SentinelX agent: connects a Linux server to sentinelx-cloud-hub via WebSocket
SentinelX has 31 tools with basic schemas and descriptions, but significant quality gaps prevent production recommendation. Most tools lack parameter descriptions (e.g., 'exec' has 4 params but only 'cmd' is described; 'service' action param has no enum constraint). Descriptions are present but often generic (e.g., 'Manage system services' for 'service' tool). No output schemas documented. Error handling is absent, no recovery guidance, no actionable error messages. Security concerns: tools like 'exec', 'script_run', 'edit', 'delete', 'chown' are high-risk but lack permission gates, input validation guidance, or audit trail documentation. No tool annotations (readOnlyHint/destructiveHint) despite clear risk levels. Composition is reasonable (31 focused tools), but parameter naming inconsistencies (e.g., 'path' vs 'src'/'dst') and missing enums force LLM guessing.
Return the policy as introspection data + ops supported. This is the dynamic equivalent of legacy SentinelX's GET /capabilities. Output is shaped to be friendly for an LLM tool: lists, dicts, no fluff.
Change file permissions on the host
Change file ownership on the host
Copy a file on the host
Delete a file on the host
Edit a file on the host
Complete a file upload for editing
Missing parameter descriptions and enums. 'service' tool has 'action' param with no enum constraint (should be: start|stop|restart|status). 'exec' has 'timeout', 'cwd', 'env' params with no descriptions. 'git' action param lacks enum (diff|apply_patch). LLMs cannot infer valid values without explicit constraints.
No output schemas documented. Tools return data but LLMs have no visibility into response structure. E.g., 'read' returns file content but no schema; 'list' returns directory contents but structure unknown; 'capabilities' returns policy but format undocumented. Agents cannot plan downstream calls without knowing what fields to expect.
No error handling guidance. Tools like 'delete', 'exec', 'chown' can fail in many ways (permission denied, file not found, invalid syntax) but provide no recovery hints. LLMs receive raw errors with no actionable next steps. E.g., 'delete' should return 'File not found. Use list() to verify path.' not a bare 404.
Inferred effective spec: 2026-07-28+.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | D | 56 | 2026-07-28+ | v2 |
Upload a complete file for editing
Initialize a file upload for editing
Execute a command on the host
Export a chunk of a file (cross-host file transfer source side)
Complete a file export (cross-host file transfer source side)
Initialize a file export (cross-host file transfer source side)
Perform structured Git operations (diff and apply_patch)
Return help text for a specific operation or general help
List directory contents on the host
Call a local API endpoint on the host
Move or rename a file on the host
Returns pong and agent version
Create a snapshot of a project directory
Read a file from the host
Read recent entries from the local audit log. Read-only. Returns entries from /var/lib/sentinelx/audit.jsonl (op + payload + status), newest first. This is the only path by which the on-host payload log leaves the host, and only in response to an explicit request routed through the hub to this host's owner.
Restart a system service
Run a script on the host
Search for files on the host
Manage system services
Return current agent state
Upload a chunk of a file
Complete a chunked file upload
Upload a file to the host
Initialize a chunked file upload
Missing tool annotations despite clear risk levels. 'delete' is DESTRUCTIVE, 'exec'/'script_run'/'chown' are WRITE, 'read'/'list' are READ_ONLY. No readOnlyHint/destructiveHint/idempotentHint annotations present. Agents cannot distinguish safe from dangerous operations without explicit hints.
Security: no permission gates or input validation guidance. High-risk tools ('exec', 'delete', 'chown', 'chmod') lack documented permission requirements or input sanitization hints. No audit trail documentation. Agents can invoke destructive operations without authorization checks visible in the schema.