# Watchdog (npm · watchdog-mcp)

Who can change a Solana program or EVM contract, dependency advisories, scans. Paid per call (x402).

- Trust score: 68/100 (medium)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-04

## Components

- npm · `watchdog-mcp`: 68/100 (this document), [markdown](https://verifymcp.io/servers/oxtof-watchdog-mcp/watchdog-mcp.md), [page](https://verifymcp.io/servers/oxtof-watchdog-mcp/watchdog-mcp)

## Channel facts

- Registry: `npm`
- Package: `watchdog-mcp`
- Version: `0.1.0`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-04.

- **Supply Chain Security**: 99/100
  - No malware found by supply-chain analysis.
  - No known CVEs affecting this package version or its production dependencies.
  - No install/post-install scripts declared.
  - 31 of 232 dependencies flagged as unhealthy.
- **Provenance & Transparency**: 45/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 2 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 71/100
  - AI-judged instruction clarity (good).
  - Context-footprint check failed: tool/resource definitions use about 1091 tokens (~136/item across 8 items; 8 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 80/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 41% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 8 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 9 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

**Unverified: 1 category.** A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

## Install

### How do I install the Watchdog MCP server?

Watchdog runs locally as an npm package, launched with npx -y watchdog-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add oxtof-watchdog-mcp -- npx -y watchdog-mcp
```

### Cursor

```json
{
  "mcpServers": {
    "oxtof-watchdog-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "watchdog-mcp"
      ]
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "oxtof-watchdog-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "watchdog-mcp"
      ]
    }
  }
}
```

### Codex

```bash
codex mcp add oxtof-watchdog-mcp -- npx -y watchdog-mcp
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "oxtof-watchdog-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "watchdog-mcp"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add oxtof-watchdog-mcp --command npx --arg -y --arg watchdog-mcp
```

### Hermes

```yaml
mcp_servers:
  oxtof-watchdog-mcp:
    command: "npx"
    args: ["-y", "watchdog-mcp"]
```

### Netclaw

```json
{
  "McpServers": {
    "oxtof-watchdog-mcp": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "watchdog-mcp"
      ]
    }
  }
}
```

### Vellum

```bash
assistant mcp add oxtof-watchdog-mcp -t stdio -c npx -a -y watchdog-mcp
```

### Other

```json
{
  "mcpServers": {
    "oxtof-watchdog-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "watchdog-mcp"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-10-02 (score 68, +15)

- [security improvement] Malware scan: unverified → pass

### 2026-10-01 (score 53)

First indexed and scored.

## MCP tools (8)

### `solana_program_authority` (~141 tokens)

Who can change this Solana program?

Use before signing a transaction for, or depositing into, a Solana mainnet program. Answers who can replace its code: immutable, a single key, a Squads v4 multisig (threshold, members and time lock read on-chain, the vault re-derived as proof), Squads v3 or SPL Governance; plus the last deploy date, OtterSec verified build, embedded security.txt and severity-ranked flags. Costs $0.05 USDC on Solana, paid over x402 from WATCHDOG_SOLANA_PRIVATE_KEY. An address that holds no program is not charged.

Input parameters:

- `programId` (string, required): Program address, base58

### `evm_contract_control` (~168 tokens)

Who can change this EVM contract?

Use before approving a token, depositing into, or signing for a contract on Base or Robinhood Chain. Detects the proxy kind (EIP-1967 transparent, UUPS, beacon, legacy zeppelinos, EIP-1167 clone, diamond, EIP-7702), the live implementation, and follows the upgrade controller and owner to the end: one key, a Safe (threshold of owners), a timelock (delay). Sourcify verification for the address and the implementation. Costs $0.05 USDC on Base, paid over x402 from WATCHDOG_EVM_PRIVATE_KEY. An address with no code is not charged.

Input parameters:

- `address` (string, required): Contract address, 0x…
- `chain` (string): Chain the contract lives on

### `dependency_advisories` (~192 tokens)

Known advisories for pinned dependencies

Use before adding or upgrading a dependency, or to triage a lockfile. Give lockfile_path (a Cargo.lock, package-lock.json or yarn.lock on disk, read locally) or the lockfile text, or a list of up to 100 packages. Rust crates go to Solana Watchdog (RustSec/OSV), npm packages to EVM Watchdog (GitHub/OSV). Only registry packages are checked; workspace and git dependencies are skipped. Costs $0.01 USDC per call (Solana for crates, Base for npm). Settled only if the answer exists.

Input parameters:

- `ecosystem` (string): Required with lockfile text or packages
- `lockfile` (string): Lockfile text, if not on disk
- `lockfile_path` (string): Path to Cargo.lock, package-lock.json or yarn.lock
- `packages` (array): Exact pinned versions

### `scan_repo` (~154 tokens)

Security scan of a public GitHub repo

Use before a release or an integration: scans a public GitHub repo for advisories on its exact pinned dependencies (split into what ships on-chain and what is tooling), build hygiene, and code leads for known bug classes with file:line. ecosystem 'solana' for Rust/Anchor programs, 'evm' for Solidity (Foundry/Hardhat). Costs $0.50 USDC (Solana or Base). Waits up to wait_seconds for the report; otherwise returns jobId and accessToken for get_scan_report. A scan, not an audit.

Input parameters:

- `ecosystem` (string, required)
- `repo` (string, required): https://github.com/OWNER/REPO
- `wait_seconds` (integer)

### `get_scan_report` (~53 tokens)

Status and report of a paid scan

Free. Returns the status of a scan started with scan_repo and, once done, its JSON report.

Input parameters:

- `accessToken` (string, required)
- `ecosystem` (string, required)
- `jobId` (string, required)

### `watch_create` (~198 tokens)

Get alerted when a program, contract or lockfile changes

Use to be told, for 30 days, when something you rely on changes: a Solana program (programId: authority, multisig rules, code upgrade, lost verification), an EVM contract (address + chain: new implementation, controller or owner, weaker Safe or timelock), or a lockfile (lockfile_path: any new advisory). Hourly checks; each change is POSTed to your https webhook, signed with x-watchdog-signature: sha256=HMAC(secret, body). Costs $0.90 USDC for the period (Solana for programs and Cargo.lock, Base for contracts and npm lockfiles). Returns watchId, secret and accessToken, each shown once.

Input parameters:

- `address` (string)
- `chain` (string)
- `lockfile_path` (string)
- `programId` (string)
- `webhook` (string, required): Public https URL that receives the signed alerts

### `watch_status` (~64 tokens)

Events of a watch

Free. Lists what a watch has seen (also kept when the webhook was down), or cancels it with cancel: true.

Input parameters:

- `accessToken` (string, required)
- `cancel` (boolean)
- `ecosystem` (string, required)
- `watchId` (string, required)

### `watchdog_wallet` (~43 tokens)

Payment setup and spend

Free. Shows which payment wallets this server is configured with (addresses only), the per-call cap, the session budget, what was spent, and the price of each tool.

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/oxtof-watchdog-mcp/watchdog-mcp#diagnostics

## Score history

- 2026-10-04: 68
- 2026-10-03: 68
- 2026-10-02: 68
- 2026-10-01: 53

## Common questions

### What is the Watchdog MCP server?

Watchdog is an MCP server listed in the public MCP registry as io.github.OxToF/watchdog-mcp. Who can change a Solana program or EVM contract, dependency advisories, scans. Paid per call (x402). This page covers its npm package (watchdog-mcp).

### Is the Watchdog MCP server safe to use?

Watchdog scores 68 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 4 October 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Watchdog MCP server expose?

Watchdog exposes 8 tools: solana_program_authority, evm_contract_control, dependency_advisories, scan_repo, get_scan_report, and 3 more. Their descriptions and schemas cost roughly 1,013 tokens of context every time the server is loaded.

### Is the Watchdog MCP server still maintained?

Watchdog is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

### What licence is the Watchdog MCP server under?

Watchdog declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.

## Links

- npm package: https://www.npmjs.com/package/watchdog-mcp
- Socket report: https://socket.dev/npm/package/watchdog-mcp
- Repository: https://github.com/OxToF/watchdog-mcp
- Changelog RSS feed: https://verifymcp.io/servers/oxtof-watchdog-mcp/watchdog-mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/oxtof-watchdog-mcp/watchdog-mcp.json
- HTML version of this page: https://verifymcp.io/servers/oxtof-watchdog-mcp/watchdog-mcp
