Scan Tool Call — Development skill for Claude Code
/scan-tool-call — Check if a tool call is safe.
How to install Scan Tool Call
Installs to ~/.claude/skills/maxwellcalkin-sentinel-ai-scan-tool-call/SKILL.md
mkdir -p ~/.claude/skills/maxwellcalkin-sentinel-ai-scan-tool-call && curl -fsSL https://raw.githubusercontent.com/MaxwellCalkin/sentinel-ai/HEAD/commands/scan-tool-call.md -o ~/.claude/skills/maxwellcalkin-sentinel-ai-scan-tool-call/SKILL.md Restart Claude Code, or start a new session, for it to be picked up.
What Scan Tool Call does
/scan-tool-call — Check if a tool call is safe
Scan a tool call for dangerous operations before execution.
Usage
/scan-tool-call
Behavior
Use the Sentinel AI `scan_tool_call` MCP tool to:
- Parse the tool name and JSON arguments
- Check for dangerous shell commands (rm -rf, credential access, etc.)
- Check for data exfiltration patterns (curl to external servers, etc.)
- Check for privilege escalation attempts
- Report risk level and whether the
Alternatives in Development
- Om Tidy — Self-maintenance pass — acts on every hygiene flag: archives completed work, groups loose clusters, splits ove 4.6k ★
- Claude-code-safety-net Rules Reference — Custom rules reference for defining safe/dangerous command patterns 1.2k ★
- Claude Keysmith — Managed Claude Code instruction deployment with safe CLI recovery and an unsigned macOS/Windows desktop beta 696 ★
Full documentation available on GitHub
View Source RepositoryRelated Skills
Florians Claude Code Kit
Cross-platform Node status line for Claude Code, plus /handover, /handover-check, dialogue, grill-me and an RC
Secondbrain Doctor
Integrity-check a techtrip-secondbrain vault and repair Obsidian MCP connectivity (registered-but-won't-connec
Dsh Acp Plugin
Agentic Control Plane for DeepSeek Harness — policy-check every tool call before it runs
SecondLook
BCC detector with Claude as a Grad-CAM trust layer - attention check for the doctor's final call.
Muse Code Acp Plugin
Agentic Control Plane for Meta Muse Code — policy-check every tool call before it runs
Install Permissions
Install a curated Claude Code allowlist for safe uip subcommands so the agent is not prompted on every command
Related Agents
Orch Scout
Cheap-tier mechanical worker for the orchestrator. Use for Class: scan work — grep, glob, list, count, fetch a
Read Only Explorer
Maps how code actually works — call paths, call sites, data flow, existing patterns, ownership boundaries, and
Rules Indexer
Scan all .md files in a project and extract rules, decisions, constraints, learnings, and conventions into a c