Sentinel — public watch

What we watch, and what moved.

These are public MCP servers we check every six hours against the version we approved. Every change below is read from the published artifact — no package was executed, and nothing here is a judgement about whether a package is safe.

13 packages published hereChecked every six hoursNothing outstandingAs of 2026-08-15 05:21 UTC
Current

Nothing has moved since we last approved these.

The other 13 were checked at the same time and had not changed.

All 13 packages — the full list we check, whether or not it moved
Reading this page

What it tells you, and what it does not.

Every change carries one of three labels. They rank what to read first — they are not risk scores, and none of them says a package is unsafe.

Read first

Something that shapes what an agent will do has changed — a tool, an entrypoint, code that runs on install, or an instruction the model reads. Read the difference before upgrading.

Worth reading

Something previously approved has moved. Usually ordinary release activity, and still worth a look before it reaches an agent.

Context

Recorded so the account of the release is complete. Not a reason to act on its own.

It does not tell you whether a package is safe. Sentinel records what changed between two published artifacts and stops there. Ranking a change is a judgement, and the judgement is yours.

It does not tell you what a package does when it runs. Nothing here was executed. A package can do things at runtime that no static report mentions.

It does not follow dependencies. Only a package’s own files are read, so a change inside something it depends on is visible as a version moving and no further.

The tool list is inferred, and sometimes cannot be read at all. Artifact digest, file inventory, dependencies, scripts and entrypoints are recorded in full on every release. Tool names are recovered by reading source, which does not always succeed — where it fails we say so on the package rather than reporting an empty toolset.