Back to Browse

Watchdog MCP Server

by OxToF
Developer ToolsLow Risk10.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

Who can change a Solana program or EVM contract, dependency advisories, scans. Paid per call (x402).

About

Who can change a Solana program or EVM contract, dependency advisories, scans. Paid per call (x402).

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (3 strong, 3 medium validity signals). No known CVEs in dependencies. Package registry verified. Imported from the Official MCP Registry.

7 files analyzed · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

file_system

Check that this permission is expected for this type of plugin.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Base58 key of a dedicated Solana wallet holding a little USDC, to pay Solana Watchdog calls. Optional.Required

Environment variable: WATCHDOG_SOLANA_PRIVATE_KEY

Hex key of a dedicated Base wallet holding a little USDC, to pay EVM Watchdog calls. Optional.Required

Environment variable: WATCHDOG_EVM_PRIVATE_KEY

Maximum total spend per server process, in USD. Default 5.Optional

Environment variable: WATCHDOG_BUDGET_USD

Maximum single payment, in USD. Default 1.Optional

Environment variable: WATCHDOG_MAX_PER_CALL_USD

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-oxtof-watchdog-mcp": {
      "env": {
        "WATCHDOG_BUDGET_USD": "your-watchdog-budget-usd-here",
        "WATCHDOG_EVM_PRIVATE_KEY": "your-watchdog-evm-private-key-here",
        "WATCHDOG_MAX_PER_CALL_USD": "your-watchdog-max-per-call-usd-here",
        "WATCHDOG_SOLANA_PRIVATE_KEY": "your-watchdog-solana-private-key-here"
      },
      "args": [
        "-y",
        "watchdog-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

watchdog-mcp

An MCP server for Solana Watchdog and EVM Watchdog. It gives an agent the security checks it needs at the moment it decides: before signing for a program, before approving a contract, before adding a dependency. Each paid call costs cents in USDC and is paid automatically over x402, from a wallet you provide, within limits you set.

Results are checks, not audits.

Tools

ToolUse itPrice
solana_program_authoritybefore signing for a Solana program: who can replace its code (single key, Squads multisig with threshold and time lock, DAO, immutable), last deploy, verified build, security.txt$0.05 (Solana)
evm_contract_controlbefore approving or depositing on Base / Robinhood Chain: proxy kind, live implementation, who controls upgrades and ownership (key, Safe, timelock), Sourcify verification$0.05 (Base)
dependency_advisoriesbefore adding a dependency: advisories for a Cargo.lock, package-lock.json or yarn.lock on disk, or a package list$0.01
scan_repobefore a release: a full scan of a public GitHub repo (Rust/Anchor or Solidity)$0.50
get_scan_reportstatus and report of a scanfree
watch_createto be alerted for 30 days when a program, contract or lockfile changes, by signed webhook$0.90
watch_statusevents of a watch, or cancel itfree
watchdog_walletwhich wallets are set, caps, what was spentfree

An address that holds no program or contract is not charged. A dependency check is settled only once its answer exists.

Install

Claude Code:

claude mcp add watchdog \
  -e WATCHDOG_SOLANA_PRIVATE_KEY=<base58 key of a Solana wallet holding a little USDC> \
  -e WATCHDOG_EVM_PRIVATE_KEY=<hex key of a Base wallet holding a little USDC> \
  -- npx -y watchdog-mcp

Claude Desktop, Cursor and other clients (mcpServers JSON):

{
  "mcpServers": {
    "watchdog": {
      "command": "npx",
      "args": ["-y", "watchdog-mcp"],
      "env": {
        "WATCHDOG_SOLANA_PRIVATE_KEY": "…",
        "WATCHDOG_EVM_PRIVATE_KEY": "…",
        "WATCHDOG_BUDGET_USD": "5"
      }
    }
  }
}

From a clone of this repository, scripts/add-to-claude-code.sh does the Claude Code step for you: it reads the Solana key from the clipboard, checks it without printing it, and registers the server.

Both keys are optional. Without a key for a chain, its tools return the price and how to pay instead of an answer.

Use a dedicated wallet that holds only what you are willing to spend on checks. No SOL or ETH is needed: the x402 facilitator pays the network fee.

Configuration

VariableDefault
WATCHDOG_SOLANA_PRIVATE_KEYnoneSolana wallet, base58 (as Phantom exports it)
WATCHDOG_EVM_PRIVATE_KEYnoneBase wallet, hex
WATCHDOG_MAX_PER_CALL_USD1refuse any single payment above this
WATCHDOG_BUDGET_USD5refuse payments beyond this total, per server process
WATCHDOG_SOLANA_RPC_URLpublic mainnetRPC used to build Solana payments

What protects your wallet

Every payment is screened before anything is signed:

  • it must go to the Watchdog merchant wallet of that service, in USDC, on the expected network. A server that asked to be paid elsewhere would be refused;
  • it must fit under the per-call cap and the remaining session budget;
  • scan and watch access tokens are only ever sent back to the Watchdog that issued them.

Keys never appear in tool output or errors, including when a key is malformed or of the wrong chain.

License

MIT

Reviews

No reviews yet

Be the first to review this server!