Indexedv1.4.16 · released Aug 25, 2026
Npm:Sentinel Scan Cli
npm:sentinel-scan-cli
MCP security scanner: scan MCP servers and tool manifests for tool poisoning, prompt injection, tool-name shadowing, excessive-agency schemas, unpinned/remote sources, and rug-pulls - 10 OWASP-mapped heuristics, CLI + MCP server, fully offline. Also runs
Indexed
Crawled from a public source. No check has passed yet, or a check failed.
Tiers are set by checks and outcomes only. Nobody can pay for a tier or a higher rank. How we check
What it can reach
From its install config and its own description; a sandbox run will confirm this later.
Network
- None seen
Files
- None seen
Accounts and secrets
- None seen
Checks on v1.4.16
Real tool
passrules 2026-09-29.1 · 3 hours agoStatic scan
passrules 2026-09-29.1 · 3 hours agoClaims check
skippedrules 2026-09-29.1 · 3 hours ago- infoLLM claims check is not configured on this deploy.
Install
Each app still asks you to confirm. Everything is pinned to the version checked above.
Open in VS Code
code --add-mcp '{"name":"npm-sentinel-scan-cli","type":"stdio","command":"npx","args":["-y","sentinel-scan-cli@1.4.16"]}'{
"servers": {
"npm-sentinel-scan-cli": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"sentinel-scan-cli@1.4.16"
]
}
}
}- 1.Click the link, or run the command.
- 2.VS Code asks you to confirm the server before it starts.
Pinned to v1.4.16 · 9de68c9ad380
Versions
- v1.4.16 · Aug 25, 2026
Signals
- Installs through us
- 0
- Agent reports
- none yet
- Publisher
- npm:sentinel-scan-cli · unclaimed
- Found via
- npm