Install. Scan. Initialize.
Python 3.10+ and pipx. Open your project in Terminal or PowerShell and run:
pipx install https://agentsentry.fun/downloads/sentry_local_guard-0.1.2-py3-none-any.whl
sentry scan . --local-only
sentry init .Install once, inspect your project, then preview local protection. Init is a dry run: review the proposed changes before applying them. No account, wallet or model API key is needed.
The package is sentry-local-guard; the command is sentry. This release installs directly from our site. It is not published on PyPI.
Need pipx first? Follow the setup for your system below, reopen your terminal, then use the quickstart above.
Download for offline installation +
Download the ZIP, extract it and install the included wheel with pipx. The bundle includes the license and notices.
pipx install ./sentry_local_guard-0.1.2-py3-none-any.whlOpen Terminal. Get started.
Set up pipx.
If you use Homebrew, run the commands below. Otherwise, follow the official pipx setup.
brew install pipx
pipx ensurepathClose and reopen Terminal, then run the quickstart above.
Check your installation.
sentry doctor
sentry --helpLook for "local_engine": "available". A missing cloud key is normal for local use.
PowerShell. Three commands.
Set up Python and pipx.
Install Python 3.10 or newer, then open PowerShell and run:
py -m pip install --user pipx
py -m pipx ensurepathClose and reopen PowerShell. Run the same quickstart above — no administrator window or manual archive extraction is needed.
Check your installation.
sentry doctor
sentry --helpLocal scans run directly in PowerShell. To reinstall this release, add --force to the install command.
Alternative Windows installer without pipx +
Already use the standalone Windows installer? You can keep using that method instead. It checks the release archive and installs under %LOCALAPPDATA%\AgentSentry. Use one installation method to avoid duplicate commands.
$sentryInstaller = Join-Path $env:TEMP "sentry-install.ps1"
Invoke-WebRequest -UseBasicParsing "https://agentsentry.fun/install.ps1" -OutFile $sentryInstaller
if ((Get-FileHash -LiteralPath $sentryInstaller -Algorithm SHA256).Hash -ne "2BB3D9929CD471075933504A25671E70ADCCE4E2995F67E48F4E8410BA6A3131") { throw "Installer checksum mismatch" }
Unblock-File -LiteralPath $sentryInstaller
powershell.exe -NoProfile -ExecutionPolicy RemoteSigned -File $sentryInstallerRemoteSigned applies only to the installer process. Managed device policies still apply. Upcoming soon
Point it at a project.
Open a terminal in the project you want to inspect, then run this read-only scan:
sentry scan . --local-onlyThe result lists findings to review. A clean scan means no known pattern was found; it is not a guarantee that every attack will be detected. The --local-only option limits the scan to the project and skips your global agent settings.
Want machine-readable results?
sentry scan . --local-only --jsonPreview the local setup and review the permission changes:
sentry init .On macOS or Linux, sentry init . --apply applies hardening and records a baseline. On Windows, use agent sandbox permissions or WSL: a read-only file attribute is not a security boundary against the same user.
Installation alone does not intercept your agent’s actions. Connect a supported hook or enforcement wrapper when you need checks before execution.
Make the check part of the flow.
For Claude Code on macOS or Windows PowerShell, preview the settings change before applying it:
sentry integration preview --agent claude --path "$HOME/.claude/settings.json"Review the generated settings. When ready, apply them and restart your agent session:
sentry integration apply --agent claude --path "$HOME/.claude/settings.json"Sentry backs up the previous settings and adds configuration-write, outgoing-content and incoming-content hooks. Existing unrelated settings are retained. These hooks inspect agent events locally.
Windows: generated write and outbound hooks use native PowerShell and stop the action if the scanner cannot start. No WSL is needed for this wrapper. Check a harmless write in your actual agent host before relying on enforcement. Incoming-content hooks annotate tool results after execution.
Remove the managed hooks +
sentry integration remove --agent claude --path "$HOME/.claude/settings.json"This removes Sentry’s managed entries. It does not uninstall the CLI.
Node.js SDK and MCP +
Node.js 24 or newer. Install the local SDK in your agent project:
npm install https://agentsentry.fun/downloads/sentry-local-guard-0.2.1.tgzRun a local check immediately before passing external text to your application:
import { consumeChecked } from '@sentry-local/guard/check';
await consumeChecked(externalText, async checkedText => {
// Pass checkedText to your existing consumer here.
});For MCP, point your agent at the installed program using an absolute path. Replace the example path with your project path; Windows paths need JSON-escaped backslashes or forward slashes.
{
"mcpServers": {
"sentry": {
"command": "node",
"args": [
"/absolute/project/node_modules/@sentry-local/guard/dist/sentry-mcp.js"
]
}
}
}Five tools: scan_text, check_before_use, check_token, verify_payment and verify_delivery. Local text checks need no API key. Optional payment peers:
npm install viem @solana/web3.js @solana/spl-tokenMCP tools provide checks when called; an agent can omit them. Use a blocking hook or SDK wrapper at the action boundary for enforcement. Token registry reads and account policies require your own Sentry server, a scoped SENTRY_API_KEY and a pinned SENTRY_PUBLIC_KEY. Without a configured metadata adapter, on-chain tokens return unchecked.
Upcoming soonLocal first. Cloud when needed.
Local scans and rule-based checks work without NanoGPT. They detect known patterns and enforce configured rules; they do not provide an AI model’s analysis of unfamiliar language.
Optional NanoGPT analysis needs a NanoGPT API key on the trusted Sentry server and a verified model. End users connect with a separate, scoped Sentry service key. Never put a NanoGPT key in browser code or paste it into a local scan command.
The hosted service is not available yet. Cloud account and analysis commands require an operator-provided service URL, Sentry key and service credit. The Playground’s local-chain balances are simulated credits.
A few useful checks.
“sentry” is not recognized +
Run pipx ensurepath (or py -m pipx ensurepath on Windows) and reopen your terminal. For the standalone Windows installer, you can run & "$env:LOCALAPPDATA\AgentSentry\bin\sentry.cmd" doctor directly.
Python is missing +
Use the official setup links above. The Windows installer looks for py, python or python3. Python 3.10 or newer is required.
Already installed or extracted +
For pipx, add --force to the quickstart install command. For the standalone Windows installer, rerun the same installer. If switching methods, uninstall the old method first to avoid two Sentry commands on PATH.
Verify the ZIP +
Compare the SHA-256 value with the linked checksum file.
shasum -a 256 "$HOME/Downloads/sentry-local-0.1.2.zip"Get-FileHash "$HOME\Downloads\sentry-local-0.1.2.zip" -Algorithm SHA256Uninstall Sentry +
Remove any managed hooks first using the command above, then uninstall the CLI.
pipx uninstall sentry-local-guardStandalone Windows installer: close Sentry, delete your %LOCALAPPDATA%\AgentSentry installation folder in File Explorer, then remove its bin entry from your user PATH. If you used the earlier pipx method, run py -m pipx uninstall sentry-local-guard.