{"_id":"@authensor/sentinel","_rev":"2-68930a598a3de1b96f77da6d0b64c8ce","name":"@authensor/sentinel","dist-tags":{"latest":"0.1.0"},"versions":{"0.0.1":{"name":"@authensor/sentinel","version":"0.0.1","keywords":["authensor","sentinel","monitoring","anomaly-detection","agent-safety","ai-safety","guardrails","ewma","cusum","behavioral-monitoring","agent-monitoring","real-time-monitoring","alerting","agentic-ai","observability","drift-detection"],"author":{"url":"https://github.com/jkearney","name":"John Kearney"},"license":"MIT","_id":"@authensor/sentinel@0.0.1","maintainers":[{"name":"jkearn","email":"john@authensor.com"}],"homepage":"https://authensor.com","bugs":{"url":"https://github.com/authensor/authensor/issues"},"dist":{"shasum":"be153096ca15ecb3a1f4c33b1bb68517b0044b5b","tarball":"https://registry.npmjs.org/@authensor/sentinel/-/sentinel-0.0.1.tgz","fileCount":25,"integrity":"sha512-WKp+Two27hKwD1y1aZlg+7IKHMAK5azR4JLuKVZOu4U16XG0jznXAm4HuMtUW1jiPmrushlheJitZkR3S1Kdkg==","signatures":[{"sig":"MEQCIF4nf0COaI4bzvPI1sMssDcYWtC68oZweozsosTeDsB9AiB+iFuKVFXVmoV52hV5fRQNrsY5gYAwXHe4P0u4eJE0Pg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":54767},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"gitHead":"814d74dd7e0ad287ca74bfdd1730ec5aa768165b","scripts":{"test":"vitest run","build":"tsc","clean":"rm -rf dist","typecheck":"tsc --noEmit","test:watch":"vitest"},"_npmUser":{"name":"jkearn","email":"john@authensor.com"},"repository":{"url":"git+https://github.com/authensor/authensor.git","type":"git","directory":"packages/sentinel"},"_npmVersion":"10.8.2","description":"Real-time monitoring and anomaly detection for AI agents — behavioral baselines, cost tracking, alert rules","directories":{},"_nodeVersion":"20.20.0","dependencies":{},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^1.1.0","typescript":"^5.3.0","@types/node":"^20.10.0"},"_npmOperationalInternal":{"tmp":"tmp/sentinel_0.0.1_1773535345016_0.5717069592539561","host":"s3://npm-registry-packages-npm-production"}},"0.1.0":{"name":"@authensor/sentinel","version":"0.1.0","description":"Real-time monitoring and anomaly detection for AI agents — behavioral baselines, cost tracking, alert rules","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","dependencies":{},"devDependencies":{"typescript":"^5.3.0","vitest":"^1.1.0","@types/node":"^20.10.0"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"keywords":["authensor","sentinel","monitoring","anomaly-detection","agent-safety","ai-safety","guardrails","policy-engine","ai-agent","agentic-ai","security","open-source","ewma","cusum","behavioral-monitoring","agent-monitoring","real-time-monitoring","alerting","observability","drift-detection"],"author":{"name":"John Kearney","url":"https://github.com/jkearney"},"bugs":{"url":"https://github.com/authensor/authensor/issues"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/authensor/authensor.git","directory":"packages/sentinel"},"homepage":"https://authensor.com","publishConfig":{"access":"public"},"scripts":{"build":"tsc","test":"vitest run","test:watch":"vitest","typecheck":"tsc --noEmit","clean":"rm -rf dist"},"_id":"@authensor/sentinel@0.1.0","_integrity":"sha512-D9Pe48tuaZnVtosZlZJejfrGye9Lb5Qnoaf+3imz5SPkVNIxmEtZewASivSlx1+SYWUZE5RgyqT5yCMt8xXfWg==","_resolved":"/private/var/folders/_h/xdjfwx_n3qxc_plpqltl399m0000gn/T/da61a25f988386a20d6df495a0bddef8/authensor-sentinel-0.1.0.tgz","_from":"file:authensor-sentinel-0.1.0.tgz","_nodeVersion":"20.20.0","_npmVersion":"10.8.2","dist":{"integrity":"sha512-D9Pe48tuaZnVtosZlZJejfrGye9Lb5Qnoaf+3imz5SPkVNIxmEtZewASivSlx1+SYWUZE5RgyqT5yCMt8xXfWg==","shasum":"d3eef81dc23aa8e1adc68100d08e21cbb533f4ce","tarball":"https://registry.npmjs.org/@authensor/sentinel/-/sentinel-0.1.0.tgz","fileCount":27,"unpackedSize":58832,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIFEEGvxX35PeyAVDeTFMXrxA2bk0lvjXsAXl8Jt8COU6AiAi2h+J0bOesz1YRFHHKwQ0ou0Pc+BZirkxCEjSiWeg6A=="}]},"_npmUser":{"name":"jkearn","email":"john@authensor.com"},"directories":{},"maintainers":[{"name":"jkearn","email":"john@authensor.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sentinel_0.1.0_1781250042606_0.4346391568594703"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-15T00:42:24.958Z","modified":"2026-06-12T07:40:42.853Z","0.0.1":"2026-03-15T00:42:25.163Z","0.1.0":"2026-06-12T07:40:42.737Z"},"bugs":{"url":"https://github.com/authensor/authensor/issues"},"author":{"name":"John Kearney","url":"https://github.com/jkearney"},"license":"MIT","homepage":"https://authensor.com","keywords":["authensor","sentinel","monitoring","anomaly-detection","agent-safety","ai-safety","guardrails","policy-engine","ai-agent","agentic-ai","security","open-source","ewma","cusum","behavioral-monitoring","agent-monitoring","real-time-monitoring","alerting","observability","drift-detection"],"repository":{"type":"git","url":"git+https://github.com/authensor/authensor.git","directory":"packages/sentinel"},"description":"Real-time monitoring and anomaly detection for AI agents — behavioral baselines, cost tracking, alert rules","maintainers":[{"name":"jkearn","email":"john@authensor.com"}],"readme":"# @authensor/sentinel\n\nReal-time behavioral monitoring for AI agents. EWMA and CUSUM anomaly detection, per-agent baselines, deny rate tracking, chain depth alerts.\n\nZero dependencies.\n\n## Install\n\n```bash\nnpm install @authensor/sentinel\n```\n\n## Quickstart\n\n```typescript\nimport { Sentinel } from '@authensor/sentinel';\n\nconst sentinel = new Sentinel({\n  onAlert: (alert) => console.log('ALERT:', alert.rule, alert.severity),\n  onAnomaly: (anomaly) => console.log('ANOMALY:', anomaly.metric, anomaly.zscore),\n});\n\n// Feed receipt events from your policy engine\nconst { anomalies, alerts } = sentinel.processEvent({\n  agentId: 'agent-1',\n  action: 'shell.execute',\n  outcome: 'deny',\n  timestamp: Date.now(),\n  latencyMs: 12,\n});\n```\n\n## What it detects\n\n- **Deny rate spikes** -- agent hitting guardrails more than baseline\n- **Latency anomalies** -- unusual processing times (possible prompt injection probing)\n- **Action frequency bursts** -- abnormal request rates\n- **Chain depth violations** -- recursive tool calls exceeding safe depth\n- **Budget anomalies** -- cost acceleration beyond expected patterns\n\n## Alert rules\n\n```typescript\nimport { Sentinel } from '@authensor/sentinel';\nimport type { AlertRule } from '@authensor/sentinel';\n\nconst rules: AlertRule[] = [\n  {\n    id: 'high-deny-rate',\n    metric: 'deny_rate',\n    condition: 'above',\n    threshold: 0.5,\n    window: 60_000,  // 1 minute\n    severity: 'high',\n  },\n  {\n    id: 'chain-depth',\n    metric: 'chain_depth',\n    condition: 'above',\n    threshold: 10,\n    severity: 'critical',\n  },\n];\n\nconst sentinel = new Sentinel({ alertRules: rules });\n```\n\n## Statistical detectors\n\n### EWMA (Exponentially Weighted Moving Average)\n\nDetects gradual drift in agent behavior:\n\n```typescript\nimport { EWMA } from '@authensor/sentinel';\n\nconst ewma = new EWMA({ alpha: 0.3 });\newma.update(10);\newma.update(12);\newma.update(100); // spike\nconsole.log(ewma.value); // weighted average tracks the shift\n```\n\n### CUSUM (Cumulative Sum)\n\nDetects sustained shifts in mean behavior:\n\n```typescript\nimport { CUSUM } from '@authensor/sentinel';\n\nconst cusum = new CUSUM({ threshold: 5, drift: 0.5 });\nconst alarm = cusum.update(15); // returns true when cumulative shift exceeds threshold\n```\n\n## Per-agent tracking\n\n```typescript\nimport { AgentTracker } from '@authensor/sentinel';\n\nconst tracker = new AgentTracker('agent-1');\nconst anomalies = tracker.processEvent(event);\n\n// Get agent stats\nconst stats = tracker.getStats();\n// { totalEvents, denyRate, avgLatency, lastSeen, ... }\n```\n\n## Chain tracking\n\nDetect recursive or circular tool call chains:\n\n```typescript\nimport { ChainTracker } from '@authensor/sentinel';\n\nconst chains = new ChainTracker();\nchains.push('agent-1', 'tool-a');\nchains.push('agent-1', 'tool-b');\nchains.push('agent-1', 'tool-a'); // circular reference detected\nconsole.log(chains.depth('agent-1')); // 3\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md"}