Analytics
A unified view of every Sentinel service — receipts written, policy compiled, bench coverage, and the agent surface guarded by the gate.
computing…
3-minute judge path
Show that Sentinel stops unsafe autonomous execution before it reaches Bitget Agent Hub.
Start with the adversarial call, show the sealed receipt, then back it with the 20-case benchmark and MCP integration surface.
- 1Run prompt injectionCompromised agent asks for DOGE and 50x leverage.
- 2Run transfer attemptUnsafe fund movement is blocked and sealed.
- 3Open Bench + MCPShow 20/20 adversarial coverage and the proxy surface.
Verdict composition by category
attack surface · sorted by severityIntercept mix
verdict ratio- Block——
- Modify——
- Allow——
Service health
drill inRecent receipts
latest bench run| Scenario | Tool | Symbol | Verdict | Receipt |
|---|---|---|---|---|
| loading… | ||||
Receipt stream
live| Time | Tool | Symbol | Verdict | Reason | Receipt |
|---|---|---|---|---|---|
| Click a trigger above to send an audited tool call through the Sentinel gate. | |||||
Active mandate
Describe the agent's mandate in natural language. Sentinel compiles it via Qwen (with a deterministic regex fallback) into a frozen policy object.
Compile the mandate to see the deterministic policy that the gate will enforce.
Violation catalog
Every code below is a structured reason the gate can emit. Receipts carry the codes verbatim so reviewers can replay decisions.
Adversarial scenarios
20 cases · deterministic Merkle rootStdio JSON-RPC proxy
The Sentinel MCP proxy wraps Bitget Agent Hub over stdio. Every tools/call for a write-class tool is intercepted, evaluated by the gate, and either passed through to Agent Hub, repaired before forwarding, or blocked with a receipt.
Tools that mutate state (orders, leverage, transfers, withdrawals) are routed through the gate. Read-only perception skills pass through transparently.
$ npm run mcp:proxy [Sentinel] MCP proxy listening on stdio [Sentinel] Bitget Agent Hub: upstream connected [Sentinel] Guarding 7 write toolsSurface
Tools currently routed through the Sentinel gate:
- futures_place_orderguarded
- futures_modify_orderguarded
- futures_cancel_orderguarded
- futures_set_leverageguarded
- spot_place_orderguarded
- transferguarded
- withdrawguarded
- market_data_*passthrough
- account_balancepassthrough
Bitget Agent Hub
Sentinel integrates with Bitget Agent Hub through a thin adapter. Tool calls arrive as MCP requests; the adapter normalizes them into a Sentinel intent, runs the gate, and either executes via the live Agent Hub or replies with a sealed block receipt.
Five perception skills (macro analyst, market intel, news briefing, sentiment analyst, technical analysis) read through the proxy without being gated. Execution-class tools are always gated.
// src/adapters/agent-hub.js const WRITE_TOOLS = new Set([ "futures_place_order", "futures_modify_order", "futures_cancel_order", "futures_set_leverage", "spot_place_order", "transfer", "withdraw" ]); export async function guardedToolCall(toolCall, ctx) { const intent = toolCallToIntent(toolCall); const decision = await ctx.gate.handle(intent); if (decision.verdict === "block") return blockResponse(decision); return ctx.hub.invoke(decision.intent); }Perception skills
Read-only context layered into the agent prompt — never gated, never sealed.
- macro-analystread-through
- market-intelread-through
- news-briefingread-through
- sentiment-analystread-through
- technical-analysisread-through
Repository
github.com/dmetagame/sentinel-flight-recorder — the deterministic gate, MCP proxy, Agent Hub adapter, Qwen integration, benchmark suite, and this dashboard.
Continuous integration runs the unit suite plus the 20-scenario bench on every push.
Layout
- src/core/risk.jsgate
- src/core/policy.jspolicy
- src/core/merkle.jssealing
- src/adapters/agent-hub.jsadapter
- src/adapters/qwen.jsllm
- src/mcp-proxy.jsstdio
- src/bench/scenarios.jsbench
- public/index.htmldashboard