CCM
/MCP
SkillsMCPMarketplacesDigestToolsAdvertise

This week in Claude

Every Monday: Claude Code, Agent SDK, MCP, and the Anthropic platform moves worth your time.

Skills by Category
Frontend DevelopmentBackend & APIsTesting & QASecurityDevOps & CI/CDGit & Pull RequestsDocumentationCode Review & QualityAI & Agent BuildingSkill Development
MCP Servers by Category
Sales & MarketingWeb & Browser AutomationDatabasesAI & LLM ToolsCloud & InfrastructureCommunication & MessagingDeveloper ToolsDesign & CreativeDocuments & KnowledgeSearch & Web Crawling
Marketplaces by Category
AI Agents & OrchestrationLLM IntegrationDevelopment ToolsFrontend & UIBackend & APIsDatabasesTesting & Code QualityDevOps & CloudSecurity & ComplianceGit & Version Control

Claude Code Marketplaces

Discover Claude Code plugins, extensions, and tools. Automatically updated directory of Anthropic Claude AI marketplaces with development tools, productivity plugins, and integrations.

Resources

  • Browse Skills
  • Browse MCP Servers
  • Browse Marketplaces
  • Skill index
  • MCP index
  • Marketplace index
  • Plugins Reference

Community

  • About
  • Tools
  • Feedback
  • Privacy Policy
  • Advertise

Built for the Claude Code community with Claude Code by mertbuilds.com

Independent project, not affiliated with Anthropic
maxgerhardson avatar

Sentrik

maxgerhardson/sentrik-community
authSTDIOregistry active
Summary

Adds governance and compliance enforcement to AI coding workflows by exposing Sentrik's scanning engine through MCP. The server gives Claude and other agents real-time access to compliance rules (OWASP, SOC 2, HIPAA, PCI-DSS), scan results, and remediation guidance so they can write compliant code from the start rather than catching violations in PR review. Useful if you're generating code at speed with AI agents and need to enforce security policies, regulatory standards, or architectural rules before commits ship. The underlying CLI supports 158+ rules across 5 free standards packs, with paid tiers adding medical device (FDA IEC 62304), government (NIST, CMMC), and automotive standards.

CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
inference shell
inference shell
create and run specialised agents in minutes
build now →
MCP-ready Email SendingMCP-ready Email Sending
MCP-ready Email Sending
Plug Mailtrap into your AI workflow and let it handle the email.
Connect Mailtrap MCP →
Make your agent a DeFi expert
Make your agent a DeFi expert
Agent, run crypto. Access onchain data & trade routes via 1inch.
Install now →
Capacitor - Shared memory for your team’s coding agents.
Capacitor - Shared memory for your team’s coding agents.
Make coding agent sessions - Searchable, Shareable, Vendor-neutral & Scored.
Try For Free →
CodeScene MCP ServerCodeScene MCP Server
CodeScene MCP Server
Your agent targets a perfect 10 Code Health score. Deterministic. Every commit.
Try For Free →
Give your AI the whole web as clean markdownGive your AI the whole web as clean markdown
Give your AI the whole web as clean markdown
Integrate web data into your AI product. One API to scrape website & brand data.
Get API Key Now →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →
CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
inference shell
inference shell
create and run specialised agents in minutes
build now →
MCP-ready Email SendingMCP-ready Email Sending
MCP-ready Email Sending
Plug Mailtrap into your AI workflow and let it handle the email.
Connect Mailtrap MCP →
Make your agent a DeFi expert
Make your agent a DeFi expert
Agent, run crypto. Access onchain data & trade routes via 1inch.
Install now →
Capacitor - Shared memory for your team’s coding agents.
Capacitor - Shared memory for your team’s coding agents.
Make coding agent sessions - Searchable, Shareable, Vendor-neutral & Scored.
Try For Free →
CodeScene MCP ServerCodeScene MCP Server
CodeScene MCP Server
Your agent targets a perfect 10 Code Health score. Deterministic. Every commit.
Try For Free →
Give your AI the whole web as clean markdownGive your AI the whole web as clean markdown
Give your AI the whole web as clean markdown
Integrate web data into your AI product. One API to scrape website & brand data.
Get API Key Now →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →

Sentrik

Governance runtime for AI-generated code

Scan, gate, and trace compliance automatically — before it ships.

Website • Docs • Community • Pricing


What is Sentrik?

Sentrik is a CLI + dashboard that enforces coding standards, compliance rules, and security policies on every commit. Built for teams using AI coding agents (Claude Code, Cursor, Copilot) where code is generated faster than humans can review it.

The problem: AI agents write code that works but may violate security policies, compliance requirements, or architectural standards. Nobody catches it until audit time.

The solution: Sentrik scans every change against regulatory standards (OWASP, SOC 2, HIPAA, PCI-DSS, FDA IEC 62304, and more), gates PRs that fail, and generates audit-ready evidence.

Install

pip install sentrik

Installing gives you the free tier immediately — 6 standards packs, 193 rules, no license key or sign-up. Paid tiers are activated with a license key from hello@sentrik.dev.

Quick Start

# 1. Initialize your project (auto-detects language, frameworks, CI)
sentrik init

# 2. Scan your code
sentrik scan

# 3. Enforce the gate in CI (exit 1 on failure)
sentrik gate

# 4. Launch the dashboard
sentrik dashboard

Free Tier (forever, no credit card)

Sentrik includes 6 standards packs with 193 rules for free:

PackRulesWhat it catches
OWASP Top 1069SQL injection, XSS, auth flaws, SSRF, and more
SOC 230Trust services criteria for security & availability
Python Security18eval/exec, pickle, subprocess, Django/Flask vulns
Go Security15Injection, crypto misuse, unsafe, concurrency bugs
Supply Chain Security26SLSA, SBOM, dependency integrity, AI tool supply chain
C/C++ Coding Standards35Modern C/C++ safety and security practices

Plus built-in commands at every tier:

  • sentrik scan / sentrik gate - Scan and enforce
  • sentrik vulns - Dependency vulnerability scanning (CVEs)
  • sentrik sbom - Software bill of materials
  • sentrik secrets - Hardcoded secrets detection
  • sentrik dashboard - Web UI with findings, charts, and reports
  • sentrik threat-model - STRIDE threat analysis
  • sentrik quality-score - Code quality scoring (0-100)

Paid Tiers

FreeTeamOrganization
Standards packs6 (193 rules)18 (475 rules)24 (595 rules)
OWASP, SOC 2, Supply Chain, C/C++YesYesYes
HIPAA, PCI-DSS, ISO 27001, GDPR-YesYes
FDA IEC 62304, NIST, CMMC, Cloud IaC-YesYes
MISRA-C, DO-178C, ISO 26262--Yes
Vulnerability scanningYesYesYes
DashboardYesYesYes
Work item reconciliation-YesYes
Custom rule packs525100
Parallel scanning--Yes
Governance & audit log--Yes

Paid tiers are available by contacting hello@sentrik.dev — see sentrik.dev/pricing.

CI/CD Integration

GitHub Actions (Marketplace)

# .github/workflows/sentrik.yml
name: Sentrik Gate
on: [pull_request]
jobs:
  gate:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with:
          fetch-depth: 0
      - uses: maxgerhardson/sentrik-community@v1

That's it — one line. The action auto-detects PR context, runs the gate, uploads SARIF to GitHub Code Scanning, and attaches the findings report as an artifact.

With options:

      - uses: maxgerhardson/sentrik-community@v1
        with:
          packs: "owasp-top-10,soc2,supply-chain-security"
          fail-on: "critical,high"
          license-key: ${{ secrets.SENTRIK_LICENSE_KEY }}

Using outputs:

      - uses: maxgerhardson/sentrik-community@v1
        id: sentrik
      - run: echo "Found ${{ steps.sentrik.outputs.findings-count }} findings"
        if: always()

GitLab CI

sentrik:
  image: maxgerhardson/sentrik:latest
  script:
    - sentrik gate --git-range "origin/main...HEAD"
  rules:
    - if: $CI_PIPELINE_SOURCE == "merge_request_event"

Azure Pipelines

- script: |
    pip install sentrik
    sentrik gate --git-range "origin/main...HEAD"
  displayName: Sentrik Gate

AI Agent Integration

Sentrik works as an MCP server for AI coding agents:

# Start MCP server for Claude Code, Cursor, VS Code
sentrik mcp-server

The MCP server gives AI agents real-time access to compliance rules, scan results, and remediation guidance — so they write compliant code from the start.

Example Configurations

Starter (web app)

# .sentrik/config.yaml
standards_packs:
  - owasp-top-10
  - supply-chain-security
gate:
  fail_on:
    - critical
    - high

Healthcare / Medical Device

standards_packs:
  - owasp-top-10
  - hipaa
  - fda-iec-62304
  - supply-chain-security
gate:
  fail_on:
    - critical
    - high
    - medium

Fintech

standards_packs:
  - owasp-top-10
  - pci-dss
  - soc2
  - supply-chain-security
gate:
  fail_on:
    - critical
    - high

Government / Defense

standards_packs:
  - owasp-top-10
  - nist-800-53
  - cmmc
  - supply-chain-security
gate:
  fail_on:
    - critical
    - high
    - medium

Community

  • Discussions - Ask questions, share tips, show what you've built
  • Issues - Report bugs or request features
  • Documentation - Full CLI reference, configuration guide, API docs

Support

ChannelFor
GitHub DiscussionsQuestions, ideas, community help
support@sentrik.devDirect support (paid tiers)
sales@sentrik.devPricing and licensing

License

Proprietary. Free tier available forever with no credit card required.

Featured
CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
inference shell
inference shell
create and run specialised agents in minutes
build now →
MCP-ready Email SendingMCP-ready Email Sending
MCP-ready Email Sending
Plug Mailtrap into your AI workflow and let it handle the email.
Connect Mailtrap MCP →
Make your agent a DeFi expert
Make your agent a DeFi expert
Agent, run crypto. Access onchain data & trade routes via 1inch.
Install now →
Capacitor - Shared memory for your team’s coding agents.
Capacitor - Shared memory for your team’s coding agents.
Make coding agent sessions - Searchable, Shareable, Vendor-neutral & Scored.
Try For Free →
CodeScene MCP ServerCodeScene MCP Server
CodeScene MCP Server
Your agent targets a perfect 10 Code Health score. Deterministic. Every commit.
Try For Free →
Give your AI the whole web as clean markdownGive your AI the whole web as clean markdown
Give your AI the whole web as clean markdown
Integrate web data into your AI product. One API to scrape website & brand data.
Get API Key Now →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →

Configuration

GUARD_LICENSE_KEYsecret

Sentrik license key for Team/Organization features (optional — free tier works without it)

Categories
Security & Pentesting
Registryactive
Packagesentrik
TransportSTDIO
AuthRequired
UpdatedApr 9, 2026
View on GitHub

Related Security & Pentesting MCP Servers

View all →
mcp-fortress avatar
MCP Fortress

io.github.mcp-fortress/mcp-fortress

Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.
mcp-z avatar
Gmail

io.github.mcp-z/mcp-gmail

Gmail integration with OAuth authentication, message search, batch operations, and Sheets export
mironovisa avatar
DataMCP — Secure MCP Gateway for PostgreSQL

io.github.mironovisa/datamcp

Connect AI tools to your PostgreSQL with permissions, encryption, and audit trails.
nottiboy137 avatar
Open Registry Poc

io.github.nottiboy137/open-registry-poc

PoC: Open Registry supply chain — unvetted server listing (security research)
nottiboy137 avatar
Update Hijack Poc

io.github.nottiboy137/update-hijack-poc

PoC benign MCP server for update-hijack security research
oaslananka avatar
MCP Sentinel

io.github.oaslananka/sentinel

Zero-trust MCP security proxy with policy enforcement, PII scrubbing, approvals, and audit trails.