Adapted from the black-candle-technologies/Sentinel repository docs.
An internal static analysis platform that detects code health and risk issues across many languages. Sentinel flags complexity, maintainability problems, architecture violations, and security vulnerabilities, and automatically opens GitHub issues for critical security findings.
Sentinel/
├── apps/
│ ├── cli/ # Go CLI (analyze scan, analyze findings, etc.)
│ └── mcp/ # Go MCP server (local, read-only)
├── crates/
│ ├── analyzer-protocol/ # Canonical JSON schemas (ScanRequest, Finding, ScanResponse)
│ ├── analyzer-core/ # File discovery, rule orchestration, pipeline
│ ├── analyzer-bin/ # Rust binary entrypoint
│ ├── analyzer-fingerprint/ # Stable finding identity / deduplication
│ ├── language-go/ # Go parser and entity discovery
│ ├── rules-core/ # Complexity and maintainability rules
│ ├── rules-architecture/ # Import, layering, and circular dependency rules
│ └── rules-security/ # Secret detection, raw SQL, dangerous exec rules
├── docs/
│ ├── PRD.md # Product requirements
│ ├── SPEC.md # Technical specification
│ ├── ARCHITECTURE.md # System architecture
│ └── BUILDSHEET.md # V1 build sheet and milestone plan
└── test/
└── fixtures/ # Sample JSON inputs and outputs for testing
Prerequisites: Rust (stable via rustup), Go 1.22+, Git.
git clone git@github.com:black-candle-technologies/Sentinel.git
cd Sentinel
cargo build # build the Rust analyzer
cargo test # Rust tests
cd apps/cli && go test ./... # Go tests
analyzer-protocol crate defines all data shapes before logic is built. The Go CLI reads Rust output by parsing this schema.schema_version: "1.0". Incompatible versions are rejected loudly.| Milestone | Description | Status |
|---|---|---|
| 0 | Repo bootstrap | Done |
| 1 | Protocol and schemas | Done |
| 2 | Go parsing and entity discovery | Next |
| 3 | Core rules | Planned |
| 4 | Architecture rules | Planned |
| 5 | Security rules | Planned |
| 6 | Fingerprinting | Planned |
| 7 | Go CLI | Planned |
| 8 | SQLite history | Planned |
| 9 | MCP server | Planned |
| 10 | GitHub issue automation | Planned |
| 11 | CI hardening | Planned |
See the full plan in docs/BUILDSHEET.md.
Internal project. If you're onboarding, start with docs/PRD.md and docs/BUILDSHEET.md to understand scope and priorities before touching code.