Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Transports: stdio vs HTTP
  • State of MCP (stats)
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ”’ Security
  3. SentinelX
SentinelX logo
Health: ActiveRecent health check succeeded.Last checked 9/21/2026, 6:46:11 PM

SentinelX

User RatingsBe the first to rate and review this MCP server!
View Repository9 GitHub StarsTotal stargazers on GitHub for the source repository (9 stars).Visit Website
server-managementsecuritymcplinuxmacos

Manage allowlisted Linux and macOS host operations through MCP with audited actions and an outbound WebSocket connection.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

One-click editor setup isn’t available for this listing yet β€” we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ
No confirmed setup config for this listing yet. We only publish a config block when the install details come from the project itself β€” its README, its docs, or a verified owner. We haven’t found those for SentinelX, and we’d rather show nothing than a guess you’d paste into your client. Follow the project’s own setup instructions for the current steps.
Install Tool Schemas (18) Directory Badge Claim listing AlternativesπŸ”’ More in Security

Overview

SentinelX runs an agent on each managed Linux or macOS host and exposes shell, filesystem, and service-management operations through MCP. Commands, services, and filesystem paths are restricted by configurable allowlists, and actions are recorded. Use it when an LLM needs controlled remote server administration without opening inbound ports.

Use cases

β€’Run approved shell commands on managed hosts
β€’Edit, move, copy, delete, and inspect allowlisted files
β€’Start, stop, restart, reload, and inspect systemd services
β€’Upload files to a host
β€’Search host files using regex and glob filters

Key features

β€’Allowlisted shell and script execution
β€’Per-path filesystem access controls
β€’Structured file operations
β€’Service management through systemctl
β€’Audited action recording
β€’Outbound WebSocket connection without inbound ports

Capabilities & Tool Schemas (18) ~255 tokensApproximate context cost of this server’s tool schemas (~4 chars/token), before any tool is called. Actual usage depends on your client and model.Self-reported Self-reportedParsed from the repository README, not verified against a live server β€” may be incomplete or out of date.

Inspect callable tools, capabilities, and parameters exposed to AI agents by SentinelX.

sentinel_exec

Run an allowlisted shell command

sentinel_script_run

Run a one-off bash or python3 script

sentinel_edit

Structured file edit (replace, regex, replace-block, write, append, prepend)

sentinel_move

Move/rename a file or directory

sentinel_copy

Copy a file or directory

sentinel_delete

Delete a file or directory

Documentation Overview

sentinelx-cloud-core

Operate your Linux, macOS, and Windows servers from Claude.ai or ChatGPT β€” safely. SentinelX gives your LLM an allowlisted, auditable shell: it can only run commands you've explicitly permitted, filesystem access is gated by a per-path allowlist, and every action is recorded. No inbound ports β€” just a single outbound WebSocket.

The security model is the point. Handing an LLM unrestricted shell on a server you care about is the thing SentinelX is designed to avoid: the allowlist is the real trust boundary, so the agent can't run β€” or invent β€” anything you didn't allow. This is the agent you install on the host; structured file edits and service management come with it.

SentinelX checking a server's RAM and storage from ChatGPT
SentinelX in ChatGPT β€” it reads the allowlist, runs only what's permitted (df -h, /proc/meminfo), and reports back.

Install

Most people start with the one-liner β€” it auto-detects Linux or macOS:

Terminal
curl -fsSL https://get.sentinelx.app | bash

Windows (PowerShell β€” needs Python 3.12+ and git on PATH):

Service install β€” runs as LocalSystem at boot; needs an elevated PowerShell:

powershell
iwr -useb https://get.sentinelx.app/install.ps1 -OutFile "$env:TEMP\sx.ps1"
powershell -ExecutionPolicy Bypass -File "$env:TEMP\sx.ps1"

Per-user install β€” no admin; runs as you at logon (locked-down machines):

powershell
iwr -useb https://get.sentinelx.app/install.ps1 -OutFile "$env:TEMP\sx.ps1"
powershell -ExecutionPolicy Bypass -File "$env:TEMP\sx.ps1" -User

The installer clones this repo into a virtualenv, registers the agent as a service (systemd / launchd / Windows service), and walks you through enrollment. On networks that block PyPI, add -Bundle <zip-or-url> for an offline install from the wheel bundle on the latest release; the agent uses the OS trust store (truststore) so a TLS-inspecting proxy's CA is accepted. Full options β€” per-user vs service, offline bundle, all flags, uninstall β€” live in sentinelx-cloud-installer.

SentinelX is also listed in the ChatGPT app directory β€” ChatGPT users can connect it in one click, no custom MCP URL required.

This repo is also the agent's source β€” read on if you want to audit or contribute.

Architecture

Code
                                        Internet
                                            β”‚
   β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”                       β”‚                  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
   β”‚  Claude.ai or  β”‚   MCP over HTTPS      β”‚   WebSocket      β”‚  Your host      β”‚
   β”‚   ChatGPT      β”‚ ◄───────────────────► β”‚ ◄──────────────► β”‚                 β”‚
   β”‚                β”‚   (OAuth via Google)  β”‚                  β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”‚
   β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜                       β”‚                  β”‚  β”‚  agent    β”‚  β”‚
                                β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”      β”‚  β”‚ (this)    β”‚  β”‚
                                β”‚   mcp.sentinelx.app   β”‚      β”‚  β””β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”˜  β”‚
                                β”‚  (SentinelX hub β€”     β”‚      β”‚        β”‚        β”‚
                                β”‚   closed source)      β”‚      β”‚   shell, edit,  β”‚
                                β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜      β”‚   service mgmt  β”‚
                                                               β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

The agent is the box on the right. It opens one outbound WebSocket to the hub at install time (after enrollment) and stays connected. No inbound ports, no port-forwarding, no reverse tunnel.

What runs where

ComponentWhereWhat it does
sentinelx-cloud-core (this repo)/opt/sentinelx-cloud-core on your hostReceives MCP tool calls from the hub, executes them locally, returns output
Hubmcp.sentinelx.app (operated by Pensa)Auth, multi-host routing, MCP transport
Config/etc/sentinelx/config.yamlAllowlist: which commands, services, and paths the agent will accept
Identity/etc/sentinelx/identity.jsonThe agent's enrollment JWT, used to authenticate the WebSocket handshake

Supported platforms: any modern Linux distribution with systemd (tested on Ubuntu 22.04 / 24.04 and Debian 12), macOS with launchd (Intel and Apple Silicon), and Windows β€” as a service (WinSW, admin) or as a no-admin per-user Scheduled Task (-User); see Install on Windows below. The one-line installer auto-detects Linux and macOS; Windows uses a PowerShell installer. The agent also runs unmodified inside WSL2.

Tools exposed

The agent exposes its host's operations as MCP tools to your LLM via the hub:

ToolWhat it does
sentinel_execRun an allowlisted shell command
sentinel_script_runRun a one-off bash or python3 script
sentinel_editStructured file edit (replace, regex, replace-block, write, append, prepend)
sentinel_edit_upload_*Three-step upload for large file edits
sentinel_moveMove/rename a file or directory
sentinel_copyCopy a file or directory
sentinel_deleteDelete a file or directory
sentinel_chmodChange file permissions
sentinel_chownChange file owner/group
sentinel_servicesystemctl start/stop/restart/reload/status
sentinel_restartShortcut for sentinel_service with action=restart
sentinel_upload_fileSingle-shot file upload to the host
sentinel_upload_*Three-step chunked upload for large files
sentinel_readRead a file's contents, with optional line-range slicing
sentinel_listStructured directory listing (name, type, size, mtime)
sentinel_searchRecursive content search with regex and glob filters
sentinel_capabilitiesHost policy/capabilities; optional bounded summary projection
sentinel_helpRich orientation/help; optional topic/path/single-playbook projections
sentinel_stateInternal agent state, for debugging
sentinel_pingCheap connectivity check

Progressive introspection (agent operation contract)

The agent-side help and capabilities operations also support optional narrow-response selectors. A Hub/MCP profile may expose these fields through whatever model-facing tool shape it uses; the selectors are backend-operation semantics and do not depend on full vs compact tool names.

  • help({"topic":"index"}) β€” small topic + paged playbook index.
  • help({"topic":"security"}) β€” one broad help section.
  • help({"path":"security_model.permission_errors"}) β€” one exact leaf from the existing help tree.
  • help({"playbook":"update_sentinelx_code"}) β€” one playbook only; optional path, offset, and limit can select/page a subfield such as steps.
  • capabilities({"detail":"summary"}) β€” host/operation/limit metadata and policy counts without command/service/location/playbook bodies.

Progressive help/playbook responses normalize explicit full-profile sentinel_* references to op:<name> canonical operation hints so the same guidance can be routed through compact or full presentation without teaching a playbook two sets of MCP tool names.

For compatibility, empty help({}) and capabilities({}) requests retain the legacy full responses. A Hub that wants compact-first behavior should map its compact help/capabilities branches to the narrow selectors rather than changing the agent's legacy empty-payload semantics.

sentinel_read, sentinel_list, and sentinel_search are read-only filesystem primitives. sentinel_edit and the mutating primitives (sentinel_move, sentinel_copy, sentinel_delete, sentinel_chmod, sentinel_chown) write. All of them give the LLM structured access to the filesystem without shelling out to cat/ls/mv/rm through exec, and all of them are gated by the same path allowlist (file_ops in the config, see below), not the command allowlist. Each path in that allowlist declares an access level: r (read-only ops) or rw (read-only ops plus the writing ops). Destructive operations that overwrite or remove an existing target make a timestamped backup first.

The hub additionally exposes a handful of hub-side integrations (Cloudflare DNS, Resend email, Telegram) as MCP tools your LLM can use alongside the agent's tools β€” those live on the hub, not in this repo. See the integrations table on sentinelx.app.

Config (/etc/sentinelx/config.yaml)

A starter config is generated at install time. Editable. Reloaded when the service restarts. Schema:

yaml
# Commands the agent can execute via the `exec` op. Prefix-matched against
# this list; empty/missing = nothing allowed (deny by default).
allowed_commands:
  - uptime
  - df -h
  - free
  - systemctl
  - sudo systemctl
  - journalctl
  # See config.example.yaml for the full starter list (file inspection,
  # networking, containers, git, etc.) plus opt-in categories
  # (Cloudflare tunnels, WireGuard, Android tooling, firewalling, SSH).

# Service units the agent is allowed to control via `service` / `restart`.
# Each unit explicitly lists which actions are permitted.
services:
  nginx:
    actions: [status, start, stop, restart, reload]
  docker:
    actions: [status, restart]
  # The agent itself, so the LLM can reload policy after editing the
  # config. Restarting re-reads /etc/sentinelx/config.yaml. Conservative
  # actions only β€” no start/stop, since the agent can't remotely start
  # itself once stopped.
  sentinelx-cloud-core:
    actions: [status, restart, is-active, is-enabled]
  # postgresql:
  #   actions: [status, start, stop, restart, reload]

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Security View all alternatives
  • Kastell logoKastell

    Server security auditing and hardening toolkit. 413 security checks across 29 categories (SSH, Firewall, Docker, TLS, HTTP Headers), CIS/PCI-DSS/HIPAA compliance mapping, 19-step production hardening, fleet management, and forensic evidence collection. Supports Hetzner, DigitalOcean, Vultr, and Linode. 13 MCP tools.

    πŸ”’ Security4 views
    Compare vs Kastell β†’
  • Agentward logoAgentward

    Permission control plane for AI agents. MCP proxy that enforces least-privilege YAML policies on every tool call, classifies sensitive data (PII/PHI), detects dangerous skill chains, and generates compliance audit trails. Supports stdio and HTTP proxy modes.

    πŸ”’ Security5 views
    Compare vs Agentward β†’
  • Shield logoShield

    Local guardrail proxy for AI coding agents. Wraps any MCP server (stdio or Streamable HTTP) and blocks destructive tool calls β€” DROP TABLE, rm -rf, force-push β€” before they execute. MCP supply-chain protection: TOFU tool-catalog pinning against rug pulls, plus tool-description and tool-result scanning for tool poisoning and prompt injection. 51 starter rules, approval gates, audit logging. Single binary, Apache-2.0.

    πŸ”’ Security4 views
    Compare vs Shield β†’
  • Shellward logoShellward

    AI Agent Security Middleware & MCP Server with 8-layer defense including prompt injection detection, DLP data flow tracking, command blocking, and PII detection. 7 MCP tools, zero dependencies.

    πŸ”’ Security3 views
    Compare vs Shellward β†’

Adoption & maintenance

Factual signals from GitHub, npm, and our automated checks β€” not a rating.

GitHub stars
9
Stargazers on the source repository.
Last commit
3d ago
Most recent push to the default branch.
Tools exposed
18
Callable tools this server registers over MCP.
Directory activity
2 views
Config copies, upvotes, and views on AllMCPs.

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about SentinelX

It supports modern Linux distributions with systemd and macOS with launchd. It also runs unmodified inside WSL2.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewSentinelX AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/sentinelx?style=directory)](https://allmcps.com/mcp/sentinelx)
HTML Embed
<a href="https://allmcps.com/mcp/sentinelx"><img src="https://allmcps.com/api/badge/sentinelx?style=directory" alt="SentinelX on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ”’Security
PricingFree
More technical detailsExpand β–Ύ
AuthOAuth
Last updatedSep 21, 2026
12/12 checks healthy over the last 45d
Views2
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars9
GitHub Star CountTotal stargazers on GitHub representing community popularity (9 stars).
Last commit3d ago
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Sep 21, 2026
51Quality signal: Good Β· 51/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools22/30
Adoption & activity6/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… FeaturedAllMCPs Server logo

AllMCPs Server

The official MCP server for AllMCPs.com - submit and manage tools directly from your AI. The open directory for MCP servers. Connect Claude, Cursor, Windsurf, and AI agents to databases, tools, files, and APIs. Explore 10,000+ servers. AllMCPs is the premier, open directory for discovering, evaluating, and installing Model Context Protocol (MCP) servers to equip AI agents and LLMs with real-world superpowers.

Explore Server β†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ”’ Security β†’Best MCP servers for Security β†’Alternatives to SentinelX β†’Install in Claude DesktopInstall in CursorInstall in VS CodeSetup guides for all 13 MCP clients