Watchdog

io.github.OxToFv0.1.0更新於 Oct 2, 2026

Who can change a Solana program or EVM contract, dependency advisories, scans. Paid per call (x402).

已驗證STDIO僅桌面Security & MonitoringFinance

概覽

AI 產生的概覽

讓助理對 Solana 程式、EVM 合約與相依套件執行付費安全檢查,並依每次呼叫從你提供的錢包以 USDC 自動付款。

功能
Watchdog 提供簽署前的檢查工具:solana_program_authority 回報誰能替換 Solana 程式的程式碼,evm_contract_control 回報 Base 上的代理類型、目前實作、升級控制方與驗證狀態,dependency_advisories 檢查鎖定檔或套件清單中的安全公告。scan_repo 對公開 GitHub 儲存庫執行完整掃描,get_scan_report 回傳其狀態,watch_create 透過簽章 webhook 建立 30 天的變更通知。免費工具可查看錢包設定、上限、花費與監控事件。
適用情境
適合在助理簽署交易、核准合約或加入相依套件之前核實鏈上控制權或相依風險,也適合在程式、合約或鎖定檔變更時收到通知。結果是檢查,不是稽核。
執行需求
透過 npx 以 stdio 在本機執行(需要 Node.js)。選用的 WATCHDOG_SOLANA_PRIVATE_KEY 與 WATCHDOG_EVM_PRIVATE_KEY 用於支付每次呼叫的 USDC 費用;缺少某條鏈的金鑰時,其工具只回傳價格而不回傳結果。WATCHDOG_BUDGET_USD(預設 5)與 WATCHDOG_MAX_PER_CALL_USD(預設 1)限制花費;WATCHDOG_SOLANA_RPC_URL 預設使用公開主網。需要網路存取。
安裝前請注意
付費呼叫會從所提供的錢包自動支出真實 USDC,請使用只存放可承受花費金額的專用錢包。私鑰透過 WATCHDOG_SOLANA_PRIVATE_KEY 與 WATCHDOG_EVM_PRIVATE_KEY 傳入,能讀取用戶端設定的人即可看到。watch_create 會註冊 webhook,scan_repo 會把公開儲存庫參照傳送給第三方服務。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Watchdog,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

watchdog-mcp

An MCP server for Solana Watchdog and EVM Watchdog. It gives an agent the security checks it needs at the moment it decides: before signing for a program, before approving a contract, before adding a dependency. Each paid call costs cents in USDC and is paid automatically over x402, from a wallet you provide, within limits you set.

Results are checks, not audits.

Tools

ToolUse itPrice
solana_program_authoritybefore signing for a Solana program: who can replace its code (single key, Squads multisig with threshold and time lock, DAO, immutable), last deploy, verified build, security.txt$0.05 (Solana)
evm_contract_controlbefore approving or depositing on Base / Robinhood Chain: proxy kind, live implementation, who controls upgrades and ownership (key, Safe, timelock), Sourcify verification$0.05 (Base)
dependency_advisoriesbefore adding a dependency: advisories for a Cargo.lock, package-lock.json or yarn.lock on disk, or a package list$0.01
scan_repobefore a release: a full scan of a public GitHub repo (Rust/Anchor or Solidity)$0.50
get_scan_reportstatus and report of a scanfree
watch_createto be alerted for 30 days when a program, contract or lockfile changes, by signed webhook$0.90
watch_statusevents of a watch, or cancel itfree
watchdog_walletwhich wallets are set, caps, what was spentfree

An address that holds no program or contract is not charged. A dependency check is settled only once its answer exists.

Install

Claude Code:

sh
claude mcp add watchdog \  -e WATCHDOG_SOLANA_PRIVATE_KEY=<base58 key of a Solana wallet holding a little USDC> \  -e WATCHDOG_EVM_PRIVATE_KEY=<hex key of a Base wallet holding a little USDC> \  -- npx -y watchdog-mcp

Claude Desktop, Cursor and other clients (mcpServers JSON):

json
{  "mcpServers": {    "watchdog": {      "command": "npx",      "args": ["-y", "watchdog-mcp"],      "env": {        "WATCHDOG_SOLANA_PRIVATE_KEY": "…",        "WATCHDOG_EVM_PRIVATE_KEY": "…",        "WATCHDOG_BUDGET_USD": "5"      }    }  }}

From a clone of this repository, scripts/add-to-claude-code.sh does the Claude Code step for you: it reads the Solana key from the clipboard, checks it without printing it, and registers the server.

Both keys are optional. Without a key for a chain, its tools return the price and how to pay instead of an answer.

Use a dedicated wallet that holds only what you are willing to spend on checks. No SOL or ETH is needed: the x402 facilitator pays the network fee.

Configuration

VariableDefault
WATCHDOG_SOLANA_PRIVATE_KEYnoneSolana wallet, base58 (as Phantom exports it)
WATCHDOG_EVM_PRIVATE_KEYnoneBase wallet, hex
WATCHDOG_MAX_PER_CALL_USD1refuse any single payment above this
WATCHDOG_BUDGET_USD5refuse payments beyond this total, per server process
WATCHDOG_SOLANA_RPC_URLpublic mainnetRPC used to build Solana payments

What protects your wallet

Every payment is screened before anything is signed:

  • it must go to the Watchdog merchant wallet of that service, in USDC, on the expected network. A server that asked to be paid elsewhere would be refused;
  • it must fit under the per-call cap and the remaining session budget;
  • scan and watch access tokens are only ever sent back to the Watchdog that issued them.

Keys never appear in tool output or errors, including when a key is malformed or of the wrong chain.

License

MIT

來源:README.md,提交 fedcc43

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.0最新Oct 2, 2026