Watchdog

io.github.OxToFv0.1.0更新于 Oct 2, 2026

Who can change a Solana program or EVM contract, dependency advisories, scans. Paid per call (x402).

已验证STDIO仅桌面Security & MonitoringFinance

概览

AI 生成的概览

让助手对 Solana 程序、EVM 合约和依赖项执行付费安全检查,并按次从你提供的钱包以 USDC 自动付款。

功能
Watchdog 提供签署前的检查工具:solana_program_authority 报告谁可以替换 Solana 程序的代码,evm_contract_control 报告 Base 上的代理类型、当前实现、升级控制方和验证状态,dependency_advisories 检查锁文件或包列表中的安全公告。scan_repo 对公开 GitHub 仓库做完整扫描,get_scan_report 返回其状态,watch_create 通过签名 webhook 建立 30 天的变更提醒。免费工具可查看钱包设置、限额、花费和监控事件。
适用场景
适合在助手签署交易、批准合约或添加依赖之前核实链上控制权或依赖风险,也适合在程序、合约或锁文件发生变化时接收提醒。结果是检查,不是审计。
运行要求
通过 npx 以 stdio 在本地运行(需要 Node.js)。可选的 WATCHDOG_SOLANA_PRIVATE_KEY 和 WATCHDOG_EVM_PRIVATE_KEY 用于支付按次 USDC 费用;缺少某条链的密钥时,其工具只返回价格而不返回结果。WATCHDOG_BUDGET_USD(默认 5)和 WATCHDOG_MAX_PER_CALL_USD(默认 1)限制花费;WATCHDOG_SOLANA_RPC_URL 默认使用公共主网。需要网络访问。
安装前请注意
付费调用会从所提供的钱包自动支出真实 USDC,请使用只存放可承受花费金额的专用钱包。私钥通过 WATCHDOG_SOLANA_PRIVATE_KEY 和 WATCHDOG_EVM_PRIVATE_KEY 传入,能读取客户端配置的人即可看到。watch_create 会注册 webhook,scan_repo 会把公开仓库引用发送给第三方服务。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Watchdog,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

watchdog-mcp

An MCP server for Solana Watchdog and EVM Watchdog. It gives an agent the security checks it needs at the moment it decides: before signing for a program, before approving a contract, before adding a dependency. Each paid call costs cents in USDC and is paid automatically over x402, from a wallet you provide, within limits you set.

Results are checks, not audits.

Tools

ToolUse itPrice
solana_program_authoritybefore signing for a Solana program: who can replace its code (single key, Squads multisig with threshold and time lock, DAO, immutable), last deploy, verified build, security.txt$0.05 (Solana)
evm_contract_controlbefore approving or depositing on Base / Robinhood Chain: proxy kind, live implementation, who controls upgrades and ownership (key, Safe, timelock), Sourcify verification$0.05 (Base)
dependency_advisoriesbefore adding a dependency: advisories for a Cargo.lock, package-lock.json or yarn.lock on disk, or a package list$0.01
scan_repobefore a release: a full scan of a public GitHub repo (Rust/Anchor or Solidity)$0.50
get_scan_reportstatus and report of a scanfree
watch_createto be alerted for 30 days when a program, contract or lockfile changes, by signed webhook$0.90
watch_statusevents of a watch, or cancel itfree
watchdog_walletwhich wallets are set, caps, what was spentfree

An address that holds no program or contract is not charged. A dependency check is settled only once its answer exists.

Install

Claude Code:

sh
claude mcp add watchdog \  -e WATCHDOG_SOLANA_PRIVATE_KEY=<base58 key of a Solana wallet holding a little USDC> \  -e WATCHDOG_EVM_PRIVATE_KEY=<hex key of a Base wallet holding a little USDC> \  -- npx -y watchdog-mcp

Claude Desktop, Cursor and other clients (mcpServers JSON):

json
{  "mcpServers": {    "watchdog": {      "command": "npx",      "args": ["-y", "watchdog-mcp"],      "env": {        "WATCHDOG_SOLANA_PRIVATE_KEY": "…",        "WATCHDOG_EVM_PRIVATE_KEY": "…",        "WATCHDOG_BUDGET_USD": "5"      }    }  }}

From a clone of this repository, scripts/add-to-claude-code.sh does the Claude Code step for you: it reads the Solana key from the clipboard, checks it without printing it, and registers the server.

Both keys are optional. Without a key for a chain, its tools return the price and how to pay instead of an answer.

Use a dedicated wallet that holds only what you are willing to spend on checks. No SOL or ETH is needed: the x402 facilitator pays the network fee.

Configuration

VariableDefault
WATCHDOG_SOLANA_PRIVATE_KEYnoneSolana wallet, base58 (as Phantom exports it)
WATCHDOG_EVM_PRIVATE_KEYnoneBase wallet, hex
WATCHDOG_MAX_PER_CALL_USD1refuse any single payment above this
WATCHDOG_BUDGET_USD5refuse payments beyond this total, per server process
WATCHDOG_SOLANA_RPC_URLpublic mainnetRPC used to build Solana payments

What protects your wallet

Every payment is screened before anything is signed:

  • it must go to the Watchdog merchant wallet of that service, in USDC, on the expected network. A server that asked to be paid elsewhere would be refused;
  • it must fit under the per-call cap and the remaining session budget;
  • scan and watch access tokens are only ever sent back to the Watchdog that issued them.

Keys never appear in tool output or errors, including when a key is malformed or of the wrong chain.

License

MIT

来源:README.md,提交 fedcc43

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v0.1.0最新Oct 2, 2026