Rainkernel

Product 04 · Early access — free scanner first, Q1 2027

MCPSentry

The tools your agents trust, verified continuously — not once, at install time.

Explainer for an early-access product: pin-and-verify, drift alerts, the monthly attestation statement (sample figures), the scanner-first roadmap and the published prices — captioned, no sound required. A live demo ships with the free scanner in Q1 2027. · Open the video file

The problem

Scanning an MCP server once tells you what it was. Agents load what it is now.

A third of popular MCP servers and more than a third of agent skills carry a flaw, and the protocol still has no signing or provenance for tool descriptions — so a tool that was clean at approval can change its instructions tomorrow and every agent that trusts it follows. Free scanners are point-in-time and public-only. MCPSentry pins what you approved, watches it, and gives you the inventory to prove it.

29%

of the 8,000 most popular MCP servers carry at least one risk finding.

source

Backslash Security, September 2026

36.8%

of 3,984 agent skills analysed were flawed, some outright malicious.

source

Snyk, ToxicSkills research

74%

of organisations say their AI agents are over-permissioned; most cannot distinguish an agent's actions from a human's.

source

Cloud Security Alliance and Aembit, March 2026

The place nobody else holds

What we publish that the alternatives do not.

A neutral assessment of agent tools with public, named results. Scanners are free and vendor-backed, and every one is point-in-time; nobody neutral publishes named findings on the servers and skills agents actually load, and nobody re-verifies them continuously. The Lab's advisories log and MCPSentry's attestation statements are built for that place.

From the Lab's October 2026 review of the market — the six open places, and how we earn them.

What it does

Six things the MCPSentry does that the alternatives do not.

  1. 01

    Pin and hash at approval

    Every approved tool definition, server manifest and skill file is hashed and pinned against the deterministic tools list the MCP 2026-07-28 specification introduced. Approval becomes a fact you can show.

  2. 02

    Drift and rug-pull alerts

    Continuous re-verification of what the server actually serves against what you approved — the re-verification the protocol itself does not provide — with the diff in the alert.

  3. 03

    Private and internal servers

    Local stdio servers and internal registries that cloud identity products cannot see. If an agent can load it, MCPSentry can watch it.

  4. 04

    Skill and context-file scanning

    SKILL.md, CLAUDE.md, cursor rules, editor tasks — the files that carried the first self-replicating agent worm — scanned with the open-source engines and our own corpus.

  5. 05

    Permission and identity audit

    Over-access, shared service accounts, rotation, decommissioning, mapped to OWASP ASI03 and ASI04 and to the NIST autonomy inventory.

  6. 06

    Agent BOM as an output

    A CycloneDX-shaped bill of materials for every agent — models, prompts, tools, servers, skills, data — exported for procurement questionnaires, insurers and auditors.

What you receive

Deliverables

  • Free scanner (open source, GitHub) — point-in-time findings on any MCP server or skill set
  • Attestation service: pinned approvals, drift history, alerts
  • Permission and identity audit report
  • Agent BOM per agent, exportable
  • Monthly attestation statement for your risk function

Who buys it

Built for

  • Platform and security leads running 5–100 MCP servers
  • Integrators who ship agents into clients' estates and need to prove what they shipped
  • Procurement and risk teams asking vendors for an agent inventory

Built on open engines: snyk-agent-scan, Cisco mcp-scanner, Backslash MCP hub data — under Rainkernel's corpus, rubric, report generator and BOM emitter.

Pricing

Published prices. A quote never exceeds the price on this page for the scope on this page.

Early access — free scanner first, Q1 2027

Scanner

free

Open source. Install, scan, keep the report.

Ask about this tier

Attestation — per estate

from $1,500 / month

Continuous pin-and-verify, drift alerts, monthly statement; by number of servers.

Ask about this tier

Permission audit

$5,000–10,000

One-off, inside or outside the Gate; Agent BOM included.

Ask about this tier

Prices in USD and exclusive of applicable taxes; Indian clients are invoiced in INR with GST. Window: Build January–February 2027 · free scanner on GitHub first · attestation from March 2027. Our public commitment for this product: The scanner ships free and open before we charge for anything. The attestation price is published here and stays published.

FAQ

Questions we are asked

Does the Agent BOM help with the EU Cyber Resilience Act?

If you sell a product with digital elements in the EU, the Cyber Resilience Act's reporting obligations apply from September 2026 and its main obligations from December 2027, and a bill of materials for what the product contains is part of the expected evidence. A product that embeds an agent has components no software SBOM lists — models, prompts, tools, MCP servers, skills. The Agent BOM is that list, in a CycloneDX-shaped form your existing SBOM tooling can hold.

Cisco and Snyk already have free MCP scanners. Why pay?

Use them — we do, inside MCPSentry. They tell you what a public server looked like when you ran them. MCPSentry tells you when what you approved changes, covers your private servers, and gives your risk function a statement and a BOM. The scanner tier is free precisely because scanning is commoditised.

Is MCPSentry a separate company?

No. MCPSentry is a Rainkernel product; mcpsentry.com and mcpsentry.ai are Rainkernel domains. Contracts and invoices are with Rainkernel Technologies Private Limited.

Works with

Talk to us about the MCPSentry.

A 30-minute call with the engineers who build it, no deck, no charge. If it fits, a fixed-price proposal within 48 hours.