Skip to main content
Glama
sachin0610-srm

contract-sentinel

πŸ›‘οΈ C Sentinel β€” Autonomous AI Contract Sentinel

An enterprise-grade, MCP-powered AI agent system for automated contract ingestion, clause extraction, continuous risk monitoring, and real-time LLM integration.


πŸš€ Live Demos


Related MCP server: legal-doc-intelligence

πŸ“Œ Overview

C Sentinel is an autonomous risk-analysis agent built to solve enterprise legal bottlenecks. Powered by the Model Context Protocol (MCP), C Sentinel continuously monitors, ingests, and analyzes legal agreements (MSAs, NDAs, SLAs) to extract critical risk factors, uncapped liabilities, and dangerous SLA terms.

It provides both a modern, interactive web dashboard for human operators and a standardized MCP server interface that seamlessly integrates with external LLMs like ChatGPT and Claude.


✨ Key Features

  • πŸ“„ Automated Contract Ingestion: Ingest vendor agreements and instantly calculate overall risk scores (0–100%).

  • 🧠 Continuous Sentinel Analysis Cycle: Autonomous background cycle that audits all stored agreements for non-compliant clauses.

  • ⚑ Model Context Protocol (MCP) Native: Exposed as a streamable MCP server, allowing LLMs (like ChatGPT or Claude Desktop) to invoke tool actions (ingest, fetch_contracts, run_analysis) natively.

  • πŸ“Š Real-Time Operations Dashboard: Built with React, Vite, and Tailwind CSS to display contract velocity, risk breakdown charts, and active alerts.


πŸ—οΈ Architecture & Deployment

   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
   β”‚                  ChatGPT / LLM Connectors               β”‚
   β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                β”‚ (MCP Protocol)
                                β–Ό
 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
 β”‚   Vercel Frontend    │──▢│      NitroCloud Backend       β”‚
 β”‚    (React / Vite)    β”‚   β”‚     (NitroStack MCP Server)   β”‚
 β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜   β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Component

Tech Stack

Hosting Platform

Frontend UI

React, TypeScript, Vite, Tailwind CSS

Vercel

Agent Backend

Node.js, TypeScript, NitroStack MCP SDK

NitroCloud

Repository

Monorepo Structure (/ui & /server)

GitHub


βš™οΈ Environment Variables

Frontend (/ui)

Configure the backend connection URL in your .env file or deployment settings:

VITE_API_BASE_URL=https://c-sentinel-6a6ca7d2-dcoders-srmist.app.nitrocloud.ai

πŸ› οΈ Local Development Quickstart

Prerequisites

  • Node.js (v18+)

  • npm / pnpm

1. Clone the Repository

git clone https://github.com/sachin0610-srm/contract-sentinel.git
cd contract-sentinel

2. Run Backend (MCP Server)

cd server
npm install
npm run dev

3. Run Frontend UI

cd ../ui
npm install
npm run dev

Open http://localhost:5173 to access the local dashboard.


πŸ”Œ Connecting to ChatGPT / External MCP Clients

  1. Open ChatGPT $\rightarrow$ Settings $\rightarrow$ Developer Mode / Apps.

  2. Add a new MCP Connector / Server.

  3. Set Server URL to:

    https://c-sentinel-6a6ca7d2-dcoders-srmist.app.nitrocloud.ai/mcp
  4. Set Authentication to No Auth and save!


πŸ‘₯ Authors & Credits

Developed with ❀️ for the Hackathon by Sachin K (@sachin0610-srm).

Available Tools

4 tools
ingest-contractIngest contractA

Store a contract from its raw text. Assigns a unique id, extracts key clauses, the deadline date and the obligations into structured data, and adds it to the tracked contract portfolio.

ParametersJSON Schema
NameRequiredDescriptionDefault
titleNoOptional display title; derived from the contract text when omitted
contractTextYesThe full raw text of the contract to ingest

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations indicate readOnlyHint=false, so the write behavior is expected. The description adds context about what happens during ingestion (id assignment, extraction of clauses, deadline, obligations, portfolio addition). No side effects like duplicate handling are mentioned, but core behavior is transparent.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two concise sentences, front-loaded with the primary action. Every word earns its place without redundancy.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a simple tool with two parameters and no output schema, the description covers the overall process adequately. It doesn't specify the return value, but the main behavior and outcome are described.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema descriptions already cover both parameters fully (contractText and title). The description reinforces 'raw text' but doesn't add new parameter-specific meaning beyond what the schema provides. Baseline 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool stores a contract from raw text and details the specific actions (assigns unique id, extracts key clauses, deadline, obligations, adds to portfolio). This distinguishes it from sibling tools like review-portfolio and set-company-profile.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies the use case: when you have raw contract text and want to store/process it. It doesn't explicitly mention alternatives or when not to use, but the context is clear enough.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

review-portfolioReview contract portfolioA
Read-onlyIdempotent

Return the contract board: every tracked contract as a card with its risk score, classification (safe or danger), the exact clause text that drove the score, and the recommended action. Optionally filter to safe, danger, or contracts needing attention. Renders the contract-board widget.

ParametersJSON Schema
NameRequiredDescriptionDefault
filterNoWhich contracts to include; defaults to all

TDQS

A4.5/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint and idempotentHint, so the description doesn't need to cover safety. It adds valuable context by specifying the output format (cards with risk score, classification, exact clause text, recommended action) and that it renders a widget, which goes beyond what annotations provide.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is two sentences, front-loads the primary purpose, and includes only necessary details. There is no redundant repetition of schema or annotations, and every clause adds value.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description must explain the return value, and it does so thoroughly (card contents and filter behavior). The tool is simple (one optional parameter), and the description covers the essential behavior, making it complete for an agent to select and invoke correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The filter parameter is fully documented in the schema (enum and description), and the description reinforces its meaning by listing the filter options ('safe', 'danger', 'needs_attention') and noting the default behavior ('all'). This adds interpretive light beyond the raw schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly specifies the verb 'Return' and resource 'contract board', and enumerates the exact card contents (risk score, classification, clause text, recommended action). This distinguishes it from sibling tools (set, ingest, run) which are clearly different actions.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides clear context for when to use the tool (to review the contract portfolio) and mentions optional filtering, but does not explicitly name alternatives or state when not to use it. The sibling tool names make the distinction obvious, so this is a minor gap.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

run-sentinel-cycleRun sentinel cycle (agent loop)A

Run the autonomous Contract Sentinel agent loop over the entire tracked portfolio: perceive every contract, score its clause risk with full evidence, decide whether it needs action (deadline close, high risk score, or never reviewed), then act by setting status to needs_attention and recording a recommended action (renew as-is / renegotiate with talking points / let lapse). Designed to run on a schedule in production; runnable on demand here. Renders the contract-board widget.

ParametersJSON Schema
NameRequiredDescriptionDefault
dryRunNoWhen true, score and decide but do not write status changes back to the portfolio
onlyContractIdNoRestrict the cycle to a single contract id instead of the whole portfolio

TDQS

A4.5/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description fully discloses the mutation behavior: it 'act[s] by setting status to needs_attention and recording a recommended action'. It also explains the decision triggers (deadline close, high risk, never reviewed) and mentions rendering the widget. Annotations are consistent (readOnlyHint false, destructiveHint false), and the description adds context beyond annotations, such as the specific recorded actions and evidence gathering.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three sentences, each earning its place: first describes the core loop, second provides scheduling/usage context, third mentions the UI output. No filler or repetition; front-loaded with the primary action.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a tool with a moderately complex loop, two optional parameters, and no output schema, the description covers the full workflow, side effects, intended usage, and a key UI outcome. It does not need to explain return values since no output schema exists, and the schema covers parameters. Very complete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents both parameters (dryRun and onlyContractId) with clear descriptions. The description does not add parameter-specific meaning, but baseline 3 is appropriate since the schema carries the semantic load. No gap to compensate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description names a specific verb ('Run the autonomous Contract Sentinel agent loop') and resource ('entire tracked portfolio'), and details the workflow (perceive, score, decide, act). This clearly distinguishes it from sibling tools like review-portfolio (which likely only reviews) and ingest-contract (which likely ingests).

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description states it is 'designed to run on a schedule in production; runnable on demand here', giving clear context for when to use it. It does not explicitly name alternatives or exclusions, but the 'entire tracked portfolio' scope and 'on demand' note imply usage patterns. A brief mention of when not to use (e.g., prefer review-portfolio for quick review) would make it 5.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

set-company-profileSet company profileA
Idempotent

Store the company context (industry, headcount, jurisdiction, risk tolerance) for this session. Every other Contract Sentinel tool reads this profile when scoring contracts.

ParametersJSON Schema
NameRequiredDescriptionDefault
industryYesIndustry the company operates in, e.g. "fintech"
companySizeYesNumber of employees, e.g. 200
jurisdictionYesPrimary legal jurisdiction the company operates in, e.g. "Ireland"
riskToleranceYesHow much contractual risk the company is willing to accept

TDQS

A4.3/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond the annotations (idempotent, non-destructive, not read-only), the description adds the session-scoping detail ('for this session') and the downstream dependency on other tools. This clarifies that the tool is a stateful setter, though it does not mention the effect on previously stored profile values.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences with no filler. The first sentence states the action and parameters, and the second explains why the profile matters to other tools, making every word valuable.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The description covers the essential aspects for a state-setting tool: what it stores, the session scope, and its impact on sibling tools. Combined with the idempotency and non-destructive annotations, the agent has sufficient context to invoke it correctly without needing an output schema.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema has 100% coverage with detailed descriptions for all four parameters, including an enum for riskTolerance. The description merely lists the parameter names (using 'headcount' for companySize) without adding additional meaning beyond the schema, so it stays at the baseline 3.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the verb 'Store' and the resource 'company context' with specific fields (industry, headcount, jurisdiction, risk tolerance). It also explicitly notes that every other Contract Sentinel tool reads this profile, which distinguishes it from the sibling tools and establishes its role as a session-level setup.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies the tool should be used before other Contract Sentinel tools, since those tools read the profile when scoring contracts. It provides clear context for when to use it, but lacks explicit 'when not to use' guidance or named alternatives.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 4 tool updatesv1.0.0
    • First observedingest-contract
    • First observedreview-portfolio
    • First observedrun-sentinel-cycle
    • First observedset-company-profile

TDQS

A4.4/5.0

Scored across 4 tools

Disambiguation5/5

Each tool serves a distinct role: profile setup, contract ingestion, automated analysis, and portfolio review. There is no functional overlap between them.

Naming Consistency5/5

All tool names follow a clear verb-noun pattern using hyphens (set-, ingest-, run-, review-), making the naming predictable and consistent.

Tool Count5/5

With four tools, the set is well-scoped for a contract monitoring workflow: setup, input, processing, and output. No redundancy or excessive expansion.

Completeness4/5

The core lifecycle (profile setup, contract ingestion, analysis, and review) is covered. Minor gaps like deleting or manually updating contracts are not essential for the sentinel's autonomous monitoring purpose.

Maintenance

ActivitySlowing
ResponsivenessNo issues

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers