Automated security audits for Claude Code agent deployments. Identity tamper detection, secret scanning, CVE checks. One plugin, five modules, zero dependencies.
Each module runs independently. Configure which ones to enable, customize detection patterns, get structured JSON output for CI/CD.
Tracks SHA-256 snapshots of every agent identity and config file. If CLAUDE.md, agent definitions, or system prompts change without your knowledge, Sentinel raises a CRITICAL alert. The attack surface nobody else monitors.
SSH config audit, firewall status, OS update checks, file permission scans, environment secret validation. Full coverage on macOS and Linux.
17 built-in regex patterns catch AWS keys, Anthropic and OpenAI tokens, Stripe secrets, GitHub PATs, GitLab tokens, private keys, DB connection strings. Add your own custom patterns via config.
npm audit (v6 + v7 compatible), Python pip and Pipfile via the OSV API, Rust cargo-audit. Public CVE databases only. Zero false positives by design.
Multi-project scanning with automatic detection of code vs document repositories. Locale-aware PII detection covering English, French, and German patterns.
Subscribe, accept the GitHub invite, install the plugin. That's it.
Enter your GitHub username at checkout. We grant access to the private plugin repo within minutes.
Check your GitHub notifications for the repo invite. Accept it to unlock plugin access.
Two commands in Claude Code:/plugin marketplace add/plugin install
Type /security-audit and get a full report. Auto-updates on every Claude Code startup.
Secure checkout via Stripe. You'll enter your GitHub username during payment.
This agent runs on Claude Code. You will need:
The agent installs in 2 commands and auto-updates.