Watchdog

io.github.OxToFv0.1.0Updated Oct 2, 2026

Who can change a Solana program or EVM contract, dependency advisories, scans. Paid per call (x402).

VerifiedSTDIODesktop onlySecurity & MonitoringFinance

Overview

AI-generated overview

Lets an assistant run paid security checks on Solana programs, EVM contracts, and dependencies, paying per call in USDC from a wallet you supply.

What it does
Watchdog exposes tools for pre-signing checks: solana_program_authority reports who can replace a Solana program's code, evm_contract_control reports proxy kind, live implementation, upgrade control and verification on Base, and dependency_advisories checks lockfiles or package lists for advisories. scan_repo runs a full scan of a public GitHub repo, get_scan_report returns its status, and watch_create sets up 30-day change alerts by signed webhook. Free tools show wallet settings, caps and spending, and watch events.
When to use it
Use it when an assistant should verify on-chain control or dependency risk before signing, approving a contract, or adding a dependency, and when you want alerts if a program, contract, or lockfile changes. Results are checks, not audits.
Requirements
Runs locally over stdio via npx (Node.js). Optional WATCHDOG_SOLANA_PRIVATE_KEY and WATCHDOG_EVM_PRIVATE_KEY fund per-call USDC payments; without a chain's key its tools return the price instead of an answer. WATCHDOG_BUDGET_USD (default 5) and WATCHDOG_MAX_PER_CALL_USD (default 1) cap spending; WATCHDOG_SOLANA_RPC_URL defaults to public mainnet. Network access required.
Before you install
Paid calls spend real USDC automatically from the supplied wallets, so use dedicated wallets holding only what you are willing to spend. Private keys are passed as WATCHDOG_SOLANA_PRIVATE_KEY and WATCHDOG_EVM_PRIVATE_KEY; anyone with access to the client config can read them. watch_create registers a webhook and scan_repo sends a public repo reference to a third-party service.

Installation

In SourceWeft

  1. Open Watchdog in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

watchdog-mcp

An MCP server for Solana Watchdog and EVM Watchdog. It gives an agent the security checks it needs at the moment it decides: before signing for a program, before approving a contract, before adding a dependency. Each paid call costs cents in USDC and is paid automatically over x402, from a wallet you provide, within limits you set.

Results are checks, not audits.

Tools

ToolUse itPrice
solana_program_authoritybefore signing for a Solana program: who can replace its code (single key, Squads multisig with threshold and time lock, DAO, immutable), last deploy, verified build, security.txt$0.05 (Solana)
evm_contract_controlbefore approving or depositing on Base / Robinhood Chain: proxy kind, live implementation, who controls upgrades and ownership (key, Safe, timelock), Sourcify verification$0.05 (Base)
dependency_advisoriesbefore adding a dependency: advisories for a Cargo.lock, package-lock.json or yarn.lock on disk, or a package list$0.01
scan_repobefore a release: a full scan of a public GitHub repo (Rust/Anchor or Solidity)$0.50
get_scan_reportstatus and report of a scanfree
watch_createto be alerted for 30 days when a program, contract or lockfile changes, by signed webhook$0.90
watch_statusevents of a watch, or cancel itfree
watchdog_walletwhich wallets are set, caps, what was spentfree

An address that holds no program or contract is not charged. A dependency check is settled only once its answer exists.

Install

Claude Code:

sh
claude mcp add watchdog \  -e WATCHDOG_SOLANA_PRIVATE_KEY=<base58 key of a Solana wallet holding a little USDC> \  -e WATCHDOG_EVM_PRIVATE_KEY=<hex key of a Base wallet holding a little USDC> \  -- npx -y watchdog-mcp

Claude Desktop, Cursor and other clients (mcpServers JSON):

json
{  "mcpServers": {    "watchdog": {      "command": "npx",      "args": ["-y", "watchdog-mcp"],      "env": {        "WATCHDOG_SOLANA_PRIVATE_KEY": "…",        "WATCHDOG_EVM_PRIVATE_KEY": "…",        "WATCHDOG_BUDGET_USD": "5"      }    }  }}

From a clone of this repository, scripts/add-to-claude-code.sh does the Claude Code step for you: it reads the Solana key from the clipboard, checks it without printing it, and registers the server.

Both keys are optional. Without a key for a chain, its tools return the price and how to pay instead of an answer.

Use a dedicated wallet that holds only what you are willing to spend on checks. No SOL or ETH is needed: the x402 facilitator pays the network fee.

Configuration

VariableDefault
WATCHDOG_SOLANA_PRIVATE_KEYnoneSolana wallet, base58 (as Phantom exports it)
WATCHDOG_EVM_PRIVATE_KEYnoneBase wallet, hex
WATCHDOG_MAX_PER_CALL_USD1refuse any single payment above this
WATCHDOG_BUDGET_USD5refuse payments beyond this total, per server process
WATCHDOG_SOLANA_RPC_URLpublic mainnetRPC used to build Solana payments

What protects your wallet

Every payment is screened before anything is signed:

  • it must go to the Watchdog merchant wallet of that service, in USDC, on the expected network. A server that asked to be paid elsewhere would be refused;
  • it must fit under the per-call cap and the remaining session budget;
  • scan and watch access tokens are only ever sent back to the Watchdog that issued them.

Keys never appear in tool output or errors, including when a key is malformed or of the wrong chain.

License

MIT

Source: README.md at commit fedcc43

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.1.0LatestOct 2, 2026