WardenSAFE
A Model Context Protocol (MCP) server and CLI that provides tools for agent use when working on iOS and macOS projects.
Overview
A Model Context Protocol (MCP) server and CLI that provides tools for agent use when working on iOS and macOS projects.
a8e6e2fdb267OBSERVED · 2026-10-07Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: warden
description: Run Warden to analyze code changes before committing. Use when asked to "run warden", "check my changes", "review before commit", "warden config", "warden.toml", "create a warden skill", "add trigger", or any Warden-related local development task.
---
Run Warden to analyze code changes before committing.
## References
Read the relevant reference when the task requires deeper detail:
| Document | Read When |
|----------|-----------|
| `${CLAUDE_SKILL_ROOT}/references/cli-reference.md` | Full option details, per-command flags, examples |
| `${CLAUDE_SKILL_ROOT}/references/configuration.md` | Editing warden.toml, triggers, patterns, troubleshooting |
| `${CLAUDE_SKILL_ROOT}/references/config-schema.md` | Exact field names, types, and defaults |
| `${CLAUDE_SKILL_ROOT}/references/creating-skills.md` | Writing custom skills, remote skills, skill discovery |
## Running Warden
```bash
# Analyze uncommitted changes (uses warden.toml triggers)
warden
# Run a specific skill
warden --skill <skill-name>
# Analyze specific files
warden src/auth.ts src/database.ts
# Analyze changes from a git ref
warden main..HEAD
warden HEAD~3
# Auto-apply suggested fixes
warden --fix
# Fail on high-severity findings
warden --fail-on high
```
Set `WARDEN_ANTHROPIC_API_KEY` or log in via `claude login` before running.
## Pre-Commit Workflow
After making code changes and before committing:
1. Run `warden` to analyze uncommitted changes
2. Review the findings
3. Fix issues Warden reports (or use `warden --fix` to auto-apply)
4. Commit the changes
Run Warden once to validate work. Do not loop re-running Warden on the same changes.
## Reading Output
**Severity levels:**
- `high` - Must fix before merge
- `medium` - Worth reviewing
- `low` - Minor improvement
**Exit codes:** `0` = no findings at or above fail threshold. `1` = findings at or above fail threshold.
**Verbosity:** `-v` shows real-time findings. `-vv` shows debug info (tokens, latency). `-q` shows errors and summary only.
## Commands
| Command | Description |
|---------|-------------|
| `warden` | Run analysis (default) |
| `warden init` | Initialize warden.toml and GitHub workflow |
| `warden add [skill]` | Add skill trigger to warden.toml |
| `warden sync [remote]` | Update cached remote skills |
| `warden setup-app` | Create GitHub App via manifest flow |
For full options and flags, read `${CLAUDE_SKILL_ROOT}/references/cli-reference.md`.Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
a8e6e2fdb267full audit observations/trust-audit/skill/getsentry__warden.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | a8e6e2fdb267 | SAFE | B | 89 | first audit |
Questions
What does the Warden skill do?
A Model Context Protocol (MCP) server and CLI that provides tools for agent use when working on iOS and macOS projects.
Is Warden safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Warden access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Warden work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (a8e6e2fdb267), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.