
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
sentinel-dv
Advanced tools
Sentinel DV v2.3.1 is a read-only Model Context Protocol server for design verification evidence. It indexes exported SystemVerilog, UVM, cocotb, assertion, coverage, regression, and waveform artifacts into DuckDB and exposes 28 bounded, schema-driven tools to AI agents.
Documentation | Quick start | Video walkthrough | All tools | Agent skills
*.wave.json and bounded VCD summaries. Native FSDB/WLF streaming is intentionally out of scope.Sentinel DV does not execute simulations, modify RTL or testbench files, or stream unrestricted raw artifacts. runs.submit and tests.replay return dry-run commands for engineer review.
Python 3.10 or newer is required. This example indexes the checked-in demo corpus:
For a persistent environment, install sentinel-dv>=2.3.1. The commands below use uvx to run the same release without a persistent install.
git clone https://github.com/kiranreddi/sentinel-dv.git
cd sentinel-dv
cp demo/config.example.yaml demo/config.yaml
uvx --from sentinel-dv@2.3.1 \
sentinel-dv-index --config "$PWD/demo/config.yaml" --index-all
Connect one agent:
codex mcp add sentinel-dv \
--env SENTINEL_DV_CONFIG="$PWD/demo/config.yaml" \
-- uvx --from sentinel-dv@2.3.1 sentinel-dv-server
claude mcp add \
--env SENTINEL_DV_CONFIG="$PWD/demo/config.yaml" \
--transport stdio --scope local sentinel-dv \
-- uvx --from sentinel-dv@2.3.1 sentinel-dv-server
copilot mcp add sentinel-dv \
--env SENTINEL_DV_CONFIG="$PWD/demo/config.yaml" \
-- uvx --from sentinel-dv@2.3.1 sentinel-dv-server
Use an absolute SENTINEL_DV_CONFIG path. Verify the connection in the client's MCP status view, then call runs.list.
See Agent setup for configuration-file examples, project scope, skill discovery, and troubleshooting.
Copy config.example.yaml and define allowed artifact roots:
artifact_roots:
- /absolute/path/to/regression/artifacts
index:
type: duckdb
path: ./sentinel_dv.db
adapters:
uvm: true
cocotb: true
assertions: true
coverage: true
waveform_summary: true
security:
max_response_bytes: 2097152
max_page_size: 200
max_evidence_refs: 10
redaction:
enabled: true
redact_emails: true
redact_paths: true
Build the index before starting the server:
sentinel-dv-index --config /absolute/path/to/config.yaml --index-all
sentinel-dv-server --config /absolute/path/to/config.yaml
Relative paths inside the YAML are resolved from the config file's directory. Production startup never silently falls back to demo data.
The 28 tools are grouped by engineering purpose:
| Area | Tools |
|---|---|
| Runs | runs.list, runs.get, runs.summary, runs.diff, runs.cross_sim, runs.submit |
| Tests | tests.list, tests.get, tests.history, tests.topology, tests.cluster, tests.replay |
| Failures and assertions | failures.list, assertions.list, assertions.get, assertions.failures, assertions.sva_status, assertions.vacuity |
| Coverage | coverage.list, coverage.summary, coverage.gaps, coverage.trend, coverage.advisor |
| Regression and simulation | regressions.summary, regression.health, sim.status |
| Waveforms | wave.signals, wave.summary |
Every registered tool carries read-only MCP annotations and a versioned output schema. The MCP tools reference documents exact inputs and outputs.
The canonical skills live under skills/:
Deterministic mirrors support project discovery:
| Host | Path |
|---|---|
| Codex | .agents/skills/ |
| Claude Code | .claude/skills/ |
| GitHub Copilot | .github/skills/ |
The repository also contains Codex and Claude plugin manifests. .mcp.json defines the bundled stdio server command; provide SENTINEL_DV_CONFIG or a config.yaml in the server working directory.
After editing a canonical skill:
.venv/bin/python scripts/sync_agent_skills.py
.venv/bin/python scripts/sync_agent_skills.py --check
*.wave.json and VCDAdapter output is normalized into versioned schemas so clients do not need vendor-specific parsing logic.
Read Security and Production deployment before using production artifacts.
Create a development environment:
python3 -m venv .venv
.venv/bin/pip install -e ".[dev,docs]"
Run endpoint and workflow checks:
.venv/bin/python scripts/verify_all_mcp_tools.py
.venv/bin/python scripts/verify_skill_workflows.py
Run the full quality suite:
.venv/bin/pytest
.venv/bin/ruff check .
.venv/bin/black --check .
.venv/bin/mypy sentinel_dv
.venv/bin/mkdocs build --strict
The all-tools verifier invokes every registered MCP endpoint. The skill verifier indexes 52 checked-in demo artifacts and executes the published regression triage, failure debugging, and coverage closure sequences.
sentinel_dv/
adapters/ artifact parsers
indexing/ DuckDB indexing and queries
normalization/ signatures, taxonomy, redaction, coverage guidance
schemas/ versioned response contracts
tools/core.py tool implementations
server.py FastMCP registration and stdio entry point
skills/ canonical agent skills
demo/ license-free exported verification fixtures
docs/ MkDocs documentation
scripts/ verification, gallery, release, and skill-sync tooling
tests/ unit and integration coverage
See CONTRIBUTING.md. Sentinel DV is licensed under Apache-2.0.
FAQs
Security-first MCP server for verification intelligence (SystemVerilog/UVM/cocotb)
We found that sentinel-dv demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.