tool-call contents, or live traffic.