Sentinel Memory MCP
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| prompts | {
"listChanged": true
} |
| resources | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| project_openC | Create/open an isolated project. |
| scope_registerB | Record operator-provided authorization; never derive permission from target responses. Exact origins, accounts, environments and expiry required. |
| scope_readC | Read scope and expiry. |
| memory_storeC | Store versioned typed memory with epistemic state and provenance. |
| memory_searchB | Project-isolated FTS search over latest memory versions. |
| memory_contextC | Compile compact task context; critical state may exceed soft budget and is flagged. |
| memory_graphB | Read a bounded graph neighborhood or add a relationship. |
| evidence_storeB | Redact structured secrets and store immutable content-addressed evidence; manually review free text before import. |
| evidence_readB | Read and integrity-check evidence in a project. |
| task_updateC | Version task state and record test signature including deployment state. |
| task_check_duplicateC | Check prior completed exact test; changed deployment must use new state_version. |
| project_resumeB | Resume latest task, scope, findings, open work and next actions after restart. |
| security_skillsB | List generic evidence requirements and false-positive conditions. |
| security_triageD | Evaluate supplied evidence-backed claims; preserve uncertainty and version decisions. |
| security_severityB | CVSS 3.1 base score with metric explanation. Does not infer metric values. |
| security_reportC | Generate gated technical/executive reports and a minimal request template. |
| security_controlled_getC | One bounded GET, exact authorized origin and controlled account, pinned DNS, no redirects. No state-changing requests. |
| finding_correctB | Record a human correction without overwriting decisions; review before training. |
| model_adviseB | Optional local specialist; deterministic fallback when disabled. Cannot alter decisions. |
| audit_eventsB | Read paginated append-only audit events. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| continue-investigation | Evidence-first continue-investigation |
| validate-finding | Evidence-first validate-finding |
| compare-two-users | Evidence-first compare-two-users |
| prepare-report | Evidence-first prepare-report |
| review-false-positive | Evidence-first review-false-positive |
| regression-check | Evidence-first regression-check |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| security-skills | Generic security workflows |
TDQS
Scored across 20 tools
Each tool targets a distinct resource and action, with clear boundaries between evidence, memory, tasks, scope, and security operations. The security_* cluster is nuanced but differentiated by purpose: skills list requirements, triage evaluates claims, severity computes CVSS, report generates deliverables, and controlled_get performs a bounded request.
All names use lowercase snake_case with a consistent domain prefix, making the set easy to scan. Most follow a noun_verb pattern, but a few are noun_noun (e.g., security_skills, security_severity, memory_context, audit_events), which is a minor deviation.
20 tools is slightly above the typical 3-15 sweet spot, but the domain spans projects, evidence, tasks, security triage, scope control, memory, and audit. Each tool appears to earn its place, so the count is reasonable rather than bloated.
The surface covers core project, evidence, scope, memory, security, finding, and audit workflows. Minor gaps exist, such as no explicit task_create/list or project_list/close, but immutable and versioned designs mitigate them and agents can work around via existing tools.