MCP Sentinel v0.1.0
MCP Sentinel v0.1.0 is the first public release of the build-time security scanner for Model Context Protocol servers.
Highlights
- Hybrid AST and Semgrep static analysis with SENT-001 through SENT-007.
- Required GPT-5.6 semantic review with live, replay, and explicitly degraded modes.
- Docker-isolated adversarial probing with SENT-008 through SENT-011.
- Canonical console, JSON, and offline-validated SARIF 2.1.0 reports.
- Composite GitHub Action with Code Scanning integration.
- Bundled fixtures, schemas, GPT replay cassettes, and judge-facing demo artifacts.
Quick start
Download the attached wheel, install it with pip or pipx, start Docker, and run:
sentinel demo --replay-reviewPython 3.10 through 3.12 is supported. Replay mode does not require an OpenAI API key.
Release evidence
The attached wheel passed the full Linux, macOS, and Windows CI matrix, pip and pipx installation smoke tests, and the installed-wheel Docker replay test in GitHub Actions run 29686427335.
Wheel SHA-256: 4672e63413e87bf750113c06a21133162d00f1e71ca6259a8394028c22b677aa.