← all publishers

soy-rafa

@soy-rafa source repo

1 published skill

  1. MCP Sentinel · soy-rafa bundle
    Security monitoring agent for Claude Skills and MCP servers. Real-time protection layer (PreToolUse hook, zero LLM cost by default): hard-blocks confirmed-malicious tool calls (known-bad domains from real incidents and an auto-updating URLhaus malware feed) and, for merely suspicious ones (credential exfiltration, reverse shells, curl|bash pipes, raw-IP URLs, cloud-metadata/IMDS, config/persistence writes), asks you to approve or deny at the native prompt instead of blocking outright. Approving a flagged path/domain is remembered so it stops asking (trust builds as you confirm what you use). v3 adds: multi-step attack-chain detection (credential access then egress), cross-server data-flow tracking, a config/MCP scanner + integrity baseline (catches a malicious hook planted in a cloned repo), a shadow/audit-only mode (SENTINEL_SHADOW: never blocks, just tallies what it would have stopped), and an OPTIONAL, off-by-default AI escalation layer (SENTINEL_AI: only for ambiguous cases, token-budgeted, hardened again
    0
    installs