AI.Sentinel

general MCP Server

Security monitoring middleware for IChatClient (Microsoft.Extensions.AI). 55 detectors for prompt injection, hallucination, PII leakage, and operational anomalies. Intervention engine, embedded dashboard, audit forwarders to Azure Sentinel + OpenTelemetry. Drop-in middleware for any LLM client.

Verified
generalgeneralazure
2 views1 stars0 forks

Why This Matters

Discovered via github-topic:mcp and last synced 3mo ago.

Verified
Source
github-topic:mcp
Stars
1
Last synced
3mo ago
Install
Check source

Install

Install instructions not detected yet

Check the source repository for the latest setup steps.

View source instructions
103
Tools
0
Resources
0
Prompts
Standard I/O
Transport

Available Tools (103)

SEC-06

PrivilegeEscalation

SEC-16

GovernanceGap

SEC-19

ToolCallFrequency

HAL-04

SourceGrounding

OPS-04

PlaceholderText

OPS-14

Sycophancy

LLM08

Vector & Embedding Weaknesses

Quarantine

Throws `SentinelException` with full `PipelineResult`. Stops the call. Also fires the alert sink.

SENTINEL_MCP_SCAN_MIMES

`text/,application/json,application/xml,application/yaml`

SENTINEL_HOOK_ON_LOW

`Allow`

Input

Mean

SEC-05

Jailbreak

SEC-15

PhantomCitationSecurity

SEC-28

RefusalBypass

HAL-03

CrossAgentContradiction

OPS-03

IncompleteCodeBlock

OPS-13

PersonaDrift

LLM07

System Prompt Leakage

SEC-03

ToolPoisoning

SEC-13

ShadowServer

SEC-26

PromptTemplateLeakage

HAL-01

PhantomCitation

OPS-01

BlankResponse

OPS-11

UnboundedConsumption

LLM05

Improper Output Handling

AzureSentinelAuditForwarder

`Azure.Monitor.Ingestion`, `Azure.Identity`

SENTINEL_MCP_DETECTORS

`security`

SENTINEL_HOOK_ON_CRITICAL

`Block`

Empty

clean

SEC-07

CovertChannel

SEC-17

SupplyChainPoisoning

SEC-21

ExcessiveAgency

HAL-05

ConfidenceDecay

OPS-05

ContextCollapse

OPS-15

WrongLanguage

SEC-02

CredentialExposure

SEC-12

UnauthorizedAccess

SEC-25

CodeInjection

OPS-10

WaitingForContext

LLM04

Data & Model Poisoning

Variable

Default

ID

Detector

SEC-10

AgentImpersonation

SEC-23

PiiLeakage

SEC-30

ShorthandEmergence

HAL-08

GroundlessStatistic

OPS-08

ResponseCoherence

LLM02

Sensitive Info Disclosure

In-process

`IServiceProvider.GetService<ISecurityContext>()` → Anonymous

audit

auto>] # default: auto [--output <text

Warn

Allow] [--on-low Block

Histogram

Pipeline scan duration in milliseconds

SEC-04

DataExfiltration

SEC-14

InformationFlow

SEC-27

LanguageSwitchAttack

HAL-02

SelfConsistency

OPS-02

RepetitionLoop

OPS-12

SemanticRepetition

LLM06

Excessive Agency

OpenTelemetryAuditForwarder

`OpenTelemetry`, `Microsoft.Extensions.Logging.Abstractions`

SENTINEL_MCP_MAX_SCAN_BYTES

`262144`

SENTINEL_HOOK_ON_HIGH

`Block`

Attribute

Description

Security-only

clean

SEC-08

EntropyCovertChannel

SEC-18

ToolDescriptionDivergence

SEC-22

HumanTrustManipulation

HAL-06

StaleKnowledge

OPS-06

AgentProbing

OWASP

Threat

LLM10

Unbounded Consumption

Log

Writes to `ILogger<InterventionEngine>`. Call continues.

SENTINEL_MCP_TIMEOUT_SEC

`5`

Metric

Type

Package

Purpose

SEC-09

IndirectInjection

SEC-20

SystemPromptLeakage

SEC-29

OutputSchema

HAL-07

IntraSessionContradiction

OPS-07

QueryIntent

LLM01

Prompt Injection

Surface

Caller resolution default

PassThrough

No action. Detections are still audited.

SENTINEL_MCP_LOG_JSON

(off)

Counter

Calls rejected by the per-session rate limiter (tagged by `session`)

malicious

~8,653 ns

SEC-01

PromptInjection

SEC-11

MemoryCorruption

SEC-24

AdversarialUnicode

SEC-31

VectorRetrievalPoisoning

HAL-09

UncertaintyPropagation

OPS-09

TruncatedOutput

LLM03

Supply Chain

Copilot

`CopilotHookConfig.CallerContextProvider` → Anonymous

Medium

High

LLM09

Misinformation

Alert

Publishes `ThreatDetectedNotification` + `InterventionAppliedNotification` via `IMediator`. Fires the alert sink. Call continues.

SENTINEL_MCP_HTTP_HEADERS

(none)

SENTINEL_HOOK_VERBOSE

`false`

clean

~6,268 ns

SentinelAction

Behaviour

SENTINEL_HOOK_ON_MEDIUM

`Warn`

Scenario

Mean