
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
@didwork/mcp
Advanced tools
DidWork MCP server — let agents verify outcomes instead of grading their own work. Your agent said it's done. Did it work?
Your agent said it's done. Did it work?
DidWork as an MCP server: gives any MCP-capable agent — Claude Code, Claude Desktop, Cursor, or your own — a did_verify tool, so the agent gates its next action on independently gathered evidence instead of grading its own work.
Agent acts → did_verify(claim) → VERIFIED / FAILED / UNKNOWN → agent proceeds or escalates
No key is required to try it: keyless, http.ok claims verify against any public URL (rate limited, not stored), so the server delivers a first verdict straight from /plugin install. A free API key from didwork.sh/console unlocks every claim type, the verification log, and watches.
Claude Code — install the plugin (this server plus a session rule, skill, /didwork:verify command, and verifier subagent):
/plugin marketplace add didworksh/claude-plugin
/plugin install didwork@didwork
Or wire up just the MCP server:
claude mcp add didwork -e DIDWORK_API_KEY=dk_your_key -- npx -y @didwork/mcp
Cursor — install the plugin, or add the server to ~/.cursor/mcp.json. Claude Desktop (claude_desktop_config.json):
{
"mcpServers": {
"didwork": {
"command": "npx",
"args": ["-y", "@didwork/mcp"],
"env": { "DIDWORK_API_KEY": "dk_your_key" }
}
}
}
| Tool | Does |
|---|---|
did_verify | Verify a claim now — returns the verdict with evidence attached |
did_get | Fetch a verification by id (poll async verifications) |
did_list | Recent verifications for this key, evidence included |
did_watch | Re-verify a claim on an interval; webhook on verdict transitions |
did_watches | List active watches and their last verdicts |
did_unwatch | Stop a watch |
did_usage | Verifications performed, by month |
stripe.refund, stripe.payment_succeeded, stripe.subscription_active, stripe.subscription_cancelled, stripe.invoice_paid, github.pr_merged, github.workflow_passed, github.issue_closed, github.release_published, github.commit_in_branch, github.file_exists, gitlab.mr_merged, gitlab.pipeline_passed, gitlab.issue_closed, sentry.issue_resolved, jira.issue_done, linear.issue_completed, slack.message_posted, email.delivered, and http.ok (any public URL — no provider connection needed).
Field reference: didwork.sh/docs#claims. Providers connect once, read-only, at didwork.sh/console.
A line like this in your agent's instructions makes the tool bite:
After any consequential action (refund, deploy, ticket close, message send), call
did_verifywith the matching claim before reporting success. Proceed only onverified. Treatfailedandunknownas stop-and-escalate.
| Variable | Meaning |
|---|---|
DIDWORK_API_KEY | From the console. Unset = keyless mode: http.ok only, other tools answer with how to unlock |
DIDWORK_BASE_URL | Optional — defaults to https://api.didwork.sh |
FAQs
DidWork MCP server: let agents verify outcomes instead of grading their own work. Your agent said it's done. Did it work?
The npm package @didwork/mcp receives a total of 66 weekly downloads. As such, @didwork/mcp popularity was classified as not popular.
We found that @didwork/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.