
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
watchdog-mcp
Advanced tools
MCP server for Solana and EVM Watchdog: who can change a program or contract, dependency advisories, repo scans and watches, paid per call over x402.
An MCP server for Solana Watchdog and EVM Watchdog. It gives an agent the security checks it needs at the moment it decides: before signing for a program, before approving a contract, before adding a dependency. Each paid call costs cents in USDC and is paid automatically over x402, from a wallet you provide, within limits you set.
Results are checks, not audits.
| Tool | Use it | Price |
|---|---|---|
solana_program_authority | before signing for a Solana program: who can replace its code (single key, Squads multisig with threshold and time lock, DAO, immutable), last deploy, verified build, security.txt | $0.05 (Solana) |
evm_contract_control | before approving or depositing on Base / Robinhood Chain: proxy kind, live implementation, who controls upgrades and ownership (key, Safe, timelock), Sourcify verification | $0.05 (Base) |
dependency_advisories | before adding a dependency: advisories for a Cargo.lock, package-lock.json or yarn.lock on disk, or a package list | $0.01 |
scan_repo | before a release: a full scan of a public GitHub repo (Rust/Anchor or Solidity) | $0.50 |
get_scan_report | status and report of a scan | free |
watch_create | to be alerted for 30 days when a program, contract or lockfile changes, by signed webhook | $0.90 |
watch_status | events of a watch, or cancel it | free |
watchdog_wallet | which wallets are set, caps, what was spent | free |
An address that holds no program or contract is not charged. A dependency check is settled only once its answer exists.
Claude Code:
claude mcp add watchdog \
-e WATCHDOG_SOLANA_PRIVATE_KEY=<base58 key of a Solana wallet holding a little USDC> \
-e WATCHDOG_EVM_PRIVATE_KEY=<hex key of a Base wallet holding a little USDC> \
-- npx -y watchdog-mcp
Claude Desktop, Cursor and other clients (mcpServers JSON):
{
"mcpServers": {
"watchdog": {
"command": "npx",
"args": ["-y", "watchdog-mcp"],
"env": {
"WATCHDOG_SOLANA_PRIVATE_KEY": "…",
"WATCHDOG_EVM_PRIVATE_KEY": "…",
"WATCHDOG_BUDGET_USD": "5"
}
}
}
}
From a clone of this repository, scripts/add-to-claude-code.sh does the Claude Code step for you: it reads the Solana key from the clipboard, checks it without printing it, and registers the server.
Both keys are optional. Without a key for a chain, its tools return the price and how to pay instead of an answer.
Use a dedicated wallet that holds only what you are willing to spend on checks. No SOL or ETH is needed: the x402 facilitator pays the network fee.
| Variable | Default | |
|---|---|---|
WATCHDOG_SOLANA_PRIVATE_KEY | none | Solana wallet, base58 (as Phantom exports it) |
WATCHDOG_EVM_PRIVATE_KEY | none | Base wallet, hex |
WATCHDOG_MAX_PER_CALL_USD | 1 | refuse any single payment above this |
WATCHDOG_BUDGET_USD | 5 | refuse payments beyond this total, per server process |
WATCHDOG_SOLANA_RPC_URL | public mainnet | RPC used to build Solana payments |
Every payment is screened before anything is signed:
Keys never appear in tool output or errors, including when a key is malformed or of the wrong chain.
MIT
FAQs
MCP server for Solana and EVM Watchdog: who can change a program or contract, dependency advisories, repo scans and watches, paid per call over x402.
We found that watchdog-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.