New:Introducing Socket Scanning for VS Code Marketplace Extensions.Learn more →
Get Started

watchdog-mcp

Package Overview
Dependencies
Maintainers
1
Versions
1
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

watchdog-mcp

MCP server for Solana and EVM Watchdog: who can change a program or contract, dependency advisories, repo scans and watches, paid per call over x402.

latest
Source
npmnpm
Version
0.1.0
Version published
Maintainers
1
Created
Source

watchdog-mcp

An MCP server for Solana Watchdog and EVM Watchdog. It gives an agent the security checks it needs at the moment it decides: before signing for a program, before approving a contract, before adding a dependency. Each paid call costs cents in USDC and is paid automatically over x402, from a wallet you provide, within limits you set.

Results are checks, not audits.

Tools

ToolUse itPrice
solana_program_authoritybefore signing for a Solana program: who can replace its code (single key, Squads multisig with threshold and time lock, DAO, immutable), last deploy, verified build, security.txt$0.05 (Solana)
evm_contract_controlbefore approving or depositing on Base / Robinhood Chain: proxy kind, live implementation, who controls upgrades and ownership (key, Safe, timelock), Sourcify verification$0.05 (Base)
dependency_advisoriesbefore adding a dependency: advisories for a Cargo.lock, package-lock.json or yarn.lock on disk, or a package list$0.01
scan_repobefore a release: a full scan of a public GitHub repo (Rust/Anchor or Solidity)$0.50
get_scan_reportstatus and report of a scanfree
watch_createto be alerted for 30 days when a program, contract or lockfile changes, by signed webhook$0.90
watch_statusevents of a watch, or cancel itfree
watchdog_walletwhich wallets are set, caps, what was spentfree

An address that holds no program or contract is not charged. A dependency check is settled only once its answer exists.

Install

Claude Code:

claude mcp add watchdog \
  -e WATCHDOG_SOLANA_PRIVATE_KEY=<base58 key of a Solana wallet holding a little USDC> \
  -e WATCHDOG_EVM_PRIVATE_KEY=<hex key of a Base wallet holding a little USDC> \
  -- npx -y watchdog-mcp

Claude Desktop, Cursor and other clients (mcpServers JSON):

{
  "mcpServers": {
    "watchdog": {
      "command": "npx",
      "args": ["-y", "watchdog-mcp"],
      "env": {
        "WATCHDOG_SOLANA_PRIVATE_KEY": "…",
        "WATCHDOG_EVM_PRIVATE_KEY": "…",
        "WATCHDOG_BUDGET_USD": "5"
      }
    }
  }
}

From a clone of this repository, scripts/add-to-claude-code.sh does the Claude Code step for you: it reads the Solana key from the clipboard, checks it without printing it, and registers the server.

Both keys are optional. Without a key for a chain, its tools return the price and how to pay instead of an answer.

Use a dedicated wallet that holds only what you are willing to spend on checks. No SOL or ETH is needed: the x402 facilitator pays the network fee.

Configuration

VariableDefault
WATCHDOG_SOLANA_PRIVATE_KEYnoneSolana wallet, base58 (as Phantom exports it)
WATCHDOG_EVM_PRIVATE_KEYnoneBase wallet, hex
WATCHDOG_MAX_PER_CALL_USD1refuse any single payment above this
WATCHDOG_BUDGET_USD5refuse payments beyond this total, per server process
WATCHDOG_SOLANA_RPC_URLpublic mainnetRPC used to build Solana payments

What protects your wallet

Every payment is screened before anything is signed:

  • it must go to the Watchdog merchant wallet of that service, in USDC, on the expected network. A server that asked to be paid elsewhere would be refused;
  • it must fit under the per-call cap and the remaining session budget;
  • scan and watch access tokens are only ever sent back to the Watchdog that issued them.

Keys never appear in tool output or errors, including when a key is malformed or of the wrong chain.

License

MIT

Keywords

mcp

FAQs

Package last updated on 01 Oct 2026

Related posts