Add sentinel-scan-cli to Security Testing - #81
Conversation
|
🔴 Contributor Check: HIGH
Automated check by AgenTrust Contributor Check. |
imran-siddique
left a comment
There was a problem hiding this comment.
Merging.
Verified rather than assumed: the repository exists, is MIT, is not archived, carries seven releases, and has the structure of a tool people run rather than a placeholder (bin, lib, fixtures, action.yml, package.json, plus an MCP server mode).
It is eleven days old with one star, and neither of those is a criterion here. The written criteria are what they are, and a listing that meets them does not have to wait for adoption to prove it deserved to. I have declined "hold for maturity" on this list before and it would be inconsistent to apply it now.
Disclosing that you maintain it, in one sentence, without being asked, is what a self-submission should look like. Placing it alphabetically beside Garak, PyRIT and Snyk Agent Scan rather than at the top of the section is the other half of the same instinct.
Adds sentinel-scan-cli, a free, open-source CLI (with an MCP server mode) that scans MCP manifests and LLM applications for tool poisoning, prompt injection, and rug-pulls, mapping findings to the OWASP LLM Top 10.
Placed alphabetically in Security Testing next to Garak/PyRIT/Snyk Agent Scan, since it targets the same MCP/agent-scanning use case.
Disclosure: I maintain this project (Ventrova).