
Watchdog
io.github.OxToFv0.1.0Updated Oct 2, 2026
Who can change a Solana program or EVM contract, dependency advisories, scans. Paid per call (x402).
Overview
Lets an assistant run paid security checks on Solana programs, EVM contracts, and dependencies, paying per call in USDC from a wallet you supply.
- What it does
- Watchdog exposes tools for pre-signing checks: solana_program_authority reports who can replace a Solana program's code, evm_contract_control reports proxy kind, live implementation, upgrade control and verification on Base, and dependency_advisories checks lockfiles or package lists for advisories. scan_repo runs a full scan of a public GitHub repo, get_scan_report returns its status, and watch_create sets up 30-day change alerts by signed webhook. Free tools show wallet settings, caps and spending, and watch events.
- When to use it
- Use it when an assistant should verify on-chain control or dependency risk before signing, approving a contract, or adding a dependency, and when you want alerts if a program, contract, or lockfile changes. Results are checks, not audits.
- Requirements
- Runs locally over stdio via npx (Node.js). Optional WATCHDOG_SOLANA_PRIVATE_KEY and WATCHDOG_EVM_PRIVATE_KEY fund per-call USDC payments; without a chain's key its tools return the price instead of an answer. WATCHDOG_BUDGET_USD (default 5) and WATCHDOG_MAX_PER_CALL_USD (default 1) cap spending; WATCHDOG_SOLANA_RPC_URL defaults to public mainnet. Network access required.
Installation
In SourceWeft
- Open Watchdog in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
watchdog-mcp
An MCP server for Solana Watchdog and EVM Watchdog. It gives an agent the security checks it needs at the moment it decides: before signing for a program, before approving a contract, before adding a dependency. Each paid call costs cents in USDC and is paid automatically over x402, from a wallet you provide, within limits you set.
Results are checks, not audits.
Tools
An address that holds no program or contract is not charged. A dependency check is settled only once its answer exists.
Install
Claude Code:
Claude Desktop, Cursor and other clients (mcpServers JSON):
From a clone of this repository, scripts/add-to-claude-code.sh does the Claude Code step for you: it reads the Solana key from the clipboard, checks it without printing it, and registers the server.
Both keys are optional. Without a key for a chain, its tools return the price and how to pay instead of an answer.
Use a dedicated wallet that holds only what you are willing to spend on checks. No SOL or ETH is needed: the x402 facilitator pays the network fee.
Configuration
What protects your wallet
Every payment is screened before anything is signed:
- it must go to the Watchdog merchant wallet of that service, in USDC, on the expected network. A server that asked to be paid elsewhere would be refused;
- it must fit under the per-call cap and the remaining session budget;
- scan and watch access tokens are only ever sent back to the Watchdog that issued them.
Keys never appear in tool output or errors, including when a key is malformed or of the wrong chain.
License
MIT
Source: README.md at commit fedcc43
Tools
0Version history
1- v0.1.0LatestOct 2, 2026
